# ── SERVER ─────────────────────────────────────────────────────────────────── PORT=9000 DEV_AUTH_BYPASS=false AI_LOCK_EXPIRY_HOURS=168 # Azure AD — server app registration (validates incoming JWTs) AZURE_CLIENT_ID= AZURE_TENANT_ID= # Graph / OBO — required for calendar integration # App Registration → API permissions → Graph → Calendars.Read (delegated) → grant admin consent # App Registration → Certificates & secrets → New client secret AZURE_CLIENT_SECRET= # aud of client token must match this. Only needed if frontend uses a different app registration. AZURE_OBO_CLIENT_ID= # ── CLIENT (Vite — copy relevant lines to client/.env) ─────────────────────── # VITE_AZURE_CLIENT_ID= # VITE_AZURE_TENANT_ID= # VITE_DEV_AUTH_BYPASS=true # DEV ONLY — never set in production