Dealer-controlled: --primary-button-color / -hover and their text colors, --button-border-radius, and --form-button-text-transform (CTA casing). Secondary and tertiary fills are widget-owned. Disabled flattens the box to gray-4 and keeps the variant's label color; there is no pressed style in the code. The private aliases are declared on .rt-app, matching .app in App.module.pcss — the element an external embed writes dealershipConfig.branding onto. So host variables go at :root (a Space website) or on a .rt-app element (an external embed), never on an inner wrapper: the override row below is itself a nested .rt-app, which is why it resolves.
Two deliberate deviations: the twin sets font-family: var(--primary-font) on .rt-btn, while the widget never resets font-family on button — so live buttons render in the browser default (Arial in Chrome) although the rest of the widget is Inter; the twin follows code intent and the live mismatch is an engineering bug. And the twin centers the label with flex and clips the Pill shimmer with overflow: hidden, where the code reaches the same result through default button layout and an absolutely positioned shimmer element.