# DeskcommCRM | Rafael Melgaço | Knowledge Base | Instagit

Open-source AI sales OS — self-hosted CRM with native AI agents + WhatsApp (WAHA). Open alternative to Kommo, Octadesk & Intercom for any business that sells by chat. MCP-ready, multi-tenant, LGPD.

GitHub Stars: 1.8k

Repository: https://github.com/melgarafael/DeskcommCRM

---

## Articles

### [How hostgator-setup-kit/install.sh Validates Environment Variables One at a Time](/melgarafael/DeskcommCRM/hostgator-setup-kit-install-sh-environment-variable-validation)

Discover how hostgator-setup-kit/install.sh validates environment variables individually. Learn about its recursive prompts and validation functions for robust setup.

- Tags: how-to-guide
- Published: 2026-09-13

### [How Server Actions and REST Route Handlers Differ in Authentication Surface](/melgarafael/DeskcommCRM/server-actions-app-actions-authentication-vs-api-route-handlers)

Discover the authentication differences between Server Actions and REST Route Handlers. Learn how each handles security for your Next.js app and API routes.

- Tags: deep-dive
- Published: 2026-09-13

### [How DeskcommCRM SPECS_PARTE Lists Gate New Playwright Specs in CI](/melgarafael/DeskcommCRM/e2e-yml-specs-parte-playwright-spec-gating)

Learn how DeskcommCRM SPECS_PARTE lists gate new Playwright specs in CI. Understand the e2e.yml workflow and spec whitelisting for efficient testing.

- Tags: how-to-guide
- Published: 2026-09-13

### [How `pnpm test:db` Spins Up an Ephemeral PostgreSQL 15 Container to Run RLS Cross-Tenant Invariants](/melgarafael/DeskcommCRM/pnpm-test-db-ephemeral-pg15-container-rls-invariants)

Learn how pnpm test:db spins up an ephemeral PostgreSQL 15 container using Docker to test Row-Level Security policies and prevent cross-tenant data leakage with Vitest.

- Tags: internals
- Published: 2026-09-13

### [How Postgres Migrations Are Versioned in supabase/migrations/ and Replicated in supabase/baseline.sql](/melgarafael/DeskcommCRM/postgres-migrations-versioning-supabase-baseline-sql)

Discover how DeskcommCRM versions Postgres migrations using supabase/migrations/ and replicates them in supabase/baseline.sql. Ensure reproducible database installations with this three-artifact doctrine.

- Tags: how-to-guide
- Published: 2026-09-13

### [How Sentry's beforeSend Hook Scrubs PII Before Reports Are Sent in DeskcommCRM](/melgarafael/DeskcommCRM/sentry-10-beforesend-pii-scrubbing-report-sending)

Learn how DeskcommCRM uses Sentry beforeSend hooks to scrub PII like CPF numbers and emails before sending error reports. Protect sensitive data with this guide.

- Tags: how-to-guide
- Published: 2026-09-13

### [How the LGPD PDF Export Flow Uses LGPD_SIGNING_KEY and organizations.legal_name in DeskcommCRM](/melgarafael/DeskcommCRM/lgpd-pdf-flow-signing-key-legal-name-data-export)

Explore how DeskcommCRM's LGPD PDF export uses LGPD_SIGNING_KEY and organizations.legal_name for secure data signing. Learn about digital signatures and integrity hashing.

- Tags: how-to-guide
- Published: 2026-09-13

### [How requireRole Composes with requirePlatformAdmin for RBAC in DeskcommCRM](/melgarafael/DeskcommCRM/require-role-requireplatformadmin-composition-rbac-matrix)

Understand how requireRole composes with requirePlatformAdmin for DeskcommCRM RBAC. Explore two-layer role enforcement and platform admin bypass for robust access control.

- Tags: architecture
- Published: 2026-09-13

### [How DeskcommCRM Enforces AI Guardrails to Prevent Hallucinated Prices and Unsafe Tool Calls](/melgarafael/DeskcommCRM/ai-guardrails-hallucinated-prices-unsafe-tool-calls)

DeskcommCRM enforces AI guardrails to prevent hallucinated prices and unsafe tool calls. Learn how its dual-layer system validates monetary promises and blocks unauthorized tool executions before they happen.

