Environment Variables
All environment variables of the EUDIPLO backend, generated from its validation
schema. The backend refuses to start when a value is invalid or a required
variable is missing. KMS providers and the registrar are configured in JSON
files instead (KMS config, Registrar);
the variables of the eudiplo CLI are listed in the
CLI guide.
Authentication
| Key | Type | Allowed values | Notes |
|---|---|---|---|
OIDC | string | - | Enable OIDC mode [optional] |
OIDC_INTERNAL_ISSUER_URL | string | - | Internal issuer URL in OIDC mode [optional] [when OIDC is set → then default=undefined] |
OIDC_CLIENT_ID | any | - | Client ID for OIDC [optional] [when OIDC is set → then required] |
OIDC_CLIENT_SECRET | any | - | Client secret for OIDC [optional] [when OIDC is set → then required] |
OIDC_SUB | any | - | Claim to use as subject [optional] [when OIDC is set → then default="tenant_id"] |
OIDC_ALGORITHM | any | - | Expected JWT alg [optional] [when OIDC is set → then default="RS256"] |
MASTER_SECRET | any | - | Master secret for JWT signing and encryption key derivation - required, minimum 32 characters [optional] [when OIDC is set → otherwise required] |
JWT_ISSUER | any | - | Local JWT issuer [optional] [when OIDC is set → otherwise default="eudiplo-service"] |
JWT_EXPIRES_IN | any | - | Local JWT expiration [optional] [when OIDC is set → otherwise default="24h"] |
AUTH_CLIENT_SECRET | any | - | Client secret (local auth). In OIDC mode, optional bootstrap secret used to create/update a Keycloak admin/root client when AUTH_CLIENT_ID is also set [optional] [when OIDC is set → otherwise required] |
AUTH_CLIENT_ID | any | - | Client ID (local auth). In OIDC mode, optional bootstrap client ID used to create/update a Keycloak admin/root client when AUTH_CLIENT_SECRET is also set [optional] [when OIDC is set → otherwise required] |
OIDC_UI_CLIENT_ID | any | - | Public client ID for the Angular UI in OIDC mode. Used to register a public Keycloak client for Authorization Code + PKCE login. [optional] [when OIDC is set → then default="eudiplo-ui"] |
Configuration
| Key | Type | Allowed values | Notes |
|---|---|---|---|
CONFIG_IMPORT_MODE | string | disabled, create, upsert, replace | Startup configuration reconciliation mode. [optional] (default: disabled) |
CONFIG_FOLDER | string | - | Path to config import folder [optional] (default: /path/to/config/folder) |
CONFIG_VARIABLE_STRICT | alternatives | - | Strict mode for config import. [optional] (default: skip) |
Cryptography
| Key | Type | Allowed values | Notes |
|---|---|---|---|
CRYPTO_ALG | string | ES256 | The signing algorithm to use [optional] (default: ES256) |
CRYPTO_TOLERANCE | number | - | Clock tolerance in seconds for JWT verification [optional] (default: 5) |
Database
| Key | Type | Allowed values | Notes |
|---|---|---|---|
DB_TYPE | string | sqlite, postgres | Database type [optional] (default: sqlite) |
DB_HOST | string | - | Database host [optional] [when DB_TYPE is {"override":true} | "sqlite" → otherwise required] |
DB_PORT | number | - | Database port [optional] [when DB_TYPE is {"override":true} | "sqlite" → otherwise required] |
DB_USERNAME | string | - | Database username [optional] [when DB_TYPE is {"override":true} | "sqlite" → otherwise required] |
DB_PASSWORD | string | - | Database password [optional] [when DB_TYPE is {"override":true} | "sqlite" → otherwise required] |
DB_DATABASE | string | - | Database name [optional] [when DB_TYPE is {"override":true} | "sqlite" → otherwise required] |
