Backend Mode

MySQL is the primary database for everything. Apps Script / Sheets is a backup the app only reaches automatically when MySQL doesn't answer — never for a real rejection (wrong data, validation error), only for a connectivity failure. The two "Force" modes below are for Admin testing/diagnosis only — neither one falls back automatically, so a real failure shows up as a real failure instead of being quietly covered.

Live connectivity — pings both backends directly, bypassing routing:

Manual data sync between the two stores (independent of the mode above — use if Sheets picked up changes while forced on, or to refresh Sheets as a backup):

Database Diagnostics

Read-only checks against MySQL: orphaned foreign keys, missing required fields, duplicate leads, and housekeeping. Safe to run anytime, works regardless of which backend mode is currently active.

MySQL Sync (Apps Script side)

Used only by the Sheets → MySQL direction above. DB API Base must match db-api's real URL; the shared secret here must exactly match db-api/config.php's own shared_secret (below) — two independent systems, shown side by side so they're easy to keep matched.

Google Apps Script / Sheets

The Web App /exec URL is used in three places — this writes it to all three at once.
Writes to assets/js/api.js, db-api/config.php, and documents-api/config.php together.
Never shown once saved — only whether one is currently set. Paste a new one only to replace it.
Must be outside public_html.

Lives in the Apps Script project (Script Properties), not a file — saved separately. Must exactly match documents-api's Shared Secret below.
Also lives in Script Properties — server-to-server calls only (deleting/listing files on disk).

MySQL Database (db-api/config.php)

Independent from the Hostinger/documents-api secret above by design — a leak of one shouldn't expose the other.

Documents / Storage (documents-api/config.php)

Kept in sync with assets/js/api.js's MAX_UPLOAD_BYTES automatically.
Must exactly match the Hostinger Shared Secret in the Apps Script section above.

Frontend

Ships to every visitor's browser like any frontend key — not a true secret, restricted by domain instead.

AI Provider (db-api/config.php)

Powers AI Assist / Smart Sweep, Quick Capture, and the Property Dossier. With nothing set here, those features fall back to a "copy this prompt into any chatbot, paste the answer back" manual flow that needs no key at all — so this section is optional, not required to use the CRM.
Never shown once saved — only whether one is currently set, and its last 4 characters. Rotate a compromised key by pasting a new one here; a blank field always means "leave unchanged," never "clear it."