Documentation menu

Configuration

Client configuration

Options, environment variables and defaults for each client in the secretserver-clients repository.

Environment variables

VariableRead byMeaning
SS_API_KEYPython, Node.js, PHP, AnsibleAPI key when none is passed
SS_API_URLPython, Node.js, PHP, AnsibleBase URL when none is passed. Default https://api.secretserver.io
SS_PARTIAL_UPDATESPython, Node.js, PHP1 enables partial updates without an ETag. Only safe against server build 3075630 or newer.
SS_CA_PATHAnsiblePEM CA bundle added to the system roots
NODE_EXTRA_CA_CERTSNode.js runtimeTrust a private CA in the Node.js client
SECRETSERVER_URLMCP bridgeAPI origin (required)
SECRETSERVER_TOKEN_FILEMCP bridgeOwner-only file holding the API key (required)
SECRETSERVER_ENABLE_SECRET_RESOLUTIONMCP bridge1 registers resolve_secret_template
SECRETSERVER_RESOLVE_ALLOWMCP bridgeComma-separated allowlist of variable names
The Go library reads no environment variables. Explicit constructor arguments always win over the environment, except in PHP, where SS_PARTIAL_UPDATES=1 enables partial updates even when the argument is false.

Python

SecretServerClient(api_key=None, api_url=None, timeout=10,
                   verify_ssl=True, ca_file=None, partial_updates=None)
OptionDefaultNotes
api_keySS_API_KEYRequired; AuthError if missing. CR, LF and NUL are rejected.
api_urlSS_API_URL, then https://api.secretserver.iohttps, or http to a loopback host. A trailing /api/v1 is removed.
timeout10Seconds; must be positive
verify_sslTrueAnything else raises ValueError
ca_fileNonePEM bundle added to the default trust store
partial_updatesSS_PARTIAL_UPDATES == "1"Read from the environment only when not passed

Fixed behavior: TLS 1.2 minimum, User-Agent secretserver-python/1.3.0, 4 MiB JSON and 16 MiB download caps.

Node.js / TypeScript

new SecretServerClient({ apiKey, apiUrl, fetchFn, timeoutMs, partialUpdates })
OptionDefaultNotes
apiKeySS_API_KEYRequired; AuthError if missing
apiUrlSS_API_URL, then https://api.secretserver.iohttps, or http to localhost, 127.0.0.1 or ::1
fetchFnglobal fetchCustom fetch implementation
timeoutMs10000Milliseconds; must be positive
partialUpdatesSS_PARTIAL_UPDATES === "1"An explicit false wins over the environment

Fixed behavior: redirects rejected, User-Agent secretserver-node/1.3.0.

PHP

new SecretServerClient(?string $apiKey = null, ?string $apiUrl = null, int $timeout = 10,
                       bool $verifySsl = true, ?string $caFile = null, bool $partialUpdates = false)
OptionDefaultNotes
$apiKeySS_API_KEYRequired; AuthException if empty
$apiUrlSS_API_URL, then https://api.secretserver.iohttps, or http to a loopback host; no credentials, query or fragment
$timeout10Seconds
$verifySsltruefalse throws
$caFilenullMust exist if given
$partialUpdatesfalseAlso enabled by SS_PARTIAL_UPDATES=1 or setPartialUpdates(true)

Fixed behavior: cURL without redirect following, User-Agent secretserver-php/1.3.0.

Go

ss.NewClient(&ss.Config{APIURL, APIKey, HTTPClient, UserAgent, PartialUpdates})
FieldDefaultNotes
APIKeynoneRequired
APIURLhttps://api.secretserver.iohttps, or http to a loopback host
HTTPClient30 s timeout, TLS 1.2 minimum, no redirectsIts Transport must be nil or an *http.Transport. InsecureSkipVerify and custom TLS dialers are refused. The transport is cloned and TLS raised to 1.2.
UserAgentGo defaultSent when set
PartialUpdatesfalseAllow Secrets.Update and JKS.Update without an ETag

Ansible

OptionEnvironmentansible.cfg [secretserver]Default
api_keySS_API_KEYapi_keyrequired
api_urlSS_API_URLapi_urlhttps://api.secretserver.io
ca_pathSS_CA_PATHca_pathsystem roots
timeoutnonenone10
versionnonenonenot set (1 to 12)
rendernonenonefalse

ansible.cfg

[secretserver]
api_url = https://api.secretserver.io
ca_path = /etc/ssl/private-ca.pem
# api_key: prefer SS_API_KEY or an encrypted variable over a plaintext file

The lookup honors the standard proxy environment variables.

Desktop app

SettingWhere it is storedDefault
API URLFyne preferences for app ID com.afterdarksys.secretserver, key api_urlhttps://api.secretserver.io
API keyOS keychain, service com.afterdarksys.secretserver, account = API URLnone

MCP bridge

VariableRequiredRules
SECRETSERVER_URLyeshttps, or http to a loopback host; no credentials, query or fragment. A path prefix is kept and a trailing /api/v1 removed.
SECRETSERVER_TOKEN_FILEyesRegular file with no group or other permissions; 16 to 8192 bytes after trimming
SECRETSERVER_ENABLE_SECRET_RESOLUTIONnoExactly 1 to enable
SECRETSERVER_RESOLVE_ALLOWwhen resolution is onNames matching [A-Z_][A-Z0-9_]{0,127}

Fixed behavior: TLS 1.2 minimum, 30 second timeout, no redirects, 4 MiB response cap.

Live test variables

The live integration tests in each library refuse to run unless they point at a loopback server. They never fall back to SS_API_URL or SS_API_KEY.

VariableMeaning
SS_LIVE_URLLoopback test server URL
SS_LIVE_KEYTest API key
SS_LIVE_WRITE_KEYTest key with write scopes (Go smoke test)
SS_LIVE_CONTAINERContainer used by the Go smoke test