DB_SSL | boolean | - | Enable SSL/TLS for PostgreSQL database connections [optional] (default: false) |
DB_SSL_REJECT_UNAUTHORIZED | boolean | - | Reject PostgreSQL TLS certificates that cannot be validated against trusted CAs [optional] (default: true) |
DB_SSL_CA_PATH | string | - | Path to CA certificate file used to validate PostgreSQL TLS certificates [optional] |
DB_SSL_CERT_PATH | string | - | Path to client certificate file for PostgreSQL TLS [optional] |
DB_SSL_KEY_PATH | string | - | Path to client private key file for PostgreSQL TLS [optional] |
DB_SSL_KEY_PASSPHRASE | string | - | Passphrase for encrypted DB_SSL_KEY_PATH private key [optional] |
DB_SYNCHRONIZE | boolean | - | Enable TypeORM schema synchronization. Intended for development only; fresh installations are created by migrations. [optional] (default: false) |
DB_MIGRATIONS_RUN | boolean | - | Run pending database migrations automatically on startup [optional] (default: true) |
Encryption
| Key | Type | Allowed values | Notes |
|---|---|---|---|
ENCRYPTION_KEY_SOURCE | string | env, vault, aws, azure | Source for encryption key: env (dev), vault/aws/azure (prod - key only in RAM) [optional] (default: env) |
VAULT_ADDR | string | - | URL of the HashiCorp Vault server, e.g. http://vault:8200. Required when ENCRYPTION_KEY_SOURCE=vault [optional] |
VAULT_TOKEN | string | - | Token for the HashiCorp Vault server. Required when ENCRYPTION_KEY_SOURCE=vault [optional] 🔒 |
VAULT_ENCRYPTION_KEY_PATH | string | - | Path to encryption key in Vault KV secrets engine [optional] [when ENCRYPTION_KEY_SOURCE is {"override":true} | "vault" → then default="secret/data/eudiplo/encryption-key"] |
AWS_REGION | string | - | AWS region, e.g. eu-central-1. Required when ENCRYPTION_KEY_SOURCE=aws [optional] |
AWS_ENCRYPTION_SECRET_NAME | string | - | Name of the encryption key secret in AWS Secrets Manager [optional] [when ENCRYPTION_KEY_SOURCE is {"override":true} | "aws" → then required] |
AWS_ENCRYPTION_SECRET_KEY | string | - | JSON key within the AWS secret (if secret is JSON) [optional] [when ENCRYPTION_KEY_SOURCE is {"override":true} | "aws" → then default="key"] |
AZURE_KEYVAULT_URL | string | - | Azure Key Vault URL (e.g., https://myvault.vault.azure.net) [optional] [when ENCRYPTION_KEY_SOURCE is {"override":true} | "azure" → then required] |
AZURE_ENCRYPTION_SECRET_NAME | string | - | Name of the encryption key secret in Azure Key Vault [optional] [when ENCRYPTION_KEY_SOURCE is {"override":true} | "azure" → then required] |
General
| Key | Type | Allowed values | Notes |
|---|---|---|---|
FOLDER | string | - | Root working folder for temp files [optional] (default: ../../tmp) |
PUBLIC_URL | string | - | The public URL of the issuer [optional] (default: http://localhost:3000) |
INTERNAL_URL | string | - | Internal URL used by the backend to resolve its own authorization-server JWKS [optional] (default: http://127.0.0.1:3000) |
PORT | string | - | Port the HTTP(S) server listens on (default: 3000) [optional] |
CORS_ORIGINS | string | - | Comma-separated list of origins allowed to call the management API (/api/*) from a browser, e.g. https://console.example.com. Protocol and public endpoints stay open to all origins. If unset, all origins are allowed everywhere. [optional] |
Issuer
| Key | Type | Allowed values | Notes |
|---|---|---|---|
ISSUER_MULTI_CONSUMPTION | boolean | - | Enable or disable multi-consumption for the issuer [optional] (default: false) |
Logging
| Key | Type | Allowed values | Notes |
|---|---|---|---|
LOG_LEVEL | string | trace, debug, info, warn, error, fatal | Application log level [optional] (default: debug) |
