Documentation

Reference

Environment variable reference

Reference customer-controlled Access402 adapter and Gateway environment variables and their security boundaries.
Last reviewed August 10, 2026

Shared server variables

VariableRequiredPurpose
ACCESS402_INSTALLATION_IDYesIdentifies the Access402 installation.
ACCESS402_API_KEYYesAuthenticates the installation. Treat as a secret.
ACCESS402_PUBLIC_BASE_URLYesCanonical public API origin used for resource URLs.
ACCESS402_MODEYessandbox selects Base Sepolia; live selects Base mainnet. Used by FastAPI and the Gateway.
ACCESS402_CORS_ALLOW_ORIGINNoExact browser origin allowed to read payment challenges.
ACCESS402_API_BASE_URLNoAccess402 backend override for local platform development only.

Gateway variables

VariableRequiredPurpose
ACCESS402_ORIGINNode GatewayFixed application origin. It must differ from the public Gateway origin.
ACCESS402_ORIGIN_AUTH_SECRETLive GatewaySigns short-lived origin-authorization tokens. Use at least 32 random bytes.
ACCESS402_CONFIG_TTL_SECONDSNoSigned configuration cache duration, from 30 to 3600 seconds. Defaults to 300.
ACCESS402_MAX_BODY_BYTESNoMaximum request body accepted by the Gateway. Defaults to 2 MiB.

Cloudflare Workers receive these through the env bindings passed to the Worker handler. Prefer encrypted Worker secrets for credentials and a private service binding for the origin.

Where to store values

Use encrypted server secrets provided by your deployment platform. Do not commit a populated .env file, expose values through VITE_ variables, include them in an image layer, or print them during startup.

Variables customers never receive

Coinbase CDP API key identifiers, private keys, JWT signing material, facilitator credentials, Supabase service credentials, and global platform limit settings remain inside Access402 server infrastructure. They are not adapter, Gateway, WordPress, or coding-agent configuration.