- Tags: how-to-guide
- Published: 2026-09-13

### [How AI Guardrails Prevent Prompt Injection in DeskcommCRM: A Deep Dive into lib/agent-engine/ and lib/ai/](/melgarafael/DeskcommCRM/ai-guardrails-enforcement-prompt-injection-prevention)

Discover how AI guardrails in DeskcommCRM's lib agent-engine and lib ai prevent prompt injection. Learn about synchronous before-send checks for secure LLM interactions.

- Tags: deep-dive
- Published: 2026-09-13

### [How Vercel AI Gateway Tracks Cost and Token Usage in DeskcommCRM](/melgarafael/DeskcommCRM/vercel-ai-gateway-cost-token-usage-tracking)

Discover how Vercel AI Gateway automatically tracks cost and token usage for DeskcommCRM. Gain insights into your AI expenses without custom infrastructure.

- Tags: how-to-guide
- Published: 2026-09-13

### [How Vercel AI Gateway Routes Requests Across Anthropic, OpenAI, and Google Models in DeskcommCRM](/melgarafael/DeskcommCRM/vercel-ai-gateway-routing-ai-sdks-anthropic-openai-google)

Learn how DeskcommCRM uses Vercel AI Gateway to route requests to Anthropic, OpenAI, and Google models with a four-tier fallback. Simplify your AI integration.

- Tags: how-to-guide
- Published: 2026-09-13

### [Which Routes Does the Rate Limiter in lib/auth/rate-limit.ts Cover in DeskcommCRM?](/melgarafael/DeskcommCRM/rate-limiter-routes-coverage-deskcommcrm)

Discover the five authentication routes protected by the rate limiter in lib/auth/rate-limit.ts for DeskcommCRM: login, signup, password reset, and more. Learn how it enhances security.

- Tags: api-reference
- Published: 2026-09-13

### [How the DeskcommCRM Authentication Rate Limiter Combines Upstash Redis with In-Memory Fallback](/melgarafael/DeskcommCRM/rate-limiter-redis-in-memory-fallback-implementation)

Discover how DeskcommCRM's rate limiter seamlessly integrates Upstash Redis with an in-memory fallback for robust authentication. Learn about its efficient fallback strategy.

- Tags: internals
- Published: 2026-09-13

### [How the MCP Server Exposes CRM Capabilities Without Leaking Tenant Data](/melgarafael/DeskcommCRM/mcp-server-crm-capabilities-exposure-tenant-data-leakage)

Discover how the MCP server secures CRM capabilities, preventing tenant data leaks with JWT auth, scoped queries, and sanitization. Learn about DeskcommCRM's data protection.

- Tags: architecture
- Published: 2026-09-13

### [Why `marcaDaSaida()` Is the Only Safe Function Call Outside the DOM for Branding](/melgarafael/DeskcommCRM/marca-da-saida-function-safe-call-outside-dom-branding)

Discover why marcaDaSaida() is the sole safe function for branding outside the DOM. It guarantees execution in email workers, PDF generators, and push notifications without exceptions.

- Tags: deep-dive
- Published: 2026-09-13

### [How the White-Label Branding Resolver Merges platform_branding and organizations.settings.branding in DeskcommCRM](/melgarafael/DeskcommCRM/white-label-branding-resolver-platform-branding-env-variables)

Learn how the DeskcommCRM white-label branding resolver merges platform branding and organization settings. Discover its layered configuration system that prioritizes organization specifics over environment variables.

- Tags: internals
- Published: 2026-09-13

### [How DeskcommCRM Schedules, Retries, and Observes Follow-ups Using Workers and Event-Log Consumers](/melgarafael/DeskcommCRM/follow-up-scheduling-retries-event-log-consumer-cron-workers)

Learn how DeskcommCRM schedules, retries, and observes follow-ups using cron workers and event log consumers. Understand the process from cron jobs to agent worker queues.

- Tags: internals
- Published: 2026-09-13

### [WAHA 2026.7.2 NOWEB Engine Integration: Webhook, QR‑Code Onboarding, and Session Persistence in DeskcommCRM](/melgarafael/DeskcommCRM/waha-noweb-engine-webhook-qr-code-onboarding-session-persistence)

Explore WAHA 2026.7.2 NOWEB engine integration with DeskcommCRM. Discover webhook, QR-code onboarding, and session persistence for seamless connectivity.

