OptionalagentHow long a call to the agent may take. Defaults to 10s.
It bounds how long the BFF waits, and cancels nothing: an action or a write cut off at the deadline keeps running inside the agent and still commits, so a client retrying on the timeout can double the mutation. Raise it rather than relying on a retry for operations that are not idempotent.
OptionalaiHow long the AI relay waits for the Forest server. Defaults to 120s.
OptionalallowedOrigins (scheme + host + port) allowed to call the BFF from a browser. An entry may carry a
single * as its leading host label — https://*.apps.zdusercontent.com — which matches
exactly one DNS label there, and never the scheme or the port. The host left after *. must
be at least two non-empty labels, so https://*.com is refused; a two-label public suffix
such as https://*.co.uk is not, and would allow every site under it. Any other * shape is
refused and warned about at startup.
Empty means no cross-origin browser access at all, which for a backend-for-frontend is
almost always a mistake — the BFF warns about it at startup.
OptionaldefaultFallback IANA timezone for a request that carries none.
OptionalopenapiServe /bff/docs and /bff/agent/openapi.json. Defaults to false when embedded: the
document is not filtered per caller, so any authenticated caller reads the name of every
exposed collection, relation and field.
OptionalshutdownHow long stop() waits for the activity-log writes still in flight. Defaults to 10s.
Embedded, the host owns the connections, so stop() is reached while audited requests are
still running and their status transitions are not registered yet. Unbounded, one stalled
audit store would hold the process until its orchestrator sends SIGKILL, which is worse than
the entries the deadline leaves pending — those are logged by name when it expires.
OptionaltokenBase64-encoded 32-byte AES-256 key encrypting stored refresh tokens. Gates the OAuth login/refresh flow (mode 1) and, with it, the AI relay.
It is not an access control. The data routes accept a bff_access bearer whether or not this
is set, because that token is verified against the agent's authSecret alone. Omitting it
closes the login flow, not the session-bearer path — what protects that path is authSecret.
Options of an embedded BFF. Everything the BFF shares with the agent — the secrets, the Forest urls, the logger — is inherited rather than repeated: a divergent
authSecretwould make the agent reject the very tokens the BFF mints, as an opaque 401.