# Copy this file to api.env and keep api.env outside the public directory. APP_ENV=production # Give every endpoint a unique name. Separate endpoints with commas. CONTRACTLESS_RPC_NODES=node-1=127.0.0.1:50050,node-2=192.0.2.10:50050 CONTRACTLESS_RPC_TIMEOUT=10 # An endpoint enters a temporary cooldown after this many consecutive # connection or transport failures. Protocol and validation failures do not # count because retrying them against another node could conceal bad data. RPC_FAILURE_THRESHOLD=2 RPC_COOLDOWN_SECONDS=30 # Production requests must use HTTPS. When TLS terminates at a reverse proxy, # list only that proxy's IP or CIDR below so X-Forwarded-* can be trusted. API_REQUIRE_HTTPS=true API_TRUSTED_PROXIES= # Comma-separated exact browser origins. Use * only for a deliberately public # API. Browser-extension origins are supported. API_CORS_ORIGINS=https://wallet.example.com,chrome-extension://extension-id # This directory must be writable by PHP and must remain outside public/. API_SECURITY_STATE_PATH=storage/security-state.json API_MAX_BODY_BYTES=2000000 # Public browser-wallet limits use the caller's resolved IP address. API_RATE_WINDOW_SECONDS=60 API_PUBLIC_REQUESTS_PER_WINDOW=120 API_MESSAGE_VERIFY_REQUESTS_PER_WINDOW=30 API_BROADCAST_REQUESTS_PER_WINDOW=10 API_EXPENSIVE_REQUESTS_PER_WINDOW=5 # Large raw-response routes can be disabled independently. API_ENABLE_RAW_BLOCKS=true API_ENABLE_TORRENTS=true API_ENABLE_ALL_HEADERS=false # Optional identified clients use client-id=secret:requests-per-window. # Secrets must contain at least 32 characters. Leave these settings empty when # not needed. Never embed either kind of secret in a browser wallet. API_KEYS= API_HMAC_KEYS= API_HMAC_CLOCK_SKEW_SECONDS=300