# Mindstone production for Replit apps (guide v12)

Mindstone apps are built in Replit and run in production on Mindstone's Google
Cloud (EU). Replit Publish is staging only (a preview with its own database —
test data only). Each app talks to the Mindstone
platform API with an app key in the Replit secret MINDSTONE_REPLIT_API_KEY. The optional
"Mindstone Deployment" MCP server (per-user connection) offers the same
operations as tools.

API (base https://replit.mindstone.com/api/v1, header "Authorization: Bearer $MINDSTONE_REPLIT_API_KEY"):
  GET   /app            status: production URL, config (secret names only), recent deploys
  GET   /app/plan       what production would build/route/run + blockers  (?ref=branch|sha)
  PATCH /app/config     {"env":{...}, "secrets":[NAMES], "envIgnore":[...], "removeEnv":[...], ...}
  POST  /app/deploys    deploy {"sha":"<git rev-parse HEAD>"} — refused unless GitHub has that commit
  POST  /app/git-token  short-lived (1h) token that can push to this app's repo only
  GET   /app/logs       production logs (?minutes=60&severity=ERROR&contains=text)
  GET   /app/replit-md  the current replit.md section for this app

Rules
- Database: Postgres + Drizzle, driver `pg` (node-postgres), not @neondatabase/serverless.
  Production has its own database; never set a production DATABASE_URL. The Drizzle
  schema is the source of truth — additive changes apply on deploy, destructive ones
  need a Mindstone admin.
- Secrets: never put secret values in code, config, chat or API calls. Declare the
  NAME via PATCH /app/config; a Mindstone admin sets the production value.
- Every process.env.X the code reads must be configured (env / secrets / envIgnore)
  — GET /app/plan lists any that aren't.
- Don't use Replit-only services in app code (Replit Auth, Object Storage, REPLIT_* env).
- Listen on process.env.PORT; with Express set app.set("trust proxy", 1).
- Never print or echo $MINDSTONE_REPLIT_API_KEY.
