Deploy production ready authorizer.dev instance on Render with a managed PostgreSQL database and build with it in 30seconds
After clicking the above button, follow the steps mentioned below:
Enter the name for your instance.
Note: Optionally you can choose to deploy a branch
without-postgresand configure database env, if you already have a postgres instance running.
Authorizer v2 requires the following variables. Configure them in Render's environment settings:
| Variable | Description | Example |
|---|---|---|
DATABASE_TYPE | Database type | postgres |
DATABASE_URL | Database connection string | (auto-configured by Render) |
AUTHORIZER_URL | This deployment's own public base URL (required). Not the same as allowed origins — this is where Authorizer itself lives. The server exits at boot without it | https://your-app.onrender.com |
JWT_TYPE | JWT signing algorithm | HS256 |
JWT_SECRET | JWT signing secret | test |
ENCRYPTION_KEY | At-rest key for TOTP secrets and OTP digests. Required with RS*/ES* | (output of openssl rand -hex 32) |
ADMIN_SECRET | Admin secret for admin operations | admin |
CLIENT_ID | Client identifier (required) | 123456 |
CLIENT_SECRET | Client secret (required) | secret |
| Variable | Description | Default |
|---|---|---|
METRICS_HOST | Bind address for /metrics (--metrics-host) | 127.0.0.1 |
METRICS_PORT | Port for /metrics (--metrics-port) | 8081 |
RATE_LIMIT_RPS | Per-IP requests/sec (--rate-limit-rps) | 30 |
RATE_LIMIT_BURST | Per-IP burst (--rate-limit-burst) | 20 |
RATE_LIMIT_FAIL_CLOSED | true = 503 on rate-limit backend errors (--rate-limit-fail-closed) | false |
REDIS_URL | Redis for sessions + shared rate limits if you scale to multiple instances | (unset) |
These are mapped to CLI flags at startup.
ENABLE_EMAIL_VERIFICATION=true with no SMTP configured is now a fatal boot
error, not a warning. Every account-recovery route ends at the same mailbox,
so without a mail path a user is created unverified and can never recover. If
you set it, also set SMTP_HOST, SMTP_PORT and SMTP_SENDER_EMAIL — all
three — or the container will exit on start.
APP_COOKIE_SAME_SITE is now validated at boot too: an unrecognised value
exits rather than silently falling back to lax.
Two optional flags were added for the 2.4.0 security changes, both defaulting to the secure behaviour:
OAUTH_ALLOW_UNVERIFIED_PROVIDER_EMAIL— a social login whose provider did not attest the email address no longer reaches an existing account. Settrueonly as a temporary compatibility measure.FGA_ALLOW_UNCONSTRAINED_AGENTS— a delegated (agent-acting-for-user) check against an authorization model with notype agentnow denies. Settrueonly while migrating a model.
MICROSOFT_ALLOWED_TENANTS restricts which Entra tenants may sign in when
MICROSOFT_TENANT_ID is a multi-tenant alias (common/organizations/
consumers).
Please refer to the server configuration docs for all available flags.
- Source repo: https://github.com/authorizerdev/authorizer
- Docs: https://docs.authorizer.dev/deployment/render/
You can update the docker image to the desired version in your repository which gets created with your deployment.