Repository navigation
Expand file tree
/
Copy path.env.example
More file actions
95 lines (72 loc) · 3.38 KB
/
Copy path.env.example
File metadata and controls
95 lines (72 loc) · 3.38 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
# Environment Variables Template
############################################
# REQUIRED ENVIRONMENT VARIABLES
############################################
# Contract Addresses (Base Mainnet)
# Must match the live Trivia contract that emits PlayerJoined (paid verify filters logs by this address).
NEXT_PUBLIC_TRIVIA_CONTRACT_ADDRESS=0xfF52Ed1DEb46C197aD7fce9DEC93ff9e987f8dB6
NEXT_PUBLIC_USDC_ADDRESS=0x833589fcd6edb6e08f4c7c32d4f71b54bda02913
# SpaceTimeDB Configuration (REQUIRED)
SPACETIME_HOST=https://maincloud.spacetimedb.com
SPACETIME_DATABASE=your_database_id
SPACETIME_IDENTITY=your_identity_id
SPACETIME_MODULE=beat-me
SPACETIME_PORT=443
############################################
# CDP API AUTHENTICATION (Choose ONE method)
############################################
# Method 1: Ed25519/RSA (Preferred - New Format)
CDP_API_KEY_NAME=organizations/your-org/apiKeys/your-key
CDP_API_KEY_PRIVATE_KEY=your_private_key_here
CDP_PROJECT_ID=your_project_id
# Method 2: Legacy HMAC (Fallback)
CDP_API_KEY=your_api_key
CDP_API_SECRET=your_api_secret
############################################
# SECURITY & CORS
############################################
# JWT signing secret for game entry tokens (REQUIRED in production)
# Generate: node -e "console.log(require('crypto').randomBytes(32).toString('hex'))"
ENTRY_TOKEN_SECRET=your_entry_token_secret_here
# Webhook secret for CDP/Chainlink webhooks (REQUIRED in production if using webhooks)
WEBHOOK_SECRET=your_webhook_secret_here
# Allowed origins for CORS (comma-separated)
ALLOWED_ORIGINS=https://beatme.creativeplatform.xyz,http://localhost:3000,http://localhost:3001
# Admin API secret key (generate a strong random string)
ADMIN_API_SECRET=your_super_secret_admin_key_here
############################################
# OPTIONAL CONFIGURATION
############################################
# Base Builder Code (ERC-8021 transaction attribution)
NEXT_PUBLIC_BUILDER_CODE=bc_5l04cy7v
# OnchainKit API Key (for enhanced wallet features)
NEXT_PUBLIC_ONCHAINKIT_API_KEY=your_onchainkit_api_key
# Environment
NODE_ENV=development
# Blockchain RPC URLs (for contract deployment/testing)
BASE_SEPOLIA_RPC_URL=https://sepolia.base.org
BASE_RPC_URL=https://mainnet.base.org
# Optional: primary RPC for /api/game-entry paid-tx verification (then always falls back to https://mainnet.base.org).
# Leave unset to use Base public only. CDP/Alchemy URLs may return stub receipts; server uses block-scoped getLogs as fallback.
# Paid verification does NOT use BASE_RPC_URL / NEXT_PUBLIC_BASE_RPC_URL so a broken Alchemy key cannot block joins.
# PAID_VERIFY_RPC_URL=
PRIVATE_KEY=your_wallet_private_key_for_deployment
# Etherscan API Key (for contract verification)
ETHERSCAN_API_KEY=your_etherscan_api_key
# Rate Limiting (Optional - uses default values if not set)
RATE_LIMIT_MAX_REQUESTS=10
RATE_LIMIT_WINDOW_MS=60000
```
## Generating Secure Secrets
Generate `ADMIN_API_SECRET` or `ENTRY_TOKEN_SECRET`:
```bash
node -e "console.log(require('crypto').randomBytes(32).toString('hex'))"
```
## Vercel Deployment
Set all required variables in your Vercel dashboard:
1. Go to Project Settings → Environment Variables
2. Add each variable from the REQUIRED section above
3. Set `NODE_ENV=production`
4. Set `ENTRY_TOKEN_SECRET` (required in production; do not use dev fallback)
5. Set `WEBHOOK_SECRET` if using CDP/Chainlink webhooks
6. Update `ALLOWED_ORIGINS` with your production domain