# Host deployment: remote admin UI behind HTTPS, SQLite, built-in accounts.
# Required environment: MCPHUB_PUBLIC_URL,
# MCPHUB_ADMIN_PUBLIC_URL, MCPHUB_CONFIG_KEY.
# The key is Base64-encoded 32 bytes; retain the same key across restarts.
# See deploy/README.md / deploy/README.zh-CN.md for registration and proxy setup.
# User portal and standard OAuth for MCPBridge are enabled.

server:
  listen: "127.0.0.1:8080"
  public_url: ${MCPHUB_PUBLIC_URL}
auth:
  mode: builtin
  # Enterprise membership must be reverified within this interval.
  # 企业成员关系需在此期限内重新验证。
  enterprise_membership_max_age: 24h
admin:
  enabled: true
  mode: remote
  listen: "127.0.0.1:8081"
  public_url: ${MCPHUB_ADMIN_PUBLIC_URL}
  client_id: mcphub-admin
  required_scopes: [mcphub:admin]
  database_driver: sqlite
  # Relative to this YAML file: deploy/data/mcphub.db when used from this path.
  database_path: ./data/mcphub.db
  # Environment variable NAME, not ${...} and not the key itself.
  encryption_key_env: MCPHUB_CONFIG_KEY

# Register services in the admin UI/API. YAML backends seed an empty DB only once.
client_authorization:
  enabled: true
  require_client_grant: true
  client_id: mcphub-portal

backends: []
