Forest Admin - API reference
    Preparing search index...

    Type Alias BffEmbedOptions

    Options of an embedded BFF. Everything the BFF shares with the agent — the secrets, the Forest urls, the logger — is inherited rather than repeated: a divergent authSecret would make the agent reject the very tokens the BFF mints, as an opaque 401.

    type BffEmbedOptions = {
        agentTimeoutMs?: number;
        aiTimeoutMs?: number;
        allowedOrigins?: string[];
        defaultTimezone?: string;
        openapiEnabled?: boolean;
        shutdownTimeoutMs?: number;
        tokenEncryptionKey?: string;
    }
    Index

    Properties

    agentTimeoutMs?: number

    How long a call to the agent may take. Defaults to 10s.

    It bounds how long the BFF waits, and cancels nothing: an action or a write cut off at the deadline keeps running inside the agent and still commits, so a client retrying on the timeout can double the mutation. Raise it rather than relying on a retry for operations that are not idempotent.

    aiTimeoutMs?: number

    How long the AI relay waits for the Forest server. Defaults to 120s.

    allowedOrigins?: string[]

    Origins (scheme + host + port) allowed to call the BFF from a browser. An entry may carry a single * as its leading host label — https://*.apps.zdusercontent.com — which matches exactly one DNS label there, and never the scheme or the port. The host left after *. must be at least two non-empty labels, so https://*.com is refused; a two-label public suffix such as https://*.co.uk is not, and would allow every site under it. Any other * shape is refused and warned about at startup. Empty means no cross-origin browser access at all, which for a backend-for-frontend is almost always a mistake — the BFF warns about it at startup.

    defaultTimezone?: string

    Fallback IANA timezone for a request that carries none.

    openapiEnabled?: boolean

    Serve /bff/docs and /bff/agent/openapi.json. Defaults to false when embedded: the document is not filtered per caller, so any authenticated caller reads the name of every exposed collection, relation and field.

    shutdownTimeoutMs?: number

    How long stop() waits for the activity-log writes still in flight. Defaults to 10s.

    Embedded, the host owns the connections, so stop() is reached while audited requests are still running and their status transitions are not registered yet. Unbounded, one stalled audit store would hold the process until its orchestrator sends SIGKILL, which is worse than the entries the deadline leaves pending — those are logged by name when it expires.

    tokenEncryptionKey?: string

    Base64-encoded 32-byte AES-256 key encrypting stored refresh tokens. Gates the OAuth login/refresh flow (mode 1) and, with it, the AI relay.

    It is not an access control. The data routes accept a bff_access bearer whether or not this is set, because that token is verified against the agent's authSecret alone. Omitting it closes the login flow, not the session-bearer path — what protects that path is authSecret.