Environment Variables
MockForge supports extensive configuration through environment variables. This page documents all available environment variables, their purposes, and usage examples.
Core Functionality
Server Control
-
MOCKFORGE_LATENCY_ENABLED=true|false(default:true)- Enable/disable response latency simulation
- When disabled, responses are immediate
-
MOCKFORGE_FAILURES_ENABLED=true|false(default:false)- Enable/disable failure injection
- When enabled, can simulate HTTP errors and timeouts
-
MOCKFORGE_OVERRIDES_ENABLED=true|false(default:true)- Sets the
core.overrides_enabledconfig field (1/trueenables; any other value disables) - Note: no code reads this field yet, so it does not currently turn the
overrides:rules on or off; they apply whenever they are configured
- Sets the
-
MOCKFORGE_LOG_LEVEL=debug|info|warn|error(default:info)- Set the logging verbosity level
- Available:
debug,info,warn,error
Recording and Replay
Recording, replay, and proxy modes are configured via CLI flags (--record,
--replay, --proxy-target) and YAML, not env vars. See the
Recording & Capture chapter
for the full surface.
HTTP Server Configuration
Server Settings
-
MOCKFORGE_HTTP_PORT=3000(default:3000)- Port for the HTTP server to listen on
-
MOCKFORGE_HTTP_HOST=127.0.0.1(default:0.0.0.0)- Host address for the HTTP server to bind to
The OpenAPI spec path is set via --spec, MOCKFORGE_OPENAPI_SPEC_URL, or
the http.spec YAML field. CORS, request timeouts, and other middleware
options are YAML-configured under the relevant section (see CLI --help).
Validation and Templating
-
MOCKFORGE_REQUEST_VALIDATION=enforce|warn|off(default:enforce)- Level of request validation
enforce: Reject invalid requests with errorwarn: Log warnings but allow requestsoff: Skip validation entirely
-
MOCKFORGE_RESPONSE_VALIDATION=true|false(default:false)- Enable validation of generated responses
- Useful for ensuring response format compliance
-
MOCKFORGE_RESPONSE_TEMPLATE_EXPAND=true|false(default:false)- Enable template expansion in responses
- Allows use of
{{uuid}},{{now}}, etc. in responses
-
MOCKFORGE_AGGREGATE_ERRORS=true|false(default:true)- Aggregate multiple validation errors into a single response
- When enabled, returns all validation errors at once
-
MOCKFORGE_VALIDATION_STATUS=400|422(default:400)- HTTP status code for validation errors
400: Bad Request (general)422: Unprocessable Entity (validation-specific)
WebSocket Server Configuration
Server Settings
-
MOCKFORGE_WS_PORT=3001(default:3001)- Port for the WebSocket server to listen on
-
MOCKFORGE_WS_HOST=127.0.0.1(default:0.0.0.0)- Host address for the WebSocket server to bind to
Connection timeouts are YAML-only (websocket.connection_timeout_secs).
Replay Configuration
MOCKFORGE_WS_REPLAY_FILE=path/to/replay.jsonl- Path to WebSocket replay file
- Enables scripted WebSocket message sequences
gRPC Server Configuration
Server Settings
MOCKFORGE_GRPC_PORT=50051(default:50051)- Port for the gRPC server to listen on
Host binding for the gRPC server is YAML-only (grpc.host).