LOG_ENABLE_HTTP_LOGGER | boolean | - | Enable HTTP request logging [optional] (default: false) |
LOG_HTTP_RESPONSE_BODY | boolean | - | Capture and log HTTP response bodies (buffered up to LOG_HTTP_RESPONSE_BODY_MAX_LENGTH bytes). Disabled by default because response bodies may contain access tokens, credentials, or other sensitive data. [optional] (default: false) |
LOG_HTTP_RESPONSE_BODY_MAX_LENGTH | number | - | Maximum number of bytes to capture for HTTP response bodies. Set to 0 to disable truncation. [optional] (default: 4096) |
LOG_REDACT_SENSITIVE_DATA | boolean | - | Redact sensitive request/response fields from logs. Disable only for debugging. [optional] (default: true) |
LOG_OID4VP_DECRYPTED_RESPONSE | boolean | - | Log decrypted OID4VP authorization responses. Disable by default because responses may contain personal data and credentials. [optional] (default: false) |
LOG_ENABLE_SESSION_LOGGER | boolean | - | Enable session flow logging [optional] (default: false) |
LOG_SESSION_STORE | string | off, errors, all, verbose | Controls whether session log entries are persisted to the database. 'off' disables storage, 'errors' stores only warn/error entries, 'all' stores everything, 'verbose' stores everything including full request/response bodies and error stacks. [optional] (default: off) |
LOG_TO_FILE | boolean | - | Enable logging to file in addition to console [optional] (default: false) |
LOG_FILE_PATH | string | - | File path for log output when LOG_TO_FILE is enabled [optional] (default: ./logs/session.log) |
AUDIT_LOG_RETENTION_DAYS | number | - | Delete tenant activity audit log entries older than N days. Set to 0 to disable time-based pruning. [optional] (default: 0) |
OTEL_SDK_DISABLED | boolean | - | Disable OpenTelemetry SDK (and OTel log forwarding) [optional] (default: false) |
AUDIT_LOG_MAX_ENTRIES_PER_TENANT | number | - | Keep only the newest N tenant activity audit log entries per tenant. Set to 0 to disable count-based pruning. [optional] (default: 0) |
Observability
| Key | Type | Allowed values | Notes |
|---|---|---|---|
GRAFANA_URL | string | - | Base URL of the Grafana instance for deep linking from the dashboard UI [optional] |
GRAFANA_DATASOURCE_TEMPO_UID | string | - | UID of the Tempo data source in Grafana [optional] (default: tempo) |
GRAFANA_DATASOURCE_LOKI_UID | string | - | UID of the Loki data source in Grafana [optional] (default: loki) |
OTEL_EXPORTER_OTLP_ENDPOINT | string | - | Base URL of the OTLP/HTTP endpoint (e.g. the OpenTelemetry Collector) that receives traces, metrics and logs (default: http://localhost:4318) [optional] |
OTEL_SERVICE_NAME | string | - | Service name attached to exported traces, metrics and logs (default: eudiplo-backend) [optional] |
Session
| Key | Type | Allowed values | Notes |
|---|---|---|---|
SESSION_TIDY_UP_INTERVAL | number | - | Interval in seconds to run session tidy up [optional] (default: 3600) |
SESSION_TTL | number | - | Default time to live for sessions in seconds. Can be overridden per tenant. [optional] (default: 86400) |
SESSION_CLEANUP_MODE | string | full, anonymize | Default cleanup mode when sessions expire. 'full' deletes the entire session, 'anonymize' keeps metadata but removes personal data. Can be overridden per tenant. [optional] (default: full) |
Skip Flags
Every switch that turns off a check of the normal flow is named SKIP_<CHECK>
and defaults to false. The startup log lists active skip flags as warnings.
Use them only for development and interoperability tests.
