Agent-readable docs index: /llms.txt. Full docs in one file: /llms-full.txt. Download /docs.zip to grep all markdown files locally.

Deploy Sigillo from source

self-host deploys a release without a clone or a build. To run your own changes instead:
  1. Clone the repo and install dependencies:
git clone https://github.com/kldzj/sigillo.git cd sigillo && pnpm install
  1. Create provider/.dev.vars (requires a Google OAuth client with <provider-url>/api/auth/callback/google as redirect URI):
BETTER_AUTH_SECRET=<any random string> GOOGLE_CLIENT_ID=<your Google OAuth client ID> GOOGLE_CLIENT_SECRET=<your Google OAuth client secret>
  1. Create app/.dev.vars:
BETTER_AUTH_SECRET=<any random string> ENCRYPTION_KEY=<output of: openssl rand -base64 32>
To limit who can sign in, set the same ALLOWED_USERS=acme.com,ops@partner.io in both files, and as a secret on both Workers when you deploy.
  1. Run both locally:
pnpm --dir provider dev pnpm --dir app dev
  1. To deploy, add an environment for your account to provider/wrangler.jsonc and app/wrangler.jsonc (your D1 databases, BETTER_AUTH_URL for the provider and PROVIDER_URL for the app, plus the global_fetch_strictly_public compatibility flag on the app when both Workers share a workers.dev subdomain), then deploy the provider first and the app second.
The app registers itself with its provider on first request via RFC 7591 dynamic client registration.