Admin UI Configuration
Server Settings
-
MOCKFORGE_ADMIN_ENABLED=true|false(default:false)- Enable/disable the Admin UI
- When enabled, provides web interface for management
-
MOCKFORGE_ADMIN_PORT=9080(default:9080)- Port for the Admin UI server to listen on
-
MOCKFORGE_ADMIN_HOST=127.0.0.1(default:127.0.0.1)- Host address for the Admin UI server to bind to
UI Configuration
-
MOCKFORGE_ADMIN_MOUNT_PATH=/admin(default: none)- Mount path for embedded Admin UI
- When set, Admin UI is available under HTTP server
-
MOCKFORGE_ADMIN_API_ENABLED=true|false(default:true)- Enable/disable Admin UI API endpoints
- Controls whether
/__mockforge/*endpoints are available
Data Generation Configuration
Faker Control
-
MOCKFORGE_RAG_ENABLED=true|false(default:false)- Enable Retrieval-Augmented Generation for data
- Requires additional setup for LLM integration
-
MOCKFORGE_FAKE_TOKENS=true|false(default:true)- Enable/disable faker token expansion
- Controls whether
{{faker.email}}etc. work
RAG / LLM Provider
MOCKFORGE_RAG_PROVIDER=openai|anthropic|ollama(default:openai)- LLM provider for retrieval-augmented generation.
MOCKFORGE_RAG_API_KEY=<key>— provider API key (falls back toOPENAI_API_KEYwhen unset).MOCKFORGE_RAG_API_ENDPOINT=<url>— custom endpoint, overrides the provider default.MOCKFORGE_RAG_MODEL=<name>— e.g.gpt-4,claude-3-5-sonnet,llama3.MOCKFORGE_RAG_TEMPERATURE=<float>(default:0.7).MOCKFORGE_RAG_MAX_TOKENS=<int>(default:2048).MOCKFORGE_RAG_CONTEXT_WINDOW=<int>(default:4096).MOCKFORGE_RAG_TIMEOUT_SECONDS=<int>(default:30).MOCKFORGE_RAG_MAX_RETRIES=<int>(default:3).OPENAI_API_KEY=<key>— fallback whenMOCKFORGE_RAG_API_KEYis unset.
Embedding (vector search)
MOCKFORGE_EMBEDDING_PROVIDER=openai|local|ollama— provider for embeddings used by RAG.MOCKFORGE_EMBEDDING_MODEL=<name>— e.g.text-embedding-3-small.MOCKFORGE_EMBEDDING_ENDPOINT=<url>— custom endpoint.MOCKFORGE_SIMILARITY_THRESHOLD=<float>(0.0–1.0) — minimum match score.
Registry / Marketplace
MOCKFORGE_REGISTRY_TOKEN=<token>— auth token for publishing scenarios or plugins to the registry. Required formockforge scenario publishand similar commands.MOCKFORGE_PLUGIN_REGISTRY_URL=<url>— registry endpoint used bymockforge plugin install/publish(default: the public mockforge.dev registry).
OpenAPI / Spec Loading
MOCKFORGE_OPENAPI_SPEC_URL=<url>— alternative to--spec; load the OpenAPI spec from a URL at startup. Useful in containerized deployments where the spec lives behind a static CDN.
Distributed Tracing (OpenTelemetry / OTLP)
MOCKFORGE_OTLP_ENDPOINT=<url>— OTLP collector endpoint (e.g.http://jaeger:4317orhttp://otel-collector:4318).MOCKFORGE_OTLP_SERVICE_NAME=<name>— service name attached to spans (default:mockforge).MOCKFORGE_OTLP_SAMPLING_RATE=<float>—0.0–1.0.1.0= trace every request.
Rate Limiting
MOCKFORGE_RATE_LIMIT_ENABLED=true|false— toggle the HTTP middleware rate limiter.MOCKFORGE_RATE_LIMIT_DISABLED=true|false— explicit opt-out (overrides config-fileenabled: true). Useful for--no-rate-limitparity in containers.MOCKFORGE_RATE_LIMIT_RPM=<int>— global requests-per-minute cap.
Kafka Protocol
MOCKFORGE_KAFKA_ENABLED=true|false— start the Kafka mock listener.MOCKFORGE_KAFKA_ADVERTISED_HOST=<host>— hostname advertised in metadata responses (defaults to the bind host).MOCKFORGE_KAFKA_ADVERTISED_PORT=<int>— port advertised in metadata responses (defaults to the bind port).MOCKFORGE_KAFKA_FIXTURES_DIR=path/to/kafka-fixtures— directory of pre-recorded Kafka topic fixtures.MOCKFORGE_KAFKA_RECORDING_DB=path/to/recording.sqlite— SQLite file for recording produce/consume exchanges; when set, every Kafka exchange is persisted for replay.
