# ─────────────────────────────────────────────────────────────────────────
# WHAT BELONGS IN THIS FILE — and what does NOT
#
# This file is for the DEPLOYMENT'S OWN identity and its model keys. That is
# all. Provider credentials do NOT live here.
#
#   HERE, in .env
#     LEAFMESH_LICENSE_KEY, LEAFMESH_ENV_TOKEN
#     the ports, REDIS_* / Postgres  (the store the vault itself lives in)
#     your model provider key(s): OPENAI_API_KEY / ANTHROPIC_API_KEY /
#       GOOGLE_API_KEY …  (these are read from the environment as the mesh
#       starts, so they must be here — the vault is read too late for them)
#
#   NOT HERE — in the VAULT, added on Studio's Infrastructure page
#     every channel credential  (Slack bot_token / signing_secret / app_token,
#       Teams, Discord, Cliq, WhatsApp, Email)
#     every connector credential (MCP, Zapier, Composio, n8n, custom)
#     Config then names it:  connection: "slack-workspace"
#
# Why it matters: since 2.4.180 the mesh REFUSES TO BOOT if it finds a
# provider credential written into config — and `${ENV_VAR}` does not help,
# because substitution happens before the check runs, so the check sees the
# token itself. `connection:` is the only path that works.
#
# Note: a value is EMPTY here, never a comment. `KEY=   # explanation` is read
# by python-dotenv as the COMMENT being the value.
# ─────────────────────────────────────────────────────────────────────────

# {{project_name}} — environment. Copy to .env and fill in.  cp env .env
#
# The whole pod runs on Tier 1 alone against the seeded price book / deal
# history / competitor / invoice store (./data). The LLM chain (shape ->
# approve routing -> draft -> issue -> invoice -> dun) works day-0; the
# system-of-record reads use dev stand-ins that ANNOUNCE themselves
# (available:false) until you wire Tiers 2-3.

# ── Tier 1 — required to boot ──────────────────────────────────────────────
LEAFMESH_LICENSE_KEY=
LEAFMESH_ENV_TOKEN=development   # per-environment telemetry token (dev / staging / prod)
# Cass (deal shaping, claude-sonnet-4-6)
ANTHROPIC_API_KEY=
# Quinn, drafter, billing (gpt-4o-mini) + the Manager
OPENAI_API_KEY=

# ── State store (defaults work for local dev) ──────────────────────────────
REDIS_HOST=localhost
REDIS_PORT=6379
REDIS_PASSWORD=
# Approval thresholds are NOT env vars — they live as wire conditions on
# cass_shaper_agent in configs/config.yaml. Edit them there.

# ── HITL — where human members are notified (rep / deal-desk / finance / CFO
#    / RevOps lead) ──
# HITL_OUTBOUND_URL=http://127.0.0.1:9999/human-notify
#   ^ LOCAL TEST STUB ONLY. Leave it commented. A human seat should be
#     human_interface: "default" (the Studio Inbox) — a real queue a real
#     person clicks. A custom webhook receiver is not how HITL is run.

# ── Tier 2 — real system-of-record connectors (inert until set) ────────────
# Set the URL, then UNCOMMENT the matching `mcp:` block in configs/config.yaml.
# CPQ/ERP price book + deal history (Salesforce CPQ / NetSuite / SAP) — cass_shaper_agent
CPQ_MCP_URL=
CPQ_MCP_TOKEN=
# billing / AR system (Stripe / NetSuite / Chargebee) — billing_agent
BILLING_MCP_URL=
BILLING_MCP_TOKEN=

# ── Tier 3 — CPQ create-quote webhook (the finisher's push) ────────────────
# your CPQ create-quote webhook — quote_issuer_agent's push. Inert until set; the issuer renders ./out/<quote>.pdf and records a dev-store fallback regardless.
CPQ_WEBHOOK_URL=
# bearer token for the CPQ webhook (optional)
CPQ_WEBHOOK_TOKEN=
