Docs / Reference

Configuration reference

Environment variables for the PastKeys broker: mode, custody key, workload identity, audit, break-glass and provider settings.

The broker is configured with environment variables. Secrets should come from your secret manager at runtime, never from files in version control.

Mode and identity

BROKER_CONTROLPLANE_URL, BROKER_TOKENControl-plane mode: the dashboard URL and the broker token
BROKER_DB_DSN, BROKER_ACCOUNT_IDDatabase mode (co-located with a self-hosted control plane)
BROKER_ADDRListen address (default :8080)
BROKER_NAMELabel shown in the dashboard (default: host name)
BROKER_POLICY_DIRPolicy files for local mode
BROKER_OIDC_ISSUERS / _FILEJSON array of trusted workload-identity issuers
BROKER_OIDC_ISSUER, _AUDIENCE, _SUBJECT_CLAIM, _ENV_CLAIM, _REQUIRED_CLAIMSSingle-issuer shorthand
BROKER_REQUIRE_WORKLOAD_IDENTITY=1Refuse agent tokens on this broker
AGENT_JWT_DEV_SECRETAgent-token secret in database/local mode

Custody, audit, break-glass

BROKER_CUSTODY_KEY_FILE / BROKER_CUSTODY_KEYThe custody private key
BROKER_CUSTODY_VAULT_ADDR, _KEY, _MOUNT, _TOKEN/_TOKEN_FILE, BROKER_CUSTODY_KEY_WRAPPED_FILEUnwrap the custody key through HashiCorp Vault Transit at startup
BROKER_ALLOW_INSECURE_KEY_PERMS=1Allow a key file readable by others (not recommended)
BROKER_AUDIT_KEY_FILESign audit records with an Ed25519 key
BROKER_AUDIT_FILELocal-mode audit log file
BROKER_LOCKDOWN_FILELocal kill switch file
BROKER_LICENSE, BROKER_LICENSE_PUBKEYSelf-hosted plan license

Providers

AWS_REGION, AWS_ASSUME_ROLE_ARNAWS STS
GITHUB_APP_ID, GITHUB_APP_INSTALLATION_IDGitHub App
POSTGRES_READ_ROLE, POSTGRES_REAP_INTERVALPostgres temporary roles
CLOUDFLARE_ACCOUNT_IDCloudflare account
CLOUDFLARE_TOKEN_MINT, CLOUDFLARE_PG_*, CLOUDFLARE_MINT_TTL, CLOUDFLARE_MINT_CLIENT_IP, CLOUDFLARE_TOKEN_ENDPOINTPer-call Cloudflare tokens
HTTP_ALLOWED_HOSTSHost allowlist for the HTTP provider

MCP server

PASTKEYS_BROKER_URLBroker the MCP server talks to
PASTKEYS_AGENT_TOKENThe agent's token