- Tags: how-to-guide
- Published: 2026-09-13

### [How the Agent-Engine Dispatcher Decides Between AI Response, Human Handoff, or Follow-Up Queuing](/melgarafael/DeskcommCRM/agent-engine-dispatcher-ai-human-handoff-follow-up-queuing)

Discover how the agent-engine dispatcher in DeskcommCRM routes messages. Learn about its decision process for AI responses, human handoffs, or follow-up queuing.

- Tags: internals
- Published: 2026-09-13

### [How the Impersonation Cookie Flows Between Edge Middleware and Database-Backed Support Sessions in DeskcommCRM](/melgarafael/DeskcommCRM/impersonation-cookie-flow-edge-middleware-database-support-session)

Discover how the impersonation cookie flows from Edge middleware to database helpers in DeskcommCRM. Learn about server-side creation, verification, and tenant isolation without altering Supabase sessions.

- Tags: internals
- Published: 2026-09-13

### [Service-Role Handler Pattern in DeskcommCRM: Filtering organization_id and Bypassing RLS](/melgarafael/DeskcommCRM/service-role-handlers-app-api-organization-id-filter-rls-bypass)

Discover the service role handler pattern in DeskcommCRM. Learn to filter organization_id and bypass RLS for secure tenant isolation in your API.

- Tags: internals
- Published: 2026-09-13

### [How the Edge Middleware in proxy.ts Validates Supabase Auth and Injects X‑Request‑Id](/melgarafael/DeskcommCRM/edge-middleware-proxy-ts-supabase-auth-validation-x-request-id)

Learn how proxy.ts edge middleware validates Supabase auth using JWTs and injects X-Request-Id for tracing. Secure your API with this essential guide.

- Tags: how-to-guide
- Published: 2026-09-13

### [How DeskcommCRM Implements Multi-Tenant Row Level Security (RLS) Using JWT Organization ID Propagation](/melgarafael/DeskcommCRM/deskcommcrm-multi-tenant-rls-organization-id-jwt-propagation)

Learn how DeskcommCRM ensures multi-tenant Row Level Security RLS by validating JWTs and injecting organization_id into PostgreSQL session variables for secure data isolation.

- Tags: architecture
- Published: 2026-09-13

### [What Is the Purpose of public-paths.ts in DeskcommCRM's Authentication Flow?](/melgarafael/DeskcommCRM/what-is-the-purpose-of-public-paths-ts-in-deskcommcrm-s-authentication-flow)

Discover the purpose of public-paths.ts in DeskcommCRM's authentication flow. Learn how this file allows specific routes to bypass authentication checks for essential functions.

- Tags: internals
- Published: 2026-09-12

### [How DeskcommCRM Ensures Cross-Tenant Isolation in Its Test Suite: RLS Verification and Service-Role Guards](/melgarafael/DeskcommCRM/how-does-deskcommcrm-ensure-cross-tenant-isolation-in-its-test-suite)

Learn how DeskcommCRM ensures cross-tenant isolation in its test suite. Discover RLS verification and service-role guard strategies for secure multi-tenant data.

- Tags: testing
- Published: 2026-09-12

### [Where to Find DeskcommCRM Architecture and Doctrine Documentation](/melgarafael/DeskcommCRM/where-can-i-find-documentation-on-deskcommcrm-s-architecture-and-doctrine)

Discover DeskcommCRM architecture and doctrine documentation. Access key markdown files ARCHITECTURE.md CLAUDE.md VISION.md AGENTS.md and SECURITY.md directly from the repository root.

- Tags: architecture
- Published: 2026-09-12

### [What Versions of Next.js, React, and TypeScript Are Used in DeskcommCRM](/melgarafael/DeskcommCRM/what-versions-of-nextjs-react-and-typescript-are-used-in-deskcommcrm)

Discover the exact versions of Next.js, React, and TypeScript powering DeskcommCRM. Learn about the stack in this technical overview.

- Tags: getting-started
- Published: 2026-09-12

### [DeskcommCRM Architecture: Deep Dive into the AI-Native Sales CRM Built on Next.js and Supabase](/melgarafael/DeskcommCRM/what-is-the-architecture-of-deskcommcrm-for-ai-native-sales-crm)

Explore the AI-native sales CRM architecture of DeskcommCRM. Learn how Next.js, Supabase, and Vercel AI Gateway power automated conversational sales workflows for enhanced efficiency.

