> ## Documentation Index
> Fetch the complete documentation index at: https://docs.whirl.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploying the API

> Environment variables and release checks for running Whirl's API. For Whirl maintainers.

## Backend environment

| Variable | Purpose |
| - | - |
| `API_URL` | Canonical HTTPS API issuer; falls back to `CONVEX_SITE_URL`. Must route to this deployment's HTTP actions. |
| `APP_URL` | Frontend origin containing `/oauth/consent` and sign-in; defaults to `https://whirl.sh`. |
| `MCP_ALLOWED_ORIGINS` | Additional exact comma-separated HTTP(S) browser origins; no paths, credentials or wildcards. |

The issuer origin, frontend origin, and configured browser origins are allowed by MCP origin checks. Requests without an `Origin` header are supported. Origin permission is not OAuth permission.

Set frontend `NEXT_PUBLIC_API_URL` to the same canonical issuer. Docs and Settings fall back to `NEXT_PUBLIC_CONVEX_SITE_URL`, then the HTTP-action origin derived from `NEXT_PUBLIC_CONVEX_URL`. Rebuild after changing public environment variables.

Deploy the schema, backend functions and frontend together. OAuth, discovery, MCP, REST and dynamic client registration routes are available immediately after deployment; no enablement flags are required.

## Release checklist

* Verify public HTTPS issuer routing, OAuth discovery and protected-resource metadata.
* Exercise sign-in/consent, exact redirects, PKCE exchange, denied scopes and restricted workspaces.
* Test actual CIMD/DCR metadata and, when selected, the client's signing algorithm, key IDs and assertion audience.
* Call read-only tools, then a harmless user-approved write in a test workspace.
* Verify refresh rotation, replay/reuse rejection, revocation and lost-membership behavior.
* Test rate limits, DNS/key-fetch failure, production action memory and expected load.
* Connect the deployed server with each target external client, including ChatGPT before any directory/store submission.
* Complete an independent security review appropriate to the rollout.

Local tests cover the protocol; check ChatGPT compatibility, production memory use, behavior under load and store approval against the deployed server.

## Updating these docs

Edit guides under `content/docs`. Endpoint and tool pages derive from `convex/publicApi/operations/catalog.helpers.ts` and the shared OpenAPI builder; add or change an operation there rather than maintaining a second list. Keep the configured docs origin aligned with the deployed backend.

```bash theme={null}
pnpm run docs:generate
pnpm run fix
pnpm run typecheck
pnpm test
```

Generated MDX files live in ignored `.source/` and are recreated by `postinstall`. The docs site is public at `/docs`; search indexes only documentation and generated catalog descriptions, never private workspace data.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.