---
url: https://flip-chart.ru/developers/en/on-premise/config/backend.md
description: >-
  Reference for the flip on-premise backend configuration file: domain,
  PostgreSQL, S3, Valkey, mail, authentication methods, sessions, invitations
  and MCP AI agent tokens.
---

# Backend configuration

&#x20;Download the example configuration file&#x20;

The file is mounted into the container at `/flip/cfg/config.yaml`.

::: tip Configuration scope
The file contains the settings controlled on the installation side: connections to external services, the domain, secrets and the authentication method. Background job intervals, token and cache lifetimes, limits and plan restrictions are fixed in the image and are not set in the configuration file.
:::

::: danger Secrets
All fields marked as "secret" are required and must be unique to each installation. To generate a value:

```bash
openssl rand -hex 16
```

:::

## Configuration fields

### Domain

* **Domain**: Base URL of the application, including the `/app` path. Used in links in emails and for SSO sign-in.\
  Example: `https://example.flip-chart.ru/app`

### LogLevel

* **LogLevel**: Logging level: `debug`, `info`, `warn`, `error`.\
  Example: `info`

### Server

* **Host**: Address the server listens on.\
  Example: `0.0.0.0`
* **Port**: Server port. Must match the upstream in the nginx configuration and `flipApi.internalUrl` in the mcp-server configuration.\
  Example: `9000`
* **Timeout**: HTTP request processing timeout.\
  Example: `10s`

### Postgres

* **Address**: PostgreSQL server address.\
  Example: `flip-postgres`
* **Port**: PostgreSQL port.\
  Example: `5432`
* **User**: Username.\
  Example: `flip`
* **Password**: Password.\
  Example: `secret-passwd`
* **Database**: Database name.\
  Example: `flip`
* **Driver**: Migration driver. Always `postgres`.
* **SSLmode**: SSL connection mode: `disable`, `require`, `verify-full`.\
  For a Standalone installation with PostgreSQL in a container, use `disable`; for an external database, use `require` or `verify-full`.\
  Example: `disable`
* **SSLRootCert**: Path to the root certificate inside the container. Required with `SSLmode: verify-full`; the file must be mounted into the container.\
  Example: `/flip/certs/ca.pem`
* **MigrationDir**: Migrations directory inside the container. Always `/flip/migrations`.

::: tip Migrations
Database migrations are applied automatically every time the backend container starts.
:::

### S3

* **AwsAccessKey**: S3 storage access key.\
  Example: `flip-minioadmin`
* **AwsSecretKey**: Secret key.\
  Example: `flip-minioadminsecret`
* **AwsRegion**: Storage region. For MinIO, any value will do.\
  Example: `ru-central1`
* **AwsUrl**: S3 storage URL.\
  Example: `http://flip-minio:9000`
* **AWSPartitionID**: AWS partition ID. Leave empty.\
  Example: `""`
* **BucketName**: Bucket name.\
  Example: `flip`
* **Folders**: Prefixes for storing data inside the bucket. The values are fixed.
  * **FlipsAvatarsFolder**: `flips-avatars/`
  * **TeamsAvatarsFolder**: `teams-avatars/`
  * **UsersAvatarsFolder**: `avatars/`
  * **ElementsFolder**: `elements/`
  * **CommentsFolder**: `comments/`
  * **DocsFolder**: `documents/`
  * **LinksFolder**: `links/`
  * **PresentationFolder**: `presentations/`
  * **ShapesFolder**: `shapes/`

::: danger Important
The backend and file-handlers services must be connected to the same S3 storage and the same bucket.
:::

### RedisClient (Valkey)

* **Address**: Valkey server address.\
  Example: `flip-valkey:6379`
* **Username**: Username. Leave empty if ACLs are not used.\
  Example: `""`
* **Password**: Password. Leave empty if not used.\
  Example: `""`
* **DB**: Database number.\
  Example: `0`

::: danger Important
The backend, file-handlers and mcp-server services must be connected to the same Valkey instance. Only the Valkey standalone mode is supported (no Sentinel or Cluster).
:::

### Mail

* **Host**: SMTP server address.\
  Example: `smtp.example.ru`
* **Port**: SMTP server port.\
  Example: `587`
* **User**: SMTP username.\
  Example: `user`
* **Password**: SMTP password.\
  Example: `password`
* **From**: Sender address.\
  Example: `welcome@example.ru`

### Auth

Authentication settings section.

