diff --git a/.env.example b/.env.example
index d9df30a..f5d6216 100644
--- a/.env.example
+++ b/.env.example
@@ -13,3 +13,16 @@ NUXT_OG_IMAGE_SECRET=
# Get it from: GA4 property → Admin → Data Streams → Web stream → Measurement ID.
# Leave empty to disable analytics entirely (no script loaded, no consent banner).
NUXT_PUBLIC_GA_MEASUREMENT_ID=
+
+# Backend URL for the /dash-api proxy (server-side only, never sent to browser).
+# In production, point this to the internal API address (e.g. http://schedule-api:8080).
+# Default: http://localhost:8080
+NUXT_DASH_API_BASE_URL=
+
+# Shared secret sent as x-dash-key to the backend. Must match DASH_API_KEY in schedule-api.
+# Generate with: openssl rand -hex 32
+NUXT_DASH_API_KEY=change_me_to_a_strong_random_secret
+
+# HTTP Basic Auth credentials for the /dash page (browser prompt).
+NUXT_DASH_USER=admin
+NUXT_DASH_PASSWORD=change_me
diff --git a/app/layouts/dash.vue b/app/layouts/dash.vue
new file mode 100644
index 0000000..312873a
--- /dev/null
+++ b/app/layouts/dash.vue
@@ -0,0 +1,9 @@
+
+