Sources and configuration
Configure sign-in, change sources, company context, and APIs.
Sign in
March uses Netlify Identity with Google sign-in. Registration is invite-only,
and a signed-in email must also be listed in MARCH_ALLOWED_EMAILS. The app
fails closed when the allowlist is empty. Local development can use the
development-only MARCH_AUTH_BYPASS=1; it is refused on deploys. Dashboard setup,
session behavior, and the exact auth exceptions are covered by the operator
guide in the repository's docs/operator/ folder.
Sources page
The Sources page has Changes, Context March checks, and the MCP API key section. Its change and context rows are hard-coded fixtures, not live OAuth connections. In particular, the Linear, GitHub, and Notion rows are fixture placeholders and do not represent connected product integrations.
Change sources
The shipped product accepts changes through:
- a manual GitHub pull request check from the Inbox;
- an automatic signed GitHub webhook for merged pull requests; and
- the remote MCP
submit_eventtool for source-agnostic events.
The Sources page is where an owner manages the MCP credential. The fixture rows do not add change-ingestion flows.
Context sources
March checks exactly one configured context mode for product investigations:
MARCH_CONTEXT_PATH: a local directory of company documents; orMARCH_WEB_ROOTS: comma- or newline-separated public web roots.
Do not configure both. Optional MARCH_WEB_MAX_PAGES and
MARCH_WEB_MAX_DEPTH limit web crawling. Product investigations also need
NETLIFY_DB_URL for durable storage and deduplication. The model and background
worker settings are operator concerns, documented in the repository's
docs/operator/ folder.
GitHub and API configuration
For automatic GitHub ingestion, configure GITHUB_WEBHOOK_SECRET and, when
needed, GITHUB_TOKEN; MARCH_GITHUB_REPOS optionally restricts repositories.
The internal POST /api/investigations/from-pr route can additionally accept
Authorization: Bearer <MARCH_API_TOKEN>; the Inbox uses the signed-in session
instead. The MCP endpoint uses generated march_sk_... keys, not
MARCH_API_TOKEN.
Keep secrets in the deployment environment or an uncommitted local .env.
Never put a real key in documentation, source control, or an MCP config shared
with others.
Connect GitHub
GitHub sources are connected from the Sources page. Connect GitHub, choose an account or organization, and select repositories. March only receives access to repositories selected through its GitHub App installation.