Skip to main content

Configuration

Everything comes from the environment.

Locally, .env.development has what pnpm dev needs, and .env.development.local overrides it.

Where it is served

Variable
FG_ID_URLThe public URL, before any monolith mount point. Default: the Vercel deployment's domain, else http://localhost:3010.
FG_ID_NAMEThe name on every page, email and passkey prompt. Default Fair Garden. Read when the pages are built, too.

Database

Variable
FG_ID_DATABASE_URLAny Postgres. DATABASE_URL, then POSTGRES_URL, are used when it is not set.
FG_ID_DATABASE_POOL_SIZEDefault 5.
FG_ID_DATA_DIRThe embedded database's files. Default .data/id.
FG_ID_EMBEDDED_DATABASE_PORTDefault 54310.

Email

Variable
FG_ID_SMTP_URLsmtp:// or smtps://, with credentials.
FG_ID_EMAIL_FROMDefault <FG_ID_NAME> <no-reply@<host>>.
FG_ID_MOCK_EMAILtrue to use the mock mailbox on a public host.

Keys

Variable
FG_ID_KEY_ROTATION_DAYSDefault 30.
FG_ID_JWKSSigning keys, instead of the database.
FG_ID_COOKIE_SECRETSCookie secrets, newest first, instead of the database.

Passkeys

Variable
FG_ID_PASSKEY_RP_IDA parent domain, to share passkeys across subdomains.
FG_ID_PASSKEY_ORIGINSMore origins allowed to use them.

Services

FG_ID_SERVICE_<NAME>_*: see Services.

Policy

With none of these, id runs the policy its deployment was built with (.policy/policies.tar.gz, from fg-dist policy use), or its built-in rules when there is none. The FG_POLICY_* settings are shared by every service.

Variable
FG_POLICY_BUNDLEA policy from elsewhere than this deployment's build: a path or https URL, which must be signed. none for the built-in rules.
FG_POLICY_PUBLIC_KEYThe organization's key, which that policy must be signed with: PEM, a JWK or a JWK Set.
FG_POLICY_ALLOW_UNSIGNEDtrue to run an unsigned FG_POLICY_BUNDLE, for trying policy locally.
FG_POLICY_OPA_URLAn OPA server to ask instead.
FG_ID_POLICY_PACKAGEDefault fairgarden/id.
FG_ID_POLICY_LOG_RETENTION_DAYSHow long decisions are kept. Default 400.
FG_ID_POLICY_LOG_STDOUTtrue to also write each decision to standard output, as a JSON line.