Peren documentation
Credentials and secrets
Choose Worker secret strings, provider environment variables, or minted tokens by what the call path actually checks.
Use the credential surface that matches who must see the value and which process checks it.
Worker secret string
Use a Worker secret when application code must read the value from env.
Declare the secret on the service. A missing resolved value fails the process before listeners open. The Worker receives a string. Rotate with Rotate secrets.
[services.secrets]
STRIPE_SECRET_KEY = { source = "store", name = "services/api/STRIPE_SECRET_KEY" }
export default {
async fetch(request, env) {
return fetch("https://api.stripe.com/v1/customers", {
headers: { authorization: `Bearer ${env.STRIPE_SECRET_KEY}` },
});
},
};
A secrets-store binding also resolves to a string on env. Prefer one declared secret name per capability the Worker must call itself.
Provider environment variable
Use a provider environment variable when the node must hold a credential the Worker must not read.
Examples:
- AWS SigV4
access_key_env,secret_key_env, and optionaltoken_envforconfiguredorenvironmentcredential sources. Signing runs in the node. The Worker cannot read the keys. - Client mTLS
cert_pem_envandkey_pem_envontype = "mtls_certificate". Pass the binding asfetch(url, { cf: { mtlsCertificate: env.NAME } }). The Worker cannot read the PEM. - Object-store, broker, AI, and vector provider credentials named by the provider configuration.
Do not copy those values into [services.secrets] unless the Worker itself must present them.
peren credential mint
Mint a scoped token when an operator or automation needs a signed tenant credential with an explicit bucket prefix and scopes.
peren credential mint ./credential-keys \
--tenant acme \
--bucket-prefix tenants/acme \
--scope r2:read \
--scopes r2:write
The command prints one token to stdout. The token expires 15 minutes after mint. Scopes must be non-empty ASCII tokens using letters, digits, and :, -, _, or ..
authorize exists for scope and bucket-prefix checks against a minted token. That check is not wired into the Worker request path. Do not treat a minted token as something Peren verifies on every R2 request.
peren credential node
Mint a node identity token when joining a node to the fleet registry.
peren credential node ./credential-keys \
--cluster prod \
--node 00000000-0000-0000-0000-000000000001 \
--peer-addr 127.0.0.1:7000
The command prints one token to stdout. The token expires 15 minutes after mint. peren node join verifies the token against the same key directory, then writes an active membership record. Verification happens at join time, not on every peer request.
Rotation
Rotate Worker secret strings with Rotate secrets. Rotate provider env vars in the host environment or secret manager that supplies them, then restart or reload processes that read those names. Minted tokens expire; mint a new token when the previous one is past expires_at_ms.