Skip to main content

Product decision

Search indexing is opt-in at the app route boundary. The maintained Next.js apps use the shared policy in packages/utils/src/seo-policy.json and the header builder in packages/utils/src/seo.ts. Private routes receive X-Robots-Tag: noindex, nofollow, nosnippet even when an inherited layout has public metadata. Authentication, authorization, RLS, and private storage still control access; search directives do not protect data from a caller. This applies across Web, satellites, internal example apps, and redirect hosts. Private app metadata continues to use NO_INDEX_ROBOTS. The Flutter browser bootstrap is noindex. The paused TanStack Start runtime is not deployed or refreshed by this policy. Before any explicitly authorized resumption, establish preview noindex and canonical ownership; do not expose an indexed duplicate of the live Next.js platform.

Public exceptions

Forms retains its existing author-controlled indexing opt-out: this policy does not force every public form to noindex or reverse an author’s noIndex choice. Eligible does not mean included in a sitemap. Dynamic forms, shops, worlds, and repository pages are not crawled from privileged workspace tables merely to populate discovery feeds.

Crawling, canonical URLs, and previews

robots.txt permits crawlers to observe redirects and noindex responses. Blocking a URL in robots.txt can prevent a crawler from seeing its noindex instruction. Public pages use page-specific canonicals and social metadata. Language alternates are emitted only when distinct stable language URLs exist; apps with localePrefix: never do not invent indexed locale duplicates. Preview and development Next deployments are excluded by the HTTP policy when VERCEL_ENV is preview/development or NODE_ENV is development. Set TUTURUUU_NOINDEX=1 for a non-Vercel staging host and rebuild/redeploy its configuration. Production public routes remain eligible unless that explicit flag is set. A production-domain canonical is not a replacement for preview noindex.

Regression evidence

packages/utils/src/seo.test.ts verifies parsed Next header patterns against private workspaces, auth/API routes, form/embed boundaries, buyer transactions, public education/tool pages, Git integration paths, Tulletin drafts, the generated Web allowlist, and preview behavior. scripts/generate-app-seo.test.js checks sitemap host ownership, truthful locale alternates, and the absence of private sitemaps. Deployment HTML/header inspection and Search Console URL Inspection remain required to establish the served/indexed result. References: Google noindex guidance and content access controls. The SEO runbook explains maintenance. Public Forms metadata explicitly overrides its private root layout for accessible anonymous snapshots when noIndex is false. Protected, unavailable, and opted-out forms retain noindex; embeds and workspace pages always do. Regression coverage: apps/forms/src/features/forms/shared-form-data.test.ts and shared-form-loader.test.ts. This changes discovery metadata, not response access.