All guides
Running the platform

Security checklist before going live

1. Set your secrets

Both must be long random values in .env. Generate them with openssl rand -base64 48.

  • JWT_SECRET — signs login sessions. Left at the default, anyone could forge a session for any account. Changing it logs everyone out once.
  • APP_KEY — encrypts stored GitHub tokens. Set it once: changing it later means users must reconnect GitHub.

2. Lock down file permissions

sudo ./scripts/harden-permissions.sh

3. Understand the sandbox limits

Generated apps run on the same machine as this platform, as the same user. Directory permissions raise the bar but do not fully contain code running as that user. Before opening public signups, run sandboxes as their own unix user or in containers.

4. Email deliverability

If you send password resets from the server, add an SPF record and reverse DNS for the IP, or they will land in spam.