#### CommonAuthConfig

* **CommonRegistrationFlow**: Self-registration of users by email. When `false`, users can access the application only by invitation or via SSO/LDAP.\
  Example: `true`

#### ConfirmationConfig

* **CodeDigits**: Number of digits in the email confirmation code.\
  Example: `6`
* **Secret**: Secret used to sign confirmation codes.\
  Example: `3f1c9a7e2b8d4c6a1e5f0b9d7c3a2e81`

#### HashPasswordSalt

* **HashPasswordSalt**: Salt for password hashing. Secret.

#### FlipPasswordCipherSecret

* **FlipPasswordCipherSecret**: Secret used to encrypt board access passwords.

#### TokenConfig

* **AccessToken.Secret**: Secret used to sign access tokens.
* **RefreshToken.Secret**: Secret used to sign refresh tokens.
* **FlipPasswordToken.Secret**: Secret used to sign access tokens for password-protected boards.

#### KeyCloakAuthConfig

Direct integration with Keycloak. Not used for SSO via OIDC/SAML — see [SSO setup](/en/on-premise/installation/other/sso).

* **Enable**: Enables the integration.\
  Example: `false`
* **Address**: Keycloak server address.\
  Example: `https://keycloak.example.ru`
* **ClientID**: Client ID.
* **ClientSecret**: Client secret.
* **Realm**: Realm name.

#### LdapAuthConfig

See [LDAP integration](/en/on-premise/installation/other/ldap).

* **Enable**: Enables LDAP authentication.\
  Example: `false`
* **Address**: LDAP server URL.\
  Example: `ldap://ldap.example.ru:389`
* **BaseDN**: Base DN for user searches.\
  Example: `dc=example,dc=ru`
* **BindDN**: DN of the service account used to connect.\
  Example: `cn=admin,dc=example,dc=ru`
* **BindPassword**: Service account password.
* **UseTLS**: Whether to run STARTTLS after connecting.\
  Example: `false`
* **Attributes**: LDAP attribute names.
  * **DN**: `dn`
  * **CN**: attribute with the user's display name, for example `cn`
  * **Mail**: attribute with the email address, for example `mail`
  * **AccountStatus**: account status attribute, for example `accountStatus`

::: danger Important
Only one provider can be enabled at a time: `KeyCloakAuthConfig` or `LdapAuthConfig`.
:::

### SessionConfig

* **Secret**: Secret used to sign user sessions.

### InvitationConfig

* **Secret**: Secret used to sign invitation links.

### FileHandlerServiceConfig

* **Enable**: Enables interaction with the file-handlers service (document upload, conversion, previews).\
  Example: `true`
* **Address**: API address of the file-handlers service.\
  Example: `http://flip-file-handlers:8080/api`

### Documents

* **Enable**: Enables the documents feature on boards.\
  Example: `true`

### McpAgentTokens

Authorization of AI agents through the [MCP server](/en/on-premise/config/mcp).

* **Enable**: Enables issuing tokens to agents via OAuth. Must be `true` when the MCP server is used.\
  Example: `true`
* **OAuth.Clients**: List of OAuth clients. By default, it contains the built-in `flip-mcp` client (matches `flipApi.clientId` in the mcp-server configuration) with the callback URLs `http://localhost:*`, `https://claude.ai/api/mcp/auth_callback`, `https://claude.com/api/mcp/auth_callback` and the scopes `flip:read`, `flip:write`, `comment:read`. Set it only if you need to replace the built-in list; the value you set replaces that list entirely.
  * **id**: Client ID.
  * **name**: Display name shown on the access consent screen.
  * **redirectURIPatterns**: Allowed callback URLs of MCP clients.
  * **scopes**: Scopes granted to the client.
  * **isPublic**: Public client (PKCE, no client secret). Value: `true`.
