March docs

Sources and configuration

Configure sign-in, change sources, company context, and APIs.

Sign in

March uses Netlify Identity with Google sign-in. Registration is invite-only, and a signed-in email must also be listed in MARCH_ALLOWED_EMAILS. The app fails closed when the allowlist is empty. Local development can use the development-only MARCH_AUTH_BYPASS=1; it is refused on deploys. Dashboard setup, session behavior, and the exact auth exceptions are covered by the operator guide in the repository's docs/operator/ folder.

Sources page

The Sources page has Changes, Context March checks, and the MCP API key section. Its change and context rows are hard-coded fixtures, not live OAuth connections. In particular, the Linear, GitHub, and Notion rows are fixture placeholders and do not represent connected product integrations.

Change sources

The shipped product accepts changes through:

  • a manual GitHub pull request check from the Inbox;
  • an automatic signed GitHub webhook for merged pull requests; and
  • the remote MCP submit_event tool for source-agnostic events.

The Sources page is where an owner manages the MCP credential. The fixture rows do not add change-ingestion flows.

Context sources

March checks exactly one configured context mode for product investigations:

  • MARCH_CONTEXT_PATH: a local directory of company documents; or
  • MARCH_WEB_ROOTS: comma- or newline-separated public web roots.

Do not configure both. Optional MARCH_WEB_MAX_PAGES and MARCH_WEB_MAX_DEPTH limit web crawling. Product investigations also need NETLIFY_DB_URL for durable storage and deduplication. The model and background worker settings are operator concerns, documented in the repository's docs/operator/ folder.

GitHub and API configuration

For automatic GitHub ingestion, configure GITHUB_WEBHOOK_SECRET and, when needed, GITHUB_TOKEN; MARCH_GITHUB_REPOS optionally restricts repositories. The internal POST /api/investigations/from-pr route can additionally accept Authorization: Bearer <MARCH_API_TOKEN>; the Inbox uses the signed-in session instead. The MCP endpoint uses generated march_sk_... keys, not MARCH_API_TOKEN.

Keep secrets in the deployment environment or an uncommitted local .env. Never put a real key in documentation, source control, or an MCP config shared with others.

Connect GitHub

GitHub sources are connected from the Sources page. Connect GitHub, choose an account or organization, and select repositories. March only receives access to repositories selected through its GitHub App installation.

On this page