Deployed runtime: email, signatures, and billing

CapabilityEnvironment variablesDev / production rule
Email backendNAVIGATOR_EMAIL_BACKENDMust be sendgrid outside the harness
Outbound SendGridSENDGRID_API_KEY, SENDGRID_FROM_EMAILRequired outside the harness
SendGrid base URLSENDGRID_BASE_URLOfficial hosts only outside the harness
Inbound URL gateSENDGRID_INBOUND_SECRETRequired outside the harness
Inbound signatureSENDGRID_INBOUND_PUBLIC_KEYRequired when summary review is enabled
Attachment scannerNAVIGATOR_CLAMD_ADDRRequired in every deployed profile; private clamd only
Event webhookSENDGRID_EVENTS_SECRET, SENDGRID_EVENTS_PUBLIC_KEYRequired outside the harness
Threaded mailNAVIGATOR_PARSE_HOST, NAVIGATOR_LAWYER_NOTIFY_EMAILBoth values enable it
Summary opt-inNAVIGATOR_SUMMARY_ENABLEDEnables durable review
Summary identityNAVIGATOR_DEPLOYMENT_ID, NAVIGATOR_SUMMARY_CHANNEL_IDDurable review coordinates
Summary envelopeNAVIGATOR_SUMMARY_ENVELOPE_RECIPIENTSUnset/off by default; blank values fail
SMS intakeNAVIGATOR_SMS_NUMBER, TWILIO_AUTH_TOKENOff by default; a number needs the token
Summary Gemini modelNAVIGATOR_SUMMARY_GEMINI_MODELOptional Vertex model override
Summary Gemini locationNAVIGATOR_SUMMARY_GEMINI_LOCATIONOptional Vertex location override
Summary input limitNAVIGATOR_SUMMARY_MAX_INPUT_CHARSOptional input limit
Summary output limitNAVIGATOR_SUMMARY_MAX_OUTPUT_TOKENSOptional output limit
DKIM fenceNAVIGATOR_DKIM_REQUIRE_DOMAINOptional domain pin
Lawyer-sender DKIM checknone (always on)Must pass for sender's own domain on every lawyer command/relay
Internal ops noticesSLACK_WEBHOOK_URLOptional; otherwise captured in memory
Per-Project client-view noticesSLACK_BOT_TOKENRequired outside the harness; creates private Project channels
Dash0 endpointDASH0_ENDPOINTOptional staging-only integration declaration
Dash0 datasetDASH0_DATASETRequired with DASH0_ENDPOINT
Dash0 tokenDASH0_TOKENEncrypted Secret Manager input; required with DASH0_ENDPOINT
DocuSign endpointDOCUSIGN_BASE_URLDeclares DocuSign; demo in dev, live in production
DocuSign accountDOCUSIGN_ACCOUNT_IDEnvironment-specific account
DocuSign JWT IDsDOCUSIGN_INTEGRATION_KEY, DOCUSIGN_USER_IDPreferred auth path
DocuSign JWT proofDOCUSIGN_PRIVATE_KEY, DOCUSIGN_OAUTH_BASEPreferred auth path
DocuSign static authDOCUSIGN_ACCESS_TOKENShort-lived fallback
DocuSign signerDOCUSIGN_SIGNER_EMAIL, DOCUSIGN_SIGNER_NAMERequired signer identity
DocuSign webhookDOCUSIGN_HMAC_KEY, DOCUSIGN_WEBHOOK_SECRETRequired once DOCUSIGN_BASE_URL is set
Xero tenantXERO_TENANT_ID, XERO_BASE_URLAll Xero values select real billing
Xero OAuth clientXERO_CLIENT_ID, XERO_CLIENT_SECRETOtherwise stub billing
Xero OAuth tokenXERO_TOKEN_URL, XERO_SCOPE, XERO_ACCESS_TOKENOtherwise stub billing