AMQP / MQTT Protocol
MOCKFORGE_AMQP_RECORDING_DB=path/to/recording.sqlite— SQLite file for recording AMQP publish/deliver exchanges; when set, every exchange is persisted for replay. Unset or unusable path is a no-op.MOCKFORGE_MQTT_RECORDING_DB=path/to/recording.sqlite— SQLite file for recording MQTT publish/deliver exchanges; when set, every exchange is persisted for replay. Unset or unusable path is a no-op.
Federation
MOCKFORGE_FEDERATION_POLL_URL=<url>— upstream MockForge instance to poll for shared workspaces.MOCKFORGE_FEDERATION_POLL_TOKEN=<token>— auth token for the upstream poll.MOCKFORGE_FEDERATION_POLL_INTERVAL_SECS=<int>— poll cadence (default: 60).MOCKFORGE_FEDERATION_WORKSPACE_ID=<uuid>— workspace this instance federates into.
Encryption / Secret Storage
MOCKFORGE_ENCRYPTION_KEY=<base64-key>— base64-encoded AES-256 key used to encrypt config/data at rest.MOCKFORGE_MASTER_KEY=<base64-key>— master KEK that wraps per-workspace data encryption keys.MOCKFORGE_BYOK_ENCRYPTION_KEY=<base64-key>— bring-your-own-key override for workspace encryption.MOCKFORGE_SECRET_PROVIDER=env|aws|vault|gcp|azure— backend used by the secret-resolution layer (default:env).MOCKFORGE_SECRET_CACHE_TTL=<secs>— how long resolved secrets stay in the in-process cache.MOCKFORGE_KMS_PROVIDER=aws|gcp|azure|vault— when set, MockForge fetches the master key from a managed KMS instead of usingMOCKFORGE_MASTER_KEY.MOCKFORGE_KMS_REGION=<region>— region for the KMS provider (e.g.us-east-1).MOCKFORGE_VAULT_ADDR=<url>— Vault server address when usingMOCKFORGE_KMS_PROVIDER=vault.MOCKFORGE_VAULT_TOKEN=<token>— Vault auth token.
Database (registry server / collab)
These apply to the multi-tenant registry server and the collab workspace backend; the OSS local mock server doesn’t need them.
MOCKFORGE_DB_TYPE=sqlite|postgres— backing store for the registry / collab.MOCKFORGE_DB_CONNECTION=<url>— connection string (e.g.postgres://user:pass@host/dborsqlite:./mockforge.db).
Fixtures and Testing
Fixtures Configuration
MOCKFORGE_FIXTURES_DIR=path/to/fixtures(default:./fixtures)- Directory where fixtures are stored
- Used for recording and replaying HTTP requests
Authentication (OIDC)
MOCKFORGE_OIDC_ENABLED=true|false— enable OpenID Connect for the admin API and proxied routes.MOCKFORGE_OIDC_ISSUER=<url>— issuer URL whose/.well-known/openid-configurationMockForge will fetch.MOCKFORGE_OIDC_CONFIG=<path>— path to a YAML/JSON file overriding individual OIDC discovery fields.MOCKFORGE_OIDC_SECRET=<client-secret>— confidential-client secret for the configuredclient_id.
Registry session cookies (registry server)
MOCKFORGE_SESSION_COOKIE_SECURE=true|false— setSecure; SameSite=Noneon themockforge_session/mockforge_refreshauth cookies. Required for hosted HTTPS deployments where the admin UI is served from a different origin than the API; self-hosted plain-HTTP setups keepSameSite=LaxwithoutSecure.
