Deploy production ready authorizer.dev instance on Render with a managed PostgreSQL database and build with it in 30seconds
After clicking the above button, follow the steps mentioned below:
Enter the name for your instance.
Note: Optionally you can choose to deploy a branch
without-postgresand configure database env, if you already have a postgres instance running.
Authorizer v2 requires the following variables. Configure them in Render's environment settings:
| Variable | Description | Example |
|---|---|---|
DATABASE_TYPE |
Database type | postgres |
DATABASE_URL |
Database connection string | (auto-configured by Render) |
JWT_TYPE |
JWT signing algorithm | HS256 |
JWT_SECRET |
JWT signing secret | test |
ENCRYPTION_KEY |
At-rest key for TOTP secrets and OTP digests. Required with RS*/ES* |
(output of openssl rand -hex 32) |
ADMIN_SECRET |
Admin secret for admin operations | admin |
CLIENT_ID |
Client identifier (required) | 123456 |
CLIENT_SECRET |
Client secret (required) | secret |
| Variable | Description | Default |
|---|---|---|
METRICS_HOST |
Bind address for /metrics (--metrics-host) |
127.0.0.1 |
METRICS_PORT |
Port for /metrics (--metrics-port) |
8081 |
RATE_LIMIT_RPS |
Per-IP requests/sec (--rate-limit-rps) |
30 |
RATE_LIMIT_BURST |
Per-IP burst (--rate-limit-burst) |
20 |
RATE_LIMIT_FAIL_CLOSED |
true = 503 on rate-limit backend errors (--rate-limit-fail-closed) |
false |
REDIS_URL |
Redis for sessions + shared rate limits if you scale to multiple instances | (unset) |
These are mapped to CLI flags at startup.
ENABLE_EMAIL_VERIFICATION=true with no SMTP configured is now a fatal boot
error, not a warning. Every account-recovery route ends at the same mailbox,
so without a mail path a user is created unverified and can never recover. If
you set it, also set SMTP_HOST, SMTP_PORT and SMTP_SENDER_EMAIL — all
three — or the container will exit on start.
APP_COOKIE_SAME_SITE is now validated at boot too: an unrecognised value
exits rather than silently falling back to lax.
Two optional flags were added for the 2.4.0 security changes, both defaulting to the secure behaviour:
OAUTH_ALLOW_UNVERIFIED_PROVIDER_EMAIL— a social login whose provider did not attest the email address no longer reaches an existing account. Settrueonly as a temporary compatibility measure.FGA_ALLOW_UNCONSTRAINED_AGENTS— a delegated (agent-acting-for-user) check against an authorization model with notype agentnow denies. Settrueonly while migrating a model.
MICROSOFT_ALLOWED_TENANTS restricts which Entra tenants may sign in when
MICROSOFT_TENANT_ID is a multi-tenant alias (common/organizations/
consumers).
Please refer to the server configuration docs for all available flags.
- Source repo: https://github.com/authorizerdev/authorizer
- Docs: https://docs.authorizer.dev/deployment/render/
-
You can update the docker image to the desired version in your repository which gets created with your deployment.