Configuration
site.json
| key | purpose |
|---|---|
siteName, description, author, locale | basics (locale such as en-GB) |
timezone | IANA zone for collection dates and times, e.g. Europe/London (default UTC) |
url | production origin (https://example.com); needed for canonicals, sitemap, RSS and structured data |
cleanUrls | false, true, or "extensionless" |
defaultTheme | starting colour theme: "light", "dark" or "system" (default, follows the visitor's device) |
icon, themeColor, themeColorDark | favicon and apple-touch icon, plus light and dark theme-color |
titleSeparator | between page and site name in <title> (default " | ") |
schema | "Person", "Organization" or { "type": "LocalBusiness", telephone, address, geo, openingHours } |
social | { twitter, github }, used for sameAs and twitter:site |
defaultImage | default Open Graph image |
bodyClass | classes for <body> when the layout does not render <html> itself |
navigation | [{ slug, title }]; href overrides the link |
collections | per-collection options, see Blog & collections |
deploy | { target: "netlify" or "cloudflare", project }, see Deploying |
redirects | [{ from, to, status }] written to _redirects |
csp | optional Content-Security-Policy header value |
Data files
Every data/*.json other than site.json is available in templates as data.<name>: data/apps.json is data.apps. Use them with v-for, or to generate pages (data-driven pages).
.env files
Loaded Vite-style, lowest to highest precedence:
.env.env.local(keep out of git).env.<mode>, where mode isdevelopmentforstatic devandproductionforbuildanddeploy.env.<mode>.local
Real environment variables (for example in CI) override all of the files.
What reaches the HTML
- Templates only see
PUBLIC_*variables, asenv.PUBLIC_NAME. A secret in.envcannot leak into a page by accident. - Any string in
site.jsonordata/*.jsonmay use${VAR}or${VAR:-fallback}. Writing that reference is the explicit opt-in to putting a value into the output. - Never put a secret in a
PUBLIC_*variable or reference one from JSON.
What .env is good for
Build-time and deploy-time secrets: CLOUDFLARE_API_TOKEN, NETLIFY_AUTH_TOKEN, a remote data source token. static deploy loads the project's .env files for the deploy tool. The built site is static, so a browser form cannot safely hold a secret. Anything that needs one has to run on a server or in an app you control (see Microblogging).
# .env
SITE_URL=https://example.com
PUBLIC_CONTACT_EMAIL=hello@example.com
# .env.local (git-ignored)
CLOUDFLARE_API_TOKEN=...
CLOUDFLARE_ACCOUNT_ID=...