Hot Reload
Watch the spec / config / fixtures dirs and rebuild routes on change without restarting.
MOCKFORGE_HOT_RELOAD_ENABLED=true|false— master switch.MOCKFORGE_HOT_RELOAD_SPEC=true|false— watch the OpenAPI spec file.MOCKFORGE_HOT_RELOAD_FIXTURES=true|false— watch the fixtures directory.MOCKFORGE_HOT_RELOAD_DEBOUNCE=<ms>— coalesce rapid filesystem events into a single reload.MOCKFORGE_HOT_RELOAD_INTERVAL=<ms>— polling fallback when filesystem events aren’t available.MOCKFORGE_HOT_RELOAD_TIMEOUT=<ms>— upper bound on a single reload before it’s aborted.MOCKFORGE_HOT_RELOAD_GRACEFUL=true|false— drain in-flight requests before swapping routes.MOCKFORGE_HOT_RELOAD_VALIDATE=true|false— re-run validation on every reload (safer; slower).
Plugins
MOCKFORGE_PLUGINS_ENABLED=true|false— load.so/.dylib/.wasmplugins on startup.MOCKFORGE_PLUGIN_CACHE_DIR=<path>— where downloaded plugins are cached.MOCKFORGE_PLUGIN_TIMEOUT_MS=<ms>— per-invocation timeout for plugin calls.MOCKFORGE_PLUGIN_MAX_CONCURRENT=<int>— max concurrent plugin invocations across the process.MOCKFORGE_PLUGIN_MAX_CPU=<percent>— CPU budget per plugin (0–100).MOCKFORGE_PLUGIN_MAX_MEMORY=<bytes>— memory cap per plugin.MOCKFORGE_PLUGIN_MAX_MODULE_SIZE=<bytes>— max accepted plugin binary size.MOCKFORGE_PLUGIN_NETWORK_ACCESS=true|false— allow plugins to make outbound network calls.
Compression
MOCKFORGE_COMPRESSION_ENABLED=true|false— gzip/deflate/zstd response bodies above the threshold.MOCKFORGE_COMPRESSION_ALGORITHM=gzip|deflate|zstd|br— preferred compression codec when the client accepts multiple.MOCKFORGE_COMPRESSION_LEVEL=<int>— codec-specific level (e.g. 1–9 for gzip).
Resilience
MOCKFORGE_CIRCUIT_BREAKER_ENABLED=true|false— wrap upstream calls (proxy / record-replay) in a circuit breaker.MOCKFORGE_CIRCUIT_BREAKER_THRESHOLD=<int>— consecutive failures before the breaker opens.MOCKFORGE_POOL_MAX_CONNECTIONS=<int>— outbound HTTP connection pool size.MOCKFORGE_POOL_IDLE_TIMEOUT=<secs>— close idle connections after this duration.
Performance Tuning
MOCKFORGE_WORKER_THREADS=<int>— Tokio worker-thread count (default: number of CPU cores).MOCKFORGE_MAX_BODY_SIZE=<bytes>— reject inbound HTTP bodies larger than this.
Proxy / Record-Replay
MOCKFORGE_PROXY_UPSTREAM=<url>— when set, requests with no matching mock are proxied here. Pair withmockforge serve --recorder(or the recorder admin API) to capture upstream traffic for replay.MOCKFORGE_PROXY_SPEC=<path>— OpenAPI/Swagger spec (JSON or YAML) backing the proxy’s passive conformance tap (#864).MOCKFORGE_PROXY_VALIDATE_CONFORMANCE=true|false— validate proxied requests against the spec and report violations; requiresMOCKFORGE_PROXY_SPEC.MOCKFORGE_PROXY_VALIDATE_CONFORMANCE_STRICT=true|false— additionally reject non-conforming requests with a diagnostic response instead of forwarding.
