diff --git a/README.md b/README.md index 62e052b..dfe1061 100644 --- a/README.md +++ b/README.md @@ -51,14 +51,14 @@ children are dispatched `model:"fable"` (they carry reflection). ```bash # 1. Clone with submodules -git clone --recurse-submodules git@github.com:youruser/claude-config.git -cd claude-config +git clone --recurse-submodules https://github.com/bchanot/claude +cd claude # 2. Bootstrap (CLI + auth + symlinks + plugins) -bash install.sh +make install # 3. Verify setup -bash doctor.sh +make doctor # 4. Restart Claude Code — plugins load automatically ``` @@ -221,10 +221,8 @@ in `env`, `command`, `args`, `url`, and `headers` — for both project (`.mcp.js and user (`~/.claude.json`) scope. Use that instead of a literal value: ```bash -# WRONG — plaintext key lands in ~/.claude.json: -claude mcp add magic --scope user --env API_KEY="$MAGIC_API_KEY" -- npx -y @21st-dev/magic@latest - -# RIGHT — single-quoted so bash doesn't expand it; Claude Code expands it at +MAGIC_API_KEY= +# single-quoted so bash doesn't expand it; Claude Code expands it at # launch, reading the var from its own process environment: claude mcp add magic --scope user --env 'API_KEY=${MAGIC_API_KEY}' -- npx -y @21st-dev/magic@latest ``` @@ -242,6 +240,26 @@ There is no `claude mcp add` flag that writes the reference form for you — the `${VAR}` syntax has to be typed by hand (or via a wrapper script), same as above. +### SEO data layer (`/seo` FULL) — Google OAuth + CrUX keys + +The same `~/.claude/.env` also feeds `lib/seo-data`, which pulls real Google +Search Console and Chrome UX Report data into `/seo` FULL audits. Add these +three vars (template with the GCP console steps in `.env.example`): + +```bash +# OAuth Desktop client — GCP console → APIs & Services → Credentials → +# OAuth client (Desktop). Consent scope: webmasters.readonly only. +GOOGLE_OAUTH_CLIENT_ID= +GOOGLE_OAUTH_CLIENT_SECRET= +# CrUX + PageSpeed API key — GCP console → Credentials → API key, +# restricted to those two APIs. https://developer.chrome.com/docs/crux/api +CRUX_API_KEY= +``` + +Then run the one-time consent flow: `make seo-connect` (per-label token +store, multi-site safe). Missing credentials never break an audit — `/seo` +degrades gracefully to anonymous PageSpeed lab data. + ### magic MCP (`@21st-dev/magic`) — known callback-injection risk `21st_magic_component_builder` opens an **unauthenticated** local callback