# ORBIT cross-device sync setup

## Current setup

- The ORBIT Supabase project has been created in West Europe (London).
- The `orbit_user_state` table and row-level security policies are installed. Signed-in users can only read and edit their own state.
- Authentication's Site URL and allowed redirect URL point to `https://orbit-assistant-preview.pages.dev/`.
- `orbit-config.js` contains the project URL and browser-safe publishable key. It does not contain a secret key.

## Next step: publish the app files

Upload these four files from this folder to the existing ORBIT Cloudflare Pages project:

- `index.html`
- `orbit-config.js`
- `orbit-sync-setup.sql`
- `ORBIT-cloud-sync-guide.md`

Then open the live ORBIT site, choose **Connect**, enter your email, and use the sign-in link on that same device. After signing in, ORBIT should show a synced status. Use the same email on another device to access the same tasks and notes.

Supabase's built-in email sender can have strict limits. If a sign-in email is delayed or blocked, stop retrying and wait before requesting another. Custom SMTP can be configured later.

## Security note

The publishable key is intended for browser apps. Never place a `secret` or `service_role` key in `orbit-config.js` or the website. Row-level security protects each account's data.
