# Installation

1. Clone the repository
2. Install the dependencies

```
npm install
```

3. Set up the environment variables

```
CONVEX_DEPLOYMENT=
NEXT_PUBLIC_CONVEX_URL=
NEXT_PUBLIC_CONVEX_SITE_URL=
NEXT_PUBLIC_SITE_URL=http://localhost:3000

UPLOADTHING_TOKEN=

// for deploying
CONVEX_DEPLOY_KEY=
```

4. Run Convex

```
npx convex dev
```

Set Better Auth's deployment variables once for each Convex deployment:

```
npx convex env set BETTER_AUTH_SECRET <a-random-32-byte-secret>
npx convex env set SITE_URL http://localhost:3000
npx convex env set GOOGLE_CLIENT_ID <google-client-id>
npx convex env set GOOGLE_CLIENT_SECRET <google-client-secret>
npx convex env set APPLE_CLIENT_ID com.nexfiy.web
npx convex env set APPLE_CLIENT_SECRET <signed-apple-client-secret>
```

Google OAuth must allow these development callbacks:

```
http://localhost:3000/api/auth/callback/google
http://localhost:3001/api/auth/callback/google
```

The production callbacks are:

```
https://nexfiy.com/api/auth/callback/google
https://nexfiy.com/api/auth/callback/apple
```

Apple Sign in requires HTTPS and therefore works through the production domain,
not localhost. The signed Apple client secret expires after at most six months;
rotate it before expiry and update `APPLE_CLIENT_SECRET` in Convex.

Production billing uses the live Nexfiy Dodo brand and product
`pdt_0NkWHmeRZI6qHKsuyAW4f`. Keep local development on the test product. Set the
live API key and webhook secret only in the production Convex deployment, set
`DODO_PAYMENTS_ENVIRONMENT=live_mode`, and configure both server and public
product IDs to the live product. The production webhook endpoint is:

```
https://nexfiy.com/api/auth/dodopayments/webhooks
```

5. Run the development server

```
npm run dev
```