Server Configuration

Configure D1, R2, Better Auth, and provider secrets for a Unified host.

Bind D1 and R2, then configure the Better Auth URL/secret, trusted native origin, and active Apple/Google audiences. Add explicit RevenueCat product mappings and webhook authorization plus push-provider credentials only when needed.

Secrets belong in Cloudflare deployment bindings, never Vite client defines. A client bundle receives only its API base URL, request Origin, publishable SDK keys, and platform identifiers.

Missing core Unified bindings must fail explicitly. Never reinterpret a binding failure as permission to connect a client to Supabase.