| Key | Type | Allowed values | Notes |
|---|---|---|---|
SKIP_OVERASKING_CHECK | boolean | - | Skip verifying that the registration certificate authorizes every credential in the DCQL query (overasking prevention). Intended for development and interoperability testing only. [optional] (default: false) |
Status
| Key | Type | Allowed values | Notes |
|---|---|---|---|
STATUS_CAPACITY | number | - | The default capacity of the status list. Can be overridden per tenant. [optional] (default: 10000) |
STATUS_BITS | number | 1, 2, 4, 8 | The default number of bits used per status entry. Can be overridden per tenant. [optional] (default: 1) |
STATUS_TTL | number | - | The default TTL in seconds for status list JWTs. Verifiers can cache the JWT until expiration. Can be overridden per tenant. [optional] (default: 3600) |
STATUS_IMMEDIATE_UPDATE | boolean | - | If true, regenerate status list JWT immediately on every status change. If false (default), use lazy regeneration when TTL expires. Can be overridden per tenant. [optional] (default: false) |
STATUS_ENABLE_AGGREGATION | boolean | - | If true (default), include aggregation_uri in status list JWTs. This allows relying parties to pre-fetch all status lists for offline validation per RFC draft-ietf-oauth-status-list Section 9. Can be overridden per tenant. [optional] (default: true) |
Storage
| Key | Type | Allowed values | Notes |
|---|---|---|---|
STORAGE_DRIVER | string | local, s3 | The storage driver to use [optional] (default: local) |
LOCAL_STORAGE_DIR | string | - | The directory to store files in when using local storage [optional] [when STORAGE_DRIVER is {"override":true} | "local" → then default=undefined] |
S3_REGION | string | - | The AWS region for the S3 bucket [optional] [when STORAGE_DRIVER is {"override":true} | "s3" → then required] |
S3_BUCKET | string | - | The name of the S3 bucket [optional] [when STORAGE_DRIVER is {"override":true} | "s3" → then required] |
S3_ACCESS_KEY_ID | string | - | The access key ID for the S3 bucket. Optional when using IRSA or instance profile credentials. [optional] [when STORAGE_DRIVER is {"override":true} | "s3"] |
S3_SECRET_ACCESS_KEY | string | - | The secret access key for the S3 bucket. Optional when using IRSA or instance profile credentials. [optional] [when STORAGE_DRIVER is {"override":true} | "s3"] |
S3_ENDPOINT | string | - | The endpoint URL for the S3 service (for S3-compatible services) [optional] [when STORAGE_DRIVER is {"override":true} | "s3"] |
S3_FORCE_PATH_STYLE | boolean | - | Whether to force path-style URLs for S3 [optional] [when STORAGE_DRIVER is {"override":true} | "s3" → then default=false] |
TLS
| Key | Type | Allowed values | Notes |
|---|---|---|---|
TLS_ENABLED | boolean | - | Enable built-in TLS termination (serve HTTPS directly). Requires TLS_CERT_PATH and TLS_KEY_PATH; startup fails if they are unset or unreadable [optional] (default: false) |
TLS_CERT_PATH | string | - | Path to the TLS certificate file (PEM format) [optional] |
TLS_KEY_PATH | string | - | Path to the TLS private key file (PEM format) [optional] |
TLS_CA_PATH | string | - | Path to the intermediate CA certificate(s) of the server certificate (PEM format). They are sent to clients after the certificate in TLS_CERT_PATH so clients can build the chain. Not needed if TLS_CERT_PATH already contains the full chain (e.g. Let's Encrypt fullchain.pem). Does not enable client certificate authentication (mTLS) [optional] |
TLS_KEY_PASSPHRASE | string | - | Passphrase for an encrypted TLS_KEY_PATH private key [optional] 🔒 |
Verifier
| Key | Type | Allowed values | Notes |
|---|---|---|---|
VP_REMOVE_TA | boolean | - | If true, strip trusted_authorities from the DCQL query sent to wallets in OID4VP authorization requests. Use this as an escape hatch for wallets that do not yet handle trusted_authorities correctly. [optional] (default: false) |
Webhook
| Key | Type | Allowed values | Notes |
|---|---|---|---|
OUTBOUND_URL_ALLOW_HTTP | boolean | - | Allow HTTP (non-TLS) for outbound calls (webhooks, attribute providers, issuer and schema metadata imports, trust lists, status lists, federation entities, external authorization servers and the upstream provider of a chained authorization server). CRLs may always use HTTP. Enable it for local development against HTTP endpoints. [optional] (default: false) |
OUTBOUND_URL_ALLOW_PRIVATE_NETWORK | boolean | - | Allow outbound calls (webhooks, attribute providers, metadata imports, trust lists, status lists, federation entities, CRLs, external authorization servers and the upstream provider of a chained authorization server) to private, loopback, or link-local IP ranges, e.g. for services inside the same cluster or for local development. The address actually connected to is checked as well (DNS rebinding protection). EUDIPLO's own PUBLIC_URL and INTERNAL_URL are always reachable for trust lists, status lists and authorization server keys. [optional] (default: false) |
OUTBOUND_URL_ALLOWED_HOSTS | string | - | Comma-separated hostname allowlist for outbound calls (webhooks, attribute providers, metadata imports, trust lists, status lists, federation entities, CRLs, external and upstream authorization servers; supports exact host and subdomains). When set, other hosts are rejected. Listed hosts still need HTTPS and public addresses unless OUTBOUND_URL_ALLOW_HTTP or OUTBOUND_URL_ALLOW_PRIVATE_NETWORK is set. [optional] |