Browse docs · Reference
Get started
Concepts
Guides
Security
Reference
Docs / Reference
Configuration reference
Environment variables for the PastKeys broker: mode, custody key, workload identity, audit, break-glass and provider settings.
The broker is configured with environment variables. Secrets should come from your secret manager at runtime, never from files in version control.
Mode and identity
BROKER_CONTROLPLANE_URL, BROKER_TOKEN | Control-plane mode: the dashboard URL and the broker token |
BROKER_DB_DSN, BROKER_ACCOUNT_ID | Database mode (co-located with a self-hosted control plane) |
BROKER_ADDR | Listen address (default :8080) |
BROKER_NAME | Label shown in the dashboard (default: host name) |
BROKER_POLICY_DIR | Policy files for local mode |
BROKER_OIDC_ISSUERS / _FILE | JSON array of trusted workload-identity issuers |
BROKER_OIDC_ISSUER, _AUDIENCE, _SUBJECT_CLAIM, _ENV_CLAIM, _REQUIRED_CLAIMS | Single-issuer shorthand |
BROKER_REQUIRE_WORKLOAD_IDENTITY=1 | Refuse agent tokens on this broker |
AGENT_JWT_DEV_SECRET | Agent-token secret in database/local mode |
Custody, audit, break-glass
BROKER_CUSTODY_KEY_FILE / BROKER_CUSTODY_KEY | The custody private key |
BROKER_CUSTODY_VAULT_ADDR, _KEY, _MOUNT, _TOKEN/_TOKEN_FILE, BROKER_CUSTODY_KEY_WRAPPED_FILE | Unwrap the custody key through HashiCorp Vault Transit at startup |
BROKER_ALLOW_INSECURE_KEY_PERMS=1 | Allow a key file readable by others (not recommended) |
BROKER_AUDIT_KEY_FILE | Sign audit records with an Ed25519 key |
BROKER_AUDIT_FILE | Local-mode audit log file |
BROKER_LOCKDOWN_FILE | Local kill switch file |
BROKER_LICENSE, BROKER_LICENSE_PUBKEY | Self-hosted plan license |
Providers
AWS_REGION, AWS_ASSUME_ROLE_ARN | AWS STS |
GITHUB_APP_ID, GITHUB_APP_INSTALLATION_ID | GitHub App |
POSTGRES_READ_ROLE, POSTGRES_REAP_INTERVAL | Postgres temporary roles |
CLOUDFLARE_ACCOUNT_ID | Cloudflare account |
CLOUDFLARE_TOKEN_MINT, CLOUDFLARE_PG_*, CLOUDFLARE_MINT_TTL, CLOUDFLARE_MINT_CLIENT_IP, CLOUDFLARE_TOKEN_ENDPOINT | Per-call Cloudflare tokens |
HTTP_ALLOWED_HOSTS | Host allowlist for the HTTP provider |
MCP server
PASTKEYS_BROKER_URL | Broker the MCP server talks to |
PASTKEYS_AGENT_TOKEN | The agent's token |