- Tags: architecture
- Published: 2026-09-12

### [How Inbound Captação Webhooks and the AI Dispatcher Are Rate-Limited in DeskcommCRM](/melgarafael/DeskcommCRM/how-are-inbound-captacao-webhooks-and-the-ai-dispatcher-rate-limited-in-deskcommcrm)

Discover how DeskcommCRM rate-limits inbound captação webhooks and the AI dispatcher. Learn about per-IP, per-identifier, and per-tenant throttling strategies.

- Tags: how-to-guide
- Published: 2026-09-12

### [Which Parts of DeskcommCRM Are Not Yet Rate-Limited: A Complete Security Audit](/melgarafael/DeskcommCRM/which-parts-of-deskcommcrm-are-not-yet-rate-limited)

Discover which DeskcommCRM components lack rate limiting. Our security audit reveals exposed internal APIs and CRUD handlers vulnerable to abuse. Understand your risk.

- Tags: security-audit
- Published: 2026-09-12

### [DeskcommCRM External Rate Limiting Using Upstash Redis: Implementation and Configuration Guide](/melgarafael/DeskcommCRM/does-deskcommcrm-support-external-rate-limiting-using-upstash-redis)

Implement external rate limiting for DeskcommCRM with Upstash Redis. This guide details the fixed-window counter and fallback to in-memory storage.

- Tags: how-to-guide
- Published: 2026-09-12

### [Rate-Limiting Strategy in DeskcommCRM: Fixed-Window Protection with Redis](/melgarafael/DeskcommCRM/what-is-the-rate-limiting-strategy-in-deskcommcrm-and-what-actions-does-it-cover)

Discover DeskcommCRM's fixed-window rate-limiting strategy using Redis to protect authentication endpoints. Learn about IP and identifier limits against brute-force attacks.

- Tags: internals
- Published: 2026-09-12

### [How DeskcommCRM Handles Plaintext WAHA Bearer Tokens: Security, Storage, and Implementation](/melgarafael/DeskcommCRM/how-are-plaintext-bearer-tokens-handled-and-stored-for-waha-integration-in-deskcommcrm)

Discover how DeskcommCRM secures plaintext WAHA bearer tokens by storing them in memory for runtime use only, never on disk or logs. Learn about implementation.

- Tags: security
- Published: 2026-09-12

### [How DeskcommCRM Secures WAHA Webhooks with HMAC Verification](/melgarafael/DeskcommCRM/how-are-inbound-waha-webhooks-secured-with-hmac-verification-in-deskcommcrm)

Learn how DeskcommCRM secures WAHA webhooks with SHA-512 HMAC verification for robust cryptographic authentication. Explore the webhook-auth.ts file and configure strict mode.

- Tags: how-to-guide
- Published: 2026-09-12

### [How DeskcommCRM Integrates with WhatsApp Using WAHA: A Technical Deep Dive](/melgarafael/DeskcommCRM/how-does-deskcommcrm-integrate-with-whatsapp-using-waha)

Discover how DeskcommCRM integrates with WhatsApp via WAHA using a three-layer TypeScript architecture. Learn about session management, channel adapters, and graceful degradation for seamless communication.

- Tags: deep-dive
- Published: 2026-09-12

### [How the CI Job in DeskcommCRM Ensures Idempotent Database Migrations](/melgarafael/DeskcommCRM/how-does-the-ci-job-in-deskcommcrm-ensure-idempotency-of-database-migrations)

Discover how the DeskcommCRM CI job guarantees idempotent database migrations through isolated invariant checks, ensuring data integrity and reliable updates.

- Tags: how-to-guide
- Published: 2026-09-12

### [Why Revoke Execute Permissions on New Public Schema Functions in DeskcommCRM](/melgarafael/DeskcommCRM/why-is-it-important-to-revoke-execute-permissions-on-new-public-schema-functions-in-deskcommcrm)

Learn why revoking execute permissions on DeskcommCRM public schema functions is crucial. Protect against privilege escalation, data leaks, and DoS attacks.

