npx @kldzj/sigillo self-host
npx @kldzj/sigillo self-host │ ├──> 1. Unlock ~/.sigillo/selfhost.json with your passphrase ├──> 2. Log in to Cloudflare (reuses wrangler login when present) ├──> 3. Download this version's release bundle from github.com/kldzj/sigillo, and check its SHA-256 ├──> 4. Create the app's D1 database and apply its migrations ├──> 5. Deploy the login provider (<name>-auth): D1, migrations, Worker ├──> 6. Deploy the app (<name>): Worker, static assets ├──> 7. Enable both workers.dev URLs └──> 8. Optionally attach a custom domain to the app
https://sigillo-auth.<your-subdomain>.workers.dev/api/auth/callback/google.--google-client-id and --google-client-secret.CLOUDFLARE_API_TOKEN environment variable (or --api-token)self-host runwrangler login (refreshed automatically if expired)npx @kldzj/sigillo self-host
@kldzj/sigillo deploys its own release, which is why npx @kldzj/sigillo without a version updates to the latest one. The bundle holds the code that runs with your secrets, so the CLI checks it against the SHA-256 that CI recorded in the npm package when it built both, and deploys nothing that doesn't match. It also refuses to deploy a version older than the one your instance runs, unless you pass --allow-downgrade.self-host against auth.sigillo.dev, keeps that provider on update: switching would give every user a new login.ENCRYPTION_KEY, separate from the BETTER_AUTH_SECRET that signs sessions. Deployments made before there was an ENCRYPTION_KEY keep deriving their key from BETTER_AUTH_SECRET.self-host saves both keys in ~/.sigillo/selfhost.json on the machine that ran it, together with the login provider's secret, the Google client and a Cloudflare login from the browser. The file is encrypted with a passphrase of at least 12 characters, chosen on the first run, and each run asks for it once. Keep the passphrase in your password manager; the file can then stay where it is.self-host refuses to reuse that database.SIGILLO_SELFHOST_PASSPHRASE. A file from before encryption is encrypted on the next run in a terminal, if you agree, or right away when the variable is set. To change the passphrase:npx @kldzj/sigillo self-host --change-passphrase
SIGILLO_ENCRYPTION_KEY on the first deploy:SIGILLO_ENCRYPTION_KEY="$(openssl rand -base64 32)" npx @kldzj/sigillo self-host
ENCRYPTION_KEY secret and saved in ~/.sigillo/selfhost.json. It cannot be set on an existing deployment, because a new key would make its stored secrets unreadable.npx @kldzj/sigillo self-host --allowed-users acme.com,ops@partner.io
--yes or without a terminal, pass --allowed-users, or anyone with a Google account can sign in. Only verified emails match: an address matches itself, a domain matches exactly that domain, not its subdomains. Nobody else can sign up or sign in, in the browser or with the CLI, and a signed-in user taken off the list is signed out on their next request. The app and its login provider both check it.~/.sigillo/selfhost.json. Pass --allowed-users again to change it, or --allowed-users '' to let anyone in.| Option | Description |
--name <name> | Worker name (default: sigillo); the login provider is <name>-auth |
--account <id> | Cloudflare account id (skips the account prompt) |
--api-token <token> | Cloudflare API token |
--google-client-id <id> | Google OAuth client ID for a new login provider |
--google-client-secret <secret> | Google OAuth client secret for a new login provider |
--allowed-users <list> | Email addresses and domains that may sign in, comma-separated; '' lets anyone in |
--domain <hostname> | Attach a custom domain to the app (the zone must be on your account) |
--skip-domain | Skip the custom domain prompt |
--bundle <path> | Deploy a local copy of this version's bundle, checked like a download |
--release-url <url> | Download this version's bundle from a custom URL, checked like a download |
--allow-downgrade | Deploy even if the instance runs a newer version |
--change-passphrase | Encrypt ~/.sigillo/selfhost.json with a new passphrase, then stop |
--reset-passkeys <email> | Remove every passkey of this user and sign them out, for a sole admin who lost theirs, then stop. See Hardening |
--yes | Accept all defaults, non-interactive |
CLOUDFLARE_API_TOKEN=xxx SIGILLO_SELFHOST_PASSPHRASE=xxx npx @kldzj/sigillo self-host --yes \ --google-client-id xxx.apps.googleusercontent.com --google-client-secret xxx \ --allowed-users acme.com
--api-url:sigillo login --api-url https://sigillo.<your-subdomain>.workers.dev
sigillo setup sigillo run -- next dev