apps/api/src/config/env.ts; the process refuses to start on an
invalid value rather than failing later inside an adapter.
Server
The API version is not an environment variable:
API_VERSION in
packages/contracts/src/http/version.ts is the single constant that versions the
URL prefix, the client, the response header and the generated specification. It
changes when the API version changes, in one place. See
versioning.
Database
Authentication
Rotating either secret invalidates the tokens signed with it. Refresh tokens are
additionally revoked in the database on rotation, so a stolen token is usable at
most once. See sessions.
Model provider
Timeouts and retries
A generation is a network call to someone else’s server, so it is bounded and repeated rather than left to hang.
Only a transient failure is repeated: a dropped connection, a
429, a 5xx, or a
timeout. A rejected key or a malformed request is not, because repeating it cannot
succeed. The wait grows exponentially with the attempt number and is randomised
across 0–delay (full jitter), so several requests that fail together do not
all return at the same instant.
Retries repeat the same provider. They never fall back to another one or to the
local generator: silently answering from a different model would hand back a
campaign that does not match what was asked for. When every attempt fails the
caller gets 503 with llm_unavailable. See
the generative pipeline.
With no key at all, the deterministic local generator answers, and the boot log
says so. Asking for a provider whose key is missing resolves to the generator and
logs the mismatch rather than binding an adapter that would fail on every call:
Web app
Copying the example file
.env is not committed. The example file must stay in step with the schema above;
a variable added to env.ts belongs in it.