Tunneling
MOCKFORGE_TUNNEL_SERVER_URL=<url>— control-plane URL for the MockForge tunnel server (used whenmockforge tunnel start).MOCKFORGE_TUNNEL_AUTH_TOKEN=<token>— auth token for the tunnel control plane.
Observability
Metrics CSV Log
MOCKFORGE_METRICS_LOG_FILE=path/to/metrics.csv- When set, the admin server’s system-monitoring task appends one CSV row
every 10 s with
timestamp,cpu_pct,mem_mb,total_reqs,err_rate. - Survives restarts; chartable in any spreadsheet, Grafana, or dashboarding tool.
- Example:
MOCKFORGE_METRICS_LOG_FILE=/var/log/mockforge-metrics.csv - The TUI dashboard also tracks lifetime peak CPU%, memory MB, and
error rate in-memory and renders them as
current (peak X)next to the live values.
- When set, the admin server’s system-monitoring task appends one CSV row
every 10 s with
Configuration Files
The config file path is set via --config <path>, not env var. MockForge
also auto-discovers mockforge.yaml / mockforge.yml / mockforge.json
in the working directory.
Usage Examples
Basic HTTP Server with OpenAPI
export MOCKFORGE_OPENAPI_SPEC_URL=file://./examples/openapi-demo.json
export MOCKFORGE_RESPONSE_TEMPLATE_EXPAND=true
export MOCKFORGE_ADMIN_ENABLED=true
cargo run -p mockforge-cli -- serve --http-port 3000 --admin-port 9080
Full WebSocket Support
export MOCKFORGE_WS_REPLAY_FILE=examples/ws-demo.jsonl
export MOCKFORGE_WS_PORT=3001
export MOCKFORGE_OPENAPI_SPEC_URL=file://./examples/openapi-demo.json
export MOCKFORGE_RESPONSE_TEMPLATE_EXPAND=true
cargo run -p mockforge-cli -- serve --admin
Development Setup
export MOCKFORGE_LOG_LEVEL=debug
export MOCKFORGE_LATENCY_ENABLED=false
export MOCKFORGE_RESPONSE_TEMPLATE_EXPAND=true
export MOCKFORGE_ADMIN_ENABLED=true
export MOCKFORGE_OPENAPI_SPEC_URL=file://./examples/openapi-demo.json
cargo run -p mockforge-cli -- serve
Production Setup
export MOCKFORGE_LOG_LEVEL=warn
export MOCKFORGE_LATENCY_ENABLED=true
export MOCKFORGE_FAILURES_ENABLED=false
export MOCKFORGE_REQUEST_VALIDATION=enforce
export MOCKFORGE_ADMIN_ENABLED=false
export MOCKFORGE_OPENAPI_SPEC_URL=file://./path/to/production-spec.json
cargo run -p mockforge-cli -- serve --http-port 80
Environment Variable Priority
Environment variables override configuration file settings. CLI flags take precedence over both. The priority order is:
- CLI flags (highest priority)
- Environment variables
- Configuration file settings
- Default values (lowest priority)
Security Considerations
- Be careful with
MOCKFORGE_ADMIN_ENABLED=truein production - Consider setting restrictive host bindings (
127.0.0.1) for internal use - Use
MOCKFORGE_FAKE_TOKENS=falsefor deterministic testing - Review CORS settings for cross-origin requests
Troubleshooting
Common Issues
-
Environment variables not taking effect
- Check variable names for typos
- Ensure variables are exported before running the command
- Use
env | grep MOCKFORGEto verify variables are set
-
Port conflicts
- Use different ports via
MOCKFORGE_HTTP_PORT,MOCKFORGE_WS_PORT, etc. - Check what processes are using ports with
netstat -tlnp
- Use different ports via
-
OpenAPI spec not loading
- Verify file path in
MOCKFORGE_OPENAPI_SPEC_URL - Ensure JSON/YAML syntax is valid
- Check file permissions
- Verify file path in
-
Template expansion not working
- Set
MOCKFORGE_RESPONSE_TEMPLATE_EXPAND=true - Verify token syntax (e.g.,
{{uuid}}not{uuid})
- Set
Operator and Deployment Variables
These are read by the hosted/cloud components (registry server, plugin host,
plugin egress proxy, test runner) rather than by mockforge serve. Most are
unset in a normal self-hosted deployment and only matter when running the
managed stack. Defaults below are the values the code falls back to.
