GA Release

The Multi-Agent WebGPU Engine & Interactions API are now generally available.

Part 25: Deployment Architecture & Environment Reference

A reference to the publisher-owned build and runtime: server routes, environment variables, proxy boundaries, and OAuth configuration.

Category: Tooling & Deployment • Read Time: 20 min read • Updated: September 27, 2026

1. Architecture in One Screen

The app is a React 19 + TypeScript single-page client (built with Vite) plus a small Express server (server.ts) that serves static/precompressed assets, handles GitHub OAuth, and provides the SSRF-hardened API proxy. A build step (prerender.js) pre-renders marketing/blog/docs pages for performance and SEO.

vite build → client bundle (code-split vendors)

tsx prerender.js → static HTML for /docs, /blog, tools…

esbuild server.ts → server.cjs (beside dist/)

precompress.js → .br / .gz siblings for assets

2. Deployment ownership and source permissions

The production workflow publishes the publisher's built static site to its configured host; optional API and OAuth endpoints run in the publisher's server environment. This page documents that architecture for transparency. Access to the hosted site or this reference does not grant permission to copy, locally execute, or redistribute the application source. See the Terms and LICENSE for current permissions.

3. Environment Variables

VariablePurpose
GITHUB_CLIENT_IDOAuth App client id. A legacy in-repo id is used with a loud warning if unset; set it for rotation without redeploy.
GITHUB_CLIENT_SECRETOAuth App secret. Required for the token exchange; never commit it.
APP_URLCanonical https origin advertised to clients and used as the OAuth redirect target (resolves apex/www and proxy mismatches).
TRUST_PROXYSet true behind a reverse proxy so req.protocol honours X-Forwarded-Proto (auto-on in Cloud Run via K_SERVICE).
OAUTH_ALLOWED_ORIGINSComma-separated extra origins (e.g. a static hosting mirror) allowed to participate in the OAuth relay.
FRAME_ANCESTORSComma-separated extra https origins allowed to embed the app in a frame; each is validated and malformed entries are dropped.
EXTRA_PROXY_DOMAINSComma-separated additional hostnames the API proxy may forward to (your own gateways).
NODE_ENV / DISABLE_HMRproduction tightens CSP; DISABLE_HMR=true turns off Vite HMR.

4. Server Endpoints (Overview)

POST /api/proxy — SSRF-allowlisted relay to AI/search providers (rate limited).

/api/gemini/* — Gemini generate/countTokens/image helpers.

/api/anthropic/* — Anthropic relay used when direct browser access is blocked.

/api/auth/github/* — OAuth config, session init/status/relay, callback, and token refresh (origin-checked).

/api/enhance-prompt & similar — server-side prompt utilities (rate limited, errors sanitized).

Static — precompressed brotli/gzip assets, prerendered pages, and an SPA fallback for app routes.

5. Publisher deployment safeguards

  • Set GITHUB_CLIENT_SECRET and APP_URL; confirm the redirect URI matches in the GitHub App.
  • Enable TRUST_PROXY=true if behind a load balancer (or rely on K_SERVICE on Cloud Run).
  • Terminate TLS at the proxy; the server sends HSTS in production.
  • Only add FRAME_ANCESTORS origins you actually want framing the app — a wildcard (especially for shared hosts) reopens clickjacking.
  • Keep the dependency tree patched; npm audit should show no high/critical issues in shipped packages.
  • Verify npm test and npm run build pass after configuring.

6. Data and privacy boundaries

The application does not use a central account database to persist chat history. Server routes can relay provider requests and handle short-lived OAuth state; origin checks can also write warning logs that include request metadata. The hosting provider controls its own access-log retention. Avoid logging Authorization headers or request bodies, which may contain prompts or credentials.