# ClearAI Brain + Agent v0.1.0 architecture

A standalone companion service for ClearAI PHP v1.2.1; no changes to the original ClearAI site.

Compatibility audit of the supplied v1.2.1 source:
- `inc/core.php`: single-admin PHP session auth, private JSON `storage/db.json`, atomic save and existing encrypted provider keys.
- `inc/providers.php`: streamed OpenAI-compatible, Anthropic and demo adapters.
- `inc/platform.php`: the current Agent Workspace stores plans; it does not run autonomous jobs.
- `inc/apps.php`: contains existing calculator, search and other app tools.
- API bridge MUST be called from authenticated PHP backend, not JavaScript/browser. Do not send ClearAI API key to frontend.

This standalone service intentionally has its own JSON datastore to work without SQLite/MySQL or PHP extensions. Store it OUTSIDE web root. It provides authenticated JSON POST routes to create memories, ingest knowledge, query context, route configured models, and run limited audited agent steps with approvals. It does not use or replace ClearAI's existing chats or provider credentials. Owners must explicitly configure models, endpoints and permissions. It does not train model weights. Existing private ClearAI users/chats are not imported automatically.

Production architecture: ClearAI PHP server --HTTPS + scoped Bearer token--> this companion service. Set the hostname to a separately secured subdomain; never expose Bearer token in client JS. Install the service with document root `public/`. For Apache with document root at package root a deny-first `.htaccess` fallback is supplied; Nginx must point directly at `public/`.
