static_

Configuration

site.json

key purpose
siteName, description, author, locale basics (locale such as en-GB)
timezone IANA zone for collection dates and times, e.g. Europe/London (default UTC)
url production origin (https://example.com); needed for canonicals, sitemap, RSS and structured data
cleanUrls false, true, or "extensionless"
defaultTheme starting colour theme: "light", "dark" or "system" (default, follows the visitor's device)
icon, themeColor, themeColorDark favicon and apple-touch icon, plus light and dark theme-color
titleSeparator between page and site name in <title> (default " | ")
schema "Person", "Organization" or { "type": "LocalBusiness", telephone, address, geo, openingHours }
social { twitter, github }, used for sameAs and twitter:site
defaultImage default Open Graph image
bodyClass classes for <body> when the layout does not render <html> itself
navigation [{ slug, title }]; href overrides the link
collections per-collection options, see Blog & collections
deploy { target: "netlify" or "cloudflare", project }, see Deploying
redirects [{ from, to, status }] written to _redirects
csp optional Content-Security-Policy header value

Data files

Every data/*.json other than site.json is available in templates as data.<name>: data/apps.json is data.apps. Use them with v-for, or to generate pages (data-driven pages).

.env files

Loaded Vite-style, lowest to highest precedence:

  1. .env
  2. .env.local (keep out of git)
  3. .env.<mode>, where mode is development for static dev and production for build and deploy
  4. .env.<mode>.local

Real environment variables (for example in CI) override all of the files.

What reaches the HTML

  • Templates only see PUBLIC_* variables, as env.PUBLIC_NAME. A secret in .env cannot leak into a page by accident.
  • Any string in site.json or data/*.json may use ${VAR} or ${VAR:-fallback}. Writing that reference is the explicit opt-in to putting a value into the output.
  • Never put a secret in a PUBLIC_* variable or reference one from JSON.

What .env is good for

Build-time and deploy-time secrets: CLOUDFLARE_API_TOKEN, NETLIFY_AUTH_TOKEN, a remote data source token. static deploy loads the project's .env files for the deploy tool. The built site is static, so a browser form cannot safely hold a secret. Anything that needs one has to run on a server or in an app you control (see Microblogging).

# .env
SITE_URL=https://example.com
PUBLIC_CONTACT_EMAIL=hello@example.com

# .env.local (git-ignored)
CLOUDFLARE_API_TOKEN=...
CLOUDFLARE_ACCOUNT_ID=...