HTTP keep-alive hints
MOCKFORGE_HTTP_KEEPALIVE_TIMEOUT_SECS(default:120)- Idle timeout advertised in the
Keep-Aliveresponse header
- Idle timeout advertised in the
MOCKFORGE_HTTP_KEEPALIVE_MAX_REQUESTS(default:1000)- Max requests per connection advertised in the
Keep-Aliveresponse header
- Max requests per connection advertised in the
Contract diff and drift capture
MOCKFORGE_CONTRACT_DIFF_MAX_BODY_MB(default:10)- Largest response body, in MB, the contract-diff middleware will buffer
MOCKFORGE_DRIFT_MAX_BODY_MB(default:10)- Same cap for the drift-tracking middleware
MOCKFORGE_CONTRACT_PROBE_INTERVAL_SECS(default:1800)- Interval for the background contract probe. Values below
60are ignored
- Interval for the background contract probe. Values below
Capture forwarding (cloud sync)
MOCKFORGE_CLOUD_CAPTURES_FORWARDER_URL(default: unset)- Endpoint captures are forwarded to. Falls back to
MOCKFORGE_CAPTURE_INGEST_URL. Forwarding is off when neither is set
- Endpoint captures are forwarded to. Falls back to
MOCKFORGE_CAPTURE_FORWARDER_BUFFER(default:1024)- In-memory queue depth for pending captures
MOCKFORGE_CAPTURE_FORWARDER_TIMEOUT_MS(default:5000)- HTTP timeout for each forward attempt
Kafka
MOCKFORGE_KAFKA_OFFSETS_DB(default: unset)- Path to persist consumer-group offsets. Unset or empty keeps offsets in memory only, so they are lost on restart
Observability
MOCKFORGE_OTLP_GRPC_PORT(default:4317)- Port the registry server listens on for OTLP/gRPC telemetry
Hosted deployments
MOCKFORGE_CLOUD_PLUGINS_IMAGE(default:ghcr.io/saasy-solutions/mockforge-cloud-plugins:latest)- Container image for plugin-enabled hosted mocks. Non-plugin deployments use
MOCKFORGE_DOCKER_IMAGE
- Container image for plugin-enabled hosted mocks. Non-plugin deployments use
MOCKFORGE_HOSTED_OVERAGE_CEILING_MULT(default:0)- Multiple of the plan limit at which hosted traffic is cut off.
0disables the ceiling. Values must be positive to take effect
- Multiple of the plan limit at which hosted traffic is cut off.
