Backend configuration
Download the example configuration file
The file is mounted into the container at /flip/cfg/config.yaml.
Configuration scope
The file contains the settings controlled on the installation side: connections to external services, the domain, secrets and the authentication method. Background job intervals, token and cache lifetimes, limits and plan restrictions are fixed in the image and are not set in the configuration file.
Secrets
All fields marked as "secret" are required and must be unique to each installation. To generate a value:
openssl rand -hex 16Configuration fields
Domain
- Domain: Base URL of the application, including the
/apppath. Used in links in emails and for SSO sign-in.
Example:https://example.flip-chart.ru/app
LogLevel
- LogLevel: Logging level:
debug,info,warn,error.
Example:info
Server
- Host: Address the server listens on.
Example:0.0.0.0 - Port: Server port. Must match the upstream in the nginx configuration and
flipApi.internalUrlin the mcp-server configuration.
Example:9000 - Timeout: HTTP request processing timeout.
Example:10s
Postgres
- Address: PostgreSQL server address.
Example:flip-postgres - Port: PostgreSQL port.
Example:5432 - User: Username.
Example:flip - Password: Password.
Example:secret-passwd - Database: Database name.
Example:flip - Driver: Migration driver. Always
postgres. - SSLmode: SSL connection mode:
disable,require,verify-full.
For a Standalone installation with PostgreSQL in a container, usedisable; for an external database, userequireorverify-full.
Example:disable - SSLRootCert: Path to the root certificate inside the container. Required with
SSLmode: verify-full; the file must be mounted into the container.
Example:/flip/certs/ca.pem - MigrationDir: Migrations directory inside the container. Always
/flip/migrations.
Migrations
Database migrations are applied automatically every time the backend container starts.
S3
- AwsAccessKey: S3 storage access key.
Example:flip-minioadmin - AwsSecretKey: Secret key.
Example:flip-minioadminsecret - AwsRegion: Storage region. For MinIO, any value will do.
Example:ru-central1 - AwsUrl: S3 storage URL.
Example:http://flip-minio:9000 - AWSPartitionID: AWS partition ID. Leave empty.
Example:"" - BucketName: Bucket name.
Example:flip - Folders: Prefixes for storing data inside the bucket. The values are fixed.
- FlipsAvatarsFolder:
flips-avatars/ - TeamsAvatarsFolder:
teams-avatars/ - UsersAvatarsFolder:
avatars/ - ElementsFolder:
elements/ - CommentsFolder:
comments/ - DocsFolder:
documents/ - LinksFolder:
links/ - PresentationFolder:
presentations/ - ShapesFolder:
shapes/
- FlipsAvatarsFolder:
Important
The backend and file-handlers services must be connected to the same S3 storage and the same bucket.
RedisClient (Valkey)
- Address: Valkey server address.
Example:flip-valkey:6379 - Username: Username. Leave empty if ACLs are not used.
Example:"" - Password: Password. Leave empty if not used.
Example:"" - DB: Database number.
Example:0
Important
The backend, file-handlers and mcp-server services must be connected to the same Valkey instance. Only the Valkey standalone mode is supported (no Sentinel or Cluster).
Mail
- Host: SMTP server address.
Example:smtp.example.ru - Port: SMTP server port.
Example:587 - User: SMTP username.
Example:user - Password: SMTP password.
Example:password - From: Sender address.
Example:welcome@example.ru
Auth
Authentication settings section.
CommonAuthConfig
- CommonRegistrationFlow: Self-registration of users by email. When
false, users can access the application only by invitation or via SSO/LDAP.
Example:true
ConfirmationConfig
- CodeDigits: Number of digits in the email confirmation code.
Example:6 - Secret: Secret used to sign confirmation codes.
Example:3f1c9a7e2b8d4c6a1e5f0b9d7c3a2e81
HashPasswordSalt
- HashPasswordSalt: Salt for password hashing. Secret.
FlipPasswordCipherSecret
- FlipPasswordCipherSecret: Secret used to encrypt board access passwords.
TokenConfig
- AccessToken.Secret: Secret used to sign access tokens.
- RefreshToken.Secret: Secret used to sign refresh tokens.
- FlipPasswordToken.Secret: Secret used to sign access tokens for password-protected boards.
KeyCloakAuthConfig
Direct integration with Keycloak. Not used for SSO via OIDC/SAML — see SSO setup.
- Enable: Enables the integration.
Example:false - Address: Keycloak server address.
Example:https://keycloak.example.ru - ClientID: Client ID.
- ClientSecret: Client secret.
- Realm: Realm name.
LdapAuthConfig
See LDAP integration.
- Enable: Enables LDAP authentication.
Example:false - Address: LDAP server URL.
Example:ldap://ldap.example.ru:389 - BaseDN: Base DN for user searches.
Example:dc=example,dc=ru - BindDN: DN of the service account used to connect.
Example:cn=admin,dc=example,dc=ru - BindPassword: Service account password.
- UseTLS: Whether to run STARTTLS after connecting.
Example:false - Attributes: LDAP attribute names.
- DN:
dn - CN: attribute with the user's display name, for example
cn - Mail: attribute with the email address, for example
mail - AccountStatus: account status attribute, for example
accountStatus
- DN:
Important
Only one provider can be enabled at a time: KeyCloakAuthConfig or LdapAuthConfig.
SessionConfig
- Secret: Secret used to sign user sessions.
InvitationConfig
- Secret: Secret used to sign invitation links.
FileHandlerServiceConfig
- Enable: Enables interaction with the file-handlers service (document upload, conversion, previews).
Example:true - Address: API address of the file-handlers service.
Example:http://flip-file-handlers:8080/api
Documents
- Enable: Enables the documents feature on boards.
Example:true
McpAgentTokens
Authorization of AI agents through the MCP server.
- Enable: Enables issuing tokens to agents via OAuth. Must be
truewhen the MCP server is used.
Example:true - OAuth.Clients: List of OAuth clients. By default, it contains the built-in
flip-mcpclient (matchesflipApi.clientIdin the mcp-server configuration) with the callback URLshttp://localhost:*,https://claude.ai/api/mcp/auth_callback,https://claude.com/api/mcp/auth_callbackand the scopesflip:read,flip:write,comment:read. Set it only if you need to replace the built-in list; the value you set replaces that list entirely.- id: Client ID.
- name: Display name shown on the access consent screen.
- redirectURIPatterns: Allowed callback URLs of MCP clients.
- scopes: Scopes granted to the client.
- isPublic: Public client (PKCE, no client secret). Value:
true.