Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Security settings

Admin authentication, JWT and OAuth2 egress policy, CORS, rate limits and the channel filter. Every table on these pages carries the wire name, the default the code uses, and the ORION_* override.

PageHolds
Admin authentication settingsenabling admin authentication, the accepted and read-only API keys, hashed key storage, and the credential header.
JWT verification settingsthe instance-wide egress policy for JWKS fetches, and why the per-issuer settings live on the channel or the jwt_verify task instead.
Inbound OAuth2 sign-in settingsthe instance-wide egress policy for token endpoints on private addresses, and what a channel’s block owns instead.
CORS settingsallowed origins, the additive allowed and exposed header lists, credentials, and preflight caching, with the production rules.
Rate limit settingsthe platform token bucket, per-plane limits, and trusted_proxies, which decides whether forwarded headers name the client.
Channel filter settingsinclude and exclude glob patterns over channel names, for running separate fleets off one database.

Last verified 14 September 2026