Shared server variables
| Variable | Required | Purpose |
|---|---|---|
ACCESS402_INSTALLATION_ID | Yes | Identifies the Access402 installation. |
ACCESS402_API_KEY | Yes | Authenticates the installation. Treat as a secret. |
ACCESS402_PUBLIC_BASE_URL | Yes | Canonical public API origin used for resource URLs. |
ACCESS402_MODE | Yes | sandbox selects Base Sepolia; live selects Base mainnet. Used by FastAPI and the Gateway. |
ACCESS402_CORS_ALLOW_ORIGIN | No | Exact browser origin allowed to read payment challenges. |
ACCESS402_API_BASE_URL | No | Access402 backend override for local platform development only. |
Gateway variables
| Variable | Required | Purpose |
|---|---|---|
ACCESS402_ORIGIN | Node Gateway | Fixed application origin. It must differ from the public Gateway origin. |
ACCESS402_ORIGIN_AUTH_SECRET | Live Gateway | Signs short-lived origin-authorization tokens. Use at least 32 random bytes. |
ACCESS402_CONFIG_TTL_SECONDS | No | Signed configuration cache duration, from 30 to 3600 seconds. Defaults to 300. |
ACCESS402_MAX_BODY_BYTES | No | Maximum request body accepted by the Gateway. Defaults to 2 MiB. |
Cloudflare Workers receive these through the env bindings passed to the Worker handler. Prefer encrypted Worker secrets for credentials and a private service binding for the origin.
Where to store values
Use encrypted server secrets provided by your deployment platform. Do not commit a populated .env file, expose values through VITE_ variables, include them in an image layer, or print them during startup.
Variables customers never receive
Coinbase CDP API key identifiers, private keys, JWT signing material, facilitator credentials, Supabase service credentials, and global platform limit settings remain inside Access402 server infrastructure. They are not adapter, Gateway, WordPress, or coding-agent configuration.
