Configuration reference
Configuration comes from appsettings*.json plus environment variables with the STAYFN__ prefix and __ for nesting, for example
STAYFN__Events__Streaming__Enabled=true. It is validated at start, and the host refuses to start on missing or unsafe values. The most
used keys:
| Key | Default | Meaning |
|---|---|---|
ConnectionStrings:Postgres |
— | app role connection (required) |
ConnectionStrings:PostgresMigrator |
— | migrator connection for migrations |
Database:MigrateOnStartup |
false |
migrate before listening (compose sets it; Kubernetes uses the Job) |
Auth:Issuer, Auth:Audience, Auth:SigningKey, Auth:JwksUrl |
— | admin JWT validation |
Auth:ApiKeyPepper |
— | tenant API key digests |
Auth:Oidc:Authority, Auth:Oidc:ClientId, Auth:Oidc:Scope |
— | dashboard OIDC sign-in |
Runtime:DevTenant:Enabled |
false |
keyless calls as the dev tenant (Development only) |
Runtime:Quotas:* |
unlimited | host defaults for the quota.* variables |
Ohip:RateLimit:Capacity, Ohip:RateLimit:RefillPerSecond |
40, 40 |
OHIP token bucket per app key |
Events:Streaming:Enabled |
false |
run the stream ingest (one deployment per app key) |
Events:Streaming:WebSocketUrl |
gateway host | streaming URL or env: reference |
Events:BusinessEventMap:"<MODULE>|<EVENT>" |
built-in | override an event mapping |
Webhooks:HmacSecret |
— | Development-only fallback webhook secret |
Secrets:Provider |
env |
default secret provider |
Secrets:CacheTtl, Secrets:RotationCheckInterval |
00:05:00 |
secret caching and rotation checks |
Mcp:AllowSandboxInvoke, Mcp:ScaffoldRoot |
false, empty |
MCP sandbox.invoke guard and scaffold root on the host |
Security:MaxConcurrentRequests, Security:MaxQueuedRequests |
64, 128 |
load shedding |
Telemetry:OtlpEndpoint, Telemetry:ConsoleExporter |
—, false |
telemetry export |
.env.example and deploy/prod.env.example list every variable with comments.