MOCKFORGE_MANAGEMENT_TOKEN(default: unset)- Set by the registry on every hosted mock. When set,
mockforge serverejects writes (anything but GET, HEAD, OPTIONS) to MockForge’s own control routes (/__mockforge/*,/api/chaos,/api/recorder,/api/world-state, and the other management APIs) with 401 unless the request carries the token inX-MockForge-Management-TokenorAuthorization: Bearer. Reads and your mocked API are unaffected. Leave it unset for self-hosted servers
- Set by the registry on every hosted mock. When set,
Incident dispatch
MOCKFORGE_PAGERDUTY_ENQUEUE_URL(default:https://events.pagerduty.com/v2/enqueue)- Override for the PagerDuty Events API endpoint, for testing or a proxy
Platform LLM (managed test generation)
MOCKFORGE_PLATFORM_LLM_PROVIDER(default:openai)MOCKFORGE_PLATFORM_LLM_MODEL(default:gpt-4o-mini)MOCKFORGE_PLATFORM_LLM_ENDPOINT(default: unset)- Base URL override, for a self-hosted or proxied provider
Test runner
MOCKFORGE_RUNNER_QUEUE_KEY(default:test_runs:queued)- Redis key the runner pops queued test runs from
MOCKFORGE_RUNNER_MAX_CONCURRENT_JOBS(default:4)MOCKFORGE_RUNNER_POLL_TIMEOUT_SECS(default:5)
Plugin egress proxy
MOCKFORGE_PLUGIN_EGRESS_LISTEN(default:127.0.0.1:8125)- Listen address for the egress proxy
MOCKFORGE_PLUGIN_EGRESS_ALLOWLIST(default: unset)- Comma-separated hosts plugins may reach. Takes precedence over the file form
MOCKFORGE_PLUGIN_EGRESS_ALLOWLIST_FILE(default: unset)- Path to an allowlist file, one host per line
Plugin host
MOCKFORGE_PLUGIN_HOST_SOCKET(default:/tmp/plugin-host.sock)- Unix socket the plugin host listens on
MOCKFORGE_PLUGIN_HOST_SOCKET_MODE(default: platform default)- Permission bits for that socket. Accepts
0o660,660,0660or0x1B0
- Permission bits for that socket. Accepts
MOCKFORGE_PLUGIN_HOST_SIGNATURE_MODE=required|optional(default:optional)- Whether plugin signatures are enforced. An unrecognised value falls back to
optionalwith a warning, so set this explicitly in production
- Whether plugin signatures are enforced. An unrecognised value falls back to
Trusted signing keys, one of:
MOCKFORGE_PLUGIN_HOST_TRUSTED_KEYS(default: unset)- Inline comma-separated public keys
MOCKFORGE_PLUGIN_HOST_TRUSTED_KEYS_FILE(default: unset)- Path to a file of public keys
Remote trust root, blocklist, rotation and metrics are each off unless their URL is set. The bearer and interval variables only apply once the matching URL is present:
Trust root:
MOCKFORGE_PLUGIN_HOST_TRUST_ROOT_URL(default: unset, feature off)MOCKFORGE_PLUGIN_HOST_TRUST_ROOT_BEARER(default: unset)MOCKFORGE_PLUGIN_HOST_TRUST_ROOT_INTERVAL_SECS(default: built-in interval)
Blocklist:
MOCKFORGE_PLUGIN_HOST_BLOCKLIST_URL(default: unset, feature off)MOCKFORGE_PLUGIN_HOST_BLOCKLIST_BEARER(default: unset)MOCKFORGE_PLUGIN_HOST_BLOCKLIST_INTERVAL_SECS(default: built-in interval)
Key rotation:
MOCKFORGE_PLUGIN_HOST_ROTATION_INTERVAL_SECS(default: built-in interval)MOCKFORGE_PLUGIN_HOST_ROTATION_BEARER(default: unset)
Metrics export:
MOCKFORGE_PLUGIN_HOST_METRICS_URL(default: unset, export off)MOCKFORGE_PLUGIN_HOST_METRICS_BEARER(default: unset)MOCKFORGE_PLUGIN_HOST_METRICS_FLUSH_INTERVAL_SECS(default: built-in interval)MOCKFORGE_PLUGIN_HOST_METRICS_QUEUE_SIZE(default: built-in queue depth)
Test-only escape hatches
Both relax SSRF protection and must never be set in production. Each accepts
1 or true; anything else leaves the guard strict.
MOCKFORGE_SSRF_ALLOW_LOOPBACK(default: unset, guard strict)- Allows conformance/test-run targets to point at loopback addresses
MOCKFORGE_SSO_ALLOW_INSECURE_ISSUERS(default: unset, guard strict)- Allows
http://and localhost OIDC issuers. Logs a warning when set, because it disables the issuer SSRF guard that protects the verified-domain trust model
- Allows
For more detailed configuration options, see the Configuration Files documentation.