---
title: "Configuration"
description: "Every deploy setting, Worker variable and binding, and the permissions the deploy token needs."
---

## Deploy settings

`alchemy.run.ts` reads these from the environment. All are optional except the Cloudflare credentials.

| Variable | Default | Meaning |
| --- | --- | --- |
| `CLOUDFLARE_API_TOKEN` | required | The deploy token |
| `CLOUDFLARE_ACCOUNT_ID` | required | The account to deploy to |
| `PARSEW_DOMAIN` | unset | A zone in the account. Set, the Worker serves `app.<domain>` and `logo.<domain>`; unset, only `workers.dev`. Every hostname becomes a Workers custom domain: delete any DNS record those names already have first, since Alchemy can't take them over |
| `PARSEW_APP_HOST` | `app.<domain>` | The dashboard's hostname |
| `PARSEW_IMAGES_HOST` | `logo.<domain>` | The image API's hostname |
| `PARSEW_SITE_HOST` | unset | Serves the landing page there, with the docs at `/docs` (parsew.com's deployment). Unset, the docs are on the app host |
| `PARSEW_REDIRECT_HOSTS` | `www.<domain>` (with a site host) | Comma-separated hostnames that 301 to the site with path and query, through a zone redirect rule that runs before the Worker. Empty disables |
| `PARSEW_DOCS_HOST` | `docs.<domain>` (with a site host) | An old docs hostname: the Worker 301s it to `<site>/docs<path>`. Empty disables |
| `PARSEW_EMAIL_FROM` | unset | Sender address for the "you reached your limit" email and password resets, through Cloudflare Email Sending on the zone. Unset, no email is sent and "Forgot password" is hidden |
| `PARSEW_ALLOW_SIGNUP` | `true` | `false` closes sign-up (existing accounts keep working) |
| `PARSEW_AUTUMN_SECRET_KEY` | unset | Turns on hosted billing through [Autumn](https://useautumn.com). Leave unset when self-hosting |
| `PARSEW_WORKER_NAME` | `parsew` (`parsew-<stage>` outside prod) | The Worker's name, and the prefix of every resource |

## Deploy token permissions

Create a custom account API token with:

- Account: **Workers Scripts Edit**, **D1 Edit**, **Workers R2 Storage Edit**, **Account API Tokens Edit** (mints the Worker's read-only Analytics Engine token), **Account Settings Read**, **Secrets Store Edit** (Alchemy's state store keeps its bearer token there).
- With `PARSEW_DOMAIN`, on that zone: **Zone Read**, **DNS Edit**, **Workers Routes Edit**, **SSL and Certificates Edit**, and with a site host **Single Redirect Edit** (the `www.` redirect rule).
- With `PARSEW_EMAIL_FROM`: **Email Sending Edit**.

## Worker variables and secrets

Set by Alchemy; listed for reference and for local development (`.dev.vars`).

| Name | Kind | Meaning |
| --- | --- | --- |
| `APP_URL` | variable | The dashboard's origin (on workers.dev: the Worker's own URL) |
| `IMAGES_URL` | variable | The image API's base URL; unset means `APP_URL` + `/i` |
| `SITE_URL` | variable | The landing page's origin; unset serves no landing page |
| `DOCS_HOST` | variable | The old docs hostname (`docs.parsew.com`) that 301s to `SITE_URL/docs`; set only with a site |
| `AE_DATASET` | variable | The Analytics Engine dataset's name, for the SQL API |
| `CF_ACCOUNT_ID` | variable | The account, for the SQL API |
| `ALLOW_SIGNUP` | variable | `false` closes sign-up |
| `EMAIL_FROM` | variable | The sender address; unset turns email off |
| `BETTER_AUTH_SECRET` | secret | Signs sessions; generated once by Alchemy |
| `CF_ANALYTICS_TOKEN` | secret | Account Analytics Read, minted by Alchemy |
| `AUTUMN_SECRET_KEY` | secret | Hosted billing; unset turns billing off |
| `AUTUMN_API_URL` | variable | Autumn's API base (tests point it at a stand-in); default `https://api.useautumn.com/v1` |

## Bindings

| Binding   | Resource                                     |
| --------- | -------------------------------------------- |
| `DB`      | D1 database                                  |
| `SOURCES` | R2 bucket                                    |
| `USAGE`   | Analytics Engine dataset                     |
| `IMAGES`  | Images binding                               |
| `ASSETS`  | The built dashboard, landing page and docs   |
| `EMAIL`   | Email Sending, only with `PARSEW_EMAIL_FROM` |

Why each exists is in [Architecture](/self-hosting/architecture#bindings).