- Tags: best-practices
- Published: 2026-09-12

### [How DeskcommCRM Manages Database Schema Changes for Self‑Hosted Deployments](/melgarafael/DeskcommCRM/how-are-database-schema-changes-managed-and-applied-in-deskcommcrm-for-self-hosters)

Learn how DeskcommCRM manages database schema changes for self-hosted deployments using versioned migrations, idempotent DDL, and manifest files. Ensure smooth initialization for your instance.

- Tags: how-to-guide
- Published: 2026-09-12

### [Understanding the DeskcommCRM Migration Triad: Baseline SQL, MANIFEST, and Versioned Files](/melgarafael/DeskcommCRM/what-is-the-purpose-of-the-migration-triad-in-deskcommcrm-versioned-files-baseline-and-manifest)

Discover the DeskcommCRM migration triad: baseline SQL, MANIFEST, and versioned files. Learn how this dual-path system streamlines database setup and upgrades.

- Tags: internals
- Published: 2026-09-12

### [How DeskcommCRM Handles Branding in Non-DOM Contexts: Email & MFA Rendering](/melgarafael/DeskcommCRM/how-does-deskcommcrm-handle-branding-in-non-dom-contexts-like-emails)

Discover how DeskcommCRM manages branding for emails and MFA. Learn about its output branding layer and marcaDaSaida function for consistent visual identity.

- Tags: deep-dive
- Published: 2026-09-12

### [How Branding Resolution Sources Are Prioritized in DeskcommCRM](/melgarafael/DeskcommCRM/how-are-branding-resolution-sources-prioritized-in-deskcommcrm)

Discover how DeskcommCRM prioritizes branding resolution sources. Learn about the four-layer stack and field-by-field precedence for consistent branding.

- Tags: internals
- Published: 2026-09-12

### [White-Label Branding Strategy in DeskcommCRM: How to Remove "Deskcomm" from the UI](/melgarafael/DeskcommCRM/what-is-the-strategy-for-white-label-branding-in-deskcommcrm-to-avoid-mentioning-deskcomm)

Implement white-label branding in DeskcommCRM using environment variables and database settings. Remove 'Deskcomm' at runtime with code-free configuration and automated tests for a seamless user experience.

- Tags: how-to-guide
- Published: 2026-09-12

### [How DeskcommCRM Implements Role-Based Access Control (RBAC)](/melgarafael/DeskcommCRM/how-is-role-based-access-control-rbac-implemented-in-deskcommcrm)

Discover how DeskcommCRM implements Role-Based Access Control RBAC with a centralized guard token validation tenant context role fetching Supabase RPC and MFA checks.

- Tags: how-to-guide
- Published: 2026-09-12

### [Edge Authentication in DeskcommCRM: How Request IDs Are Handled](/melgarafael/DeskcommCRM/where-is-edge-authentication-implemented-in-deskcommcrm-and-how-is-the-request-id-handled)

Discover how DeskcommCRM handles edge authentication using request IDs in its proxy middleware. Learn about JWT validation with Supabase and ID propagation.

- Tags: deep-dive
- Published: 2026-09-12

### [How DeskcommCRM Bypasses Row-Level Security (RLS) Using the Admin Supabase Client](/melgarafael/DeskcommCRM/how-does-deskcommcrm-handle-bypassing-rls-with-the-admin-supabase-client)

Discover how DeskcommCRM bypasses Row-Level Security RLS using the admin Supabase client. Learn to manage data access securely in trusted backend contexts.

- Tags: how-to-guide
- Published: 2026-09-12

### [Canonical Supabase Clients in DeskcommCRM: Admin, Server, and Browser Patterns](/melgarafael/DeskcommCRM/what-are-the-canonical-supabase-clients-exposed-in-deskcommcrm-and-their-uses)

Discover the three canonical Supabase clients in DeskcommCRM Admin Server and Browser Each client enforces strict security for Supabase operations

- Tags: architecture
- Published: 2026-09-12

### [How DeskcommCRM Enforces Multi-Tenancy Using Supabase RLS Policies](/melgarafael/DeskcommCRM/how-is-multi-tenancy-enforced-in-deskcommcrm-using-supabase-rls)

Learn how DeskcommCRM enforces multi-tenancy with Supabase RLS policies. Discover how organization boundaries are protected in PostgreSQL for secure data isolation.

- Tags: how-to-guide
- Published: 2026-09-12

