# --------------------------------------------------------------------------- # Schulcloud instance # --------------------------------------------------------------------------- # Base URL of the instance, no trailing slash. TSC_URL=https://schulcloud-thueringen.de # The value of the `jwt` cookie from a logged-in browser session. # The 30-day `exp` is only a ceiling; the real limit is a 2-hour sliding session # TTL that the built-in keepalive holds open. IMPORTANT: close the Schulportal # window after copying this — an open tab shares the session and its auto-logout # will revoke this token ~2h after login. See docs/AUTH.md. TSC_JWT_COOKIE= # --------------------------------------------------------------------------- # This MCP server # --------------------------------------------------------------------------- # Shared secret callers must present as `Authorization: Bearer `. # REQUIRED for the public deployment — without it the endpoint is open to # anyone who finds the hostname. Generate one with: # openssl rand -hex 32 MCP_AUTH_TOKEN= # Listen address inside the container. Leave as-is when running behind Caddy. PORT=8080 BIND_HOST=0.0.0.0 # --------------------------------------------------------------------------- # Limits (optional — sensible defaults are built in) # --------------------------------------------------------------------------- # Largest file download_file will pull, in bytes. Default 25 MiB. # Videos in Schulcloud routinely exceed this; they are not extractable anyway. # MAX_DOWNLOAD_BYTES=26214400 # Characters of extracted text returned before truncation. Default 120000. # MAX_EXTRACTED_CHARS=120000 # Per-request timeout against the Schulcloud API, in ms. Default 30000. # REQUEST_TIMEOUT_MS=30000 # How often to call refresh-session to hold the session open, in ms. Default # 1800000 (30 min). Must stay well under the instance's JWT_TIMEOUT_SECONDS — # 7200s here, readable from GET /api/v3/config/public. Set to 0 to disable. # KEEPALIVE_INTERVAL_MS=1800000