Operations Runbook
Procedures for operating Lite Claw in production.Token Rotation
Google OAuth Client Secret
When rotating the OAuth client secret:1
Update in Google Cloud Console
Generate a new client secret in APIs & Services → Credentials.
2
Update in Railway
Set new
GOOGLE_OAUTH_CLIENT_SECRET value.3
Redeploy worker
Trigger a new deployment.
4
Verify
Test
/integrations connect calendar with a test account.Token Encryption Key
1
Generate new key
2
Update TOKEN_ENCRYPTION_KEY in Railway
3
Redeploy
4
Notify users to reconnect
Incident Response
Suspected Token Compromise
If you suspect OAuth tokens have been compromised:1
Disconnect integrations immediately
2
Revoke in Google
Go to Google Account Security and revoke the app’s access.
3
Rotate secrets
- Rotate
GOOGLE_OAUTH_CLIENT_SECRET - Rotate
TOKEN_ENCRYPTION_KEY
4
Redeploy and reconnect
After redeploying, reconnect integrations through the OAuth flow.
Claim Code Abuse
If you see unauthorized claim attempts:1
Rotate OWNER_CLAIM_CODE
Generate a new claim code and update in Railway.
2
Audit database
Check
ownership_state and whitelist tables for unauthorized entries.3
Remove unauthorized users
Delete any unauthorized IDs from the whitelist.
4
Check audit logs
Look for
claim_failed_invalid_code spikes in audit_log.Heartbeat Troubleshooting
Quick Checks
- Verify cron services are running and calling
pnpm heartbeat:run - Check user timezone in
user_profiles.timezone - Check schedule in
heartbeat_jobs.schedule_cron
Log Interpretation
Common Issues
Heartbeats not sending
Heartbeats not sending
- Check cron service is deployed and running
- Verify
HEARTBEAT_JOB_TYPEis set correctly - Check user has heartbeats enabled (
/heartbeats) - Verify timezone is set in user profile
Duplicate heartbeats
Duplicate heartbeats
- Check Redis connection (
UPSTASH_REDIS_REST_URL) - Verify slot key TTL is working
- Check for multiple cron service instances
Wrong time delivery
Wrong time delivery
- Check
user_profiles.timezonevalue - Verify server time vs user expectation
- Check cron expression in
heartbeat_jobs.schedule_cron
Monitoring
Key Metrics
Recommended Checks
Daily:- Scan error logs for exceptions
- Check heartbeat delivery counts
- Review OAuth token refresh success rate
- Check claim attempt patterns
- Verify cron job execution history