deploy.ts

Rendering, uploads, origin checks, logging, authentication, sessions, rate limits, analytics, and content directories.

config/deploy.ts configures page rendering, file uploads, request origin checks, logging, email, the UI, user authentication, sessions, anonymous identities, OAuth 2.0, rate limits, analytics, and content directories. Settings are listed in the order they appear in websiteDeployCfg.

streamRender

Prop

Type

upload

Configure the file size limit, file delivery, and storage backend.

Prop

Type

delivery

Configure the path and cache response headers used when serving uploaded files through the Worker.

Prop

Type

cache

Prop

Type

storage

Configure the default storage backend and the settings for KV and R2.

Prop

Type

kv

Prop

Type

r2

Prop

Type

cors

Specify the HTTP methods allowed for cross-origin requests to each path. The type is Record<Path, HttpMethod[]>. Object keys must be site paths starting with /. Supported methods are GET, POST, PUT, PATCH, DELETE, OPTIONS, and HEAD.

The template defaults to an empty object. The source comments include this example:

cors: {
    // '/test': ['GET', 'POST'],
}

hosts

Prop

Type

Local development allows localhost and 127.0.0.1 by default. Production allows the host in VITE_SITE_URL by default, so only add extra rules here. Duplicate entries are ignored.

PatternMeaning
saavo.devMatches the exact host
*.saavo.devMatches subdomains
localhost:5173Matches the exact host and port
localhost*Matches localhost on different ports
https://*.example.comUses only the host part of the URL for matching

skipOriginCheck

List endpoints exempt from request origin checks by path prefix and HTTP method. The type is Record<Path, HttpMethod[]>.

PathHTTP methodPurpose
/api/webhooks/stripePOSTStripe webhook
/api/auth/oauth2/githubGETGitHub OAuth callback
/api/auth/oauth2/googleGETGoogle OAuth callback

trustedOrigins

Prop

Type

Rules containing :// match the full origin. Rules without :// match only the host. Wildcards use picomatch syntax.

PatternMeaning
saavo.devMatches the exact host
*.staging.example.comMatches hosts using a wildcard
https://partner.example.comMatches the exact origin
https://*.example.comMatches origins using a wildcard
chrome-extension://Matches the browser extension origin prefix
chrome-extension://*Matches Chrome or Edge extensions
moz-extension://*Matches Firefox extensions
chrome-extension://bamaajojgmohmjlnlfeojgibdojjkljkMatches the exact ID of a published extension

logger

Configure how system, audit, and alert logs are written and how long they are retained.

Prop

Type

system

Prop

Type

audit

Prop

Type

alert

Prop

Type

emailProvider

Prop

Type

ui

Configure the default theme, sign-in behavior, and redirect paths after signup, sign-in, and sign-out.

Prop

Type

redirectTo

Prop

Type

oauthRedirectTo

Prop

Type

auth

Configure sign-in, email verification, two-factor authentication (2FA), and bot verification.

Prop

Type

useTurnstile

Define when Turnstile is triggered. You can also set the entire configuration to false to disable Turnstile.

Prop

Type

emailVerification

Prop

Type

twoFactorAuth

Prop

Type

sessions

Cookie names and lifetimes for each session type. duration uses DateIntervalType.

saasSession

Prop

Type

authStepUpSession

Prop

Type

emailVerificationSession

Prop

Type

passwordResetSession

Prop

Type

twoFactorSetupSession

Prop

Type

oauthAuthRequestSession

Prop

Type

anonymousIdentity

Assign an anonymous identity to browsers that are not signed in, independently of sign-in sessions. Identity tokens are signed and stored in cookies. Application code reads the validated identity from the request context.

Prop

Type

token

Prop

Type

networkBucket

Prop

Type

fingerprint

Fingerprints only help network-bucket distinguish visitors. They cannot identify visitors on their own. The template's frontend pages do not send this request header.

Prop

Type

oauth2

Configure the built-in OAuth 2.0 authorization server.

Prop

Type

spam

Configure global rate limits and limits for authentication endpoints, email sending, ticket creation, and OAuth 2.0 endpoints.

globalBlock

Count requests by IP address and request path. Requests are temporarily rejected after reaching freeRetries. The count resets when lifetimeDuration expires.

Prop

Type

Pages frequently call /api/auth/current-user to refresh user state and poll /api/account/profile/email-verification for email verification results. The template therefore exempts these two paths by default.

authBlock

Limit access to sensitive authentication pages and endpoints. Opening these pages also counts toward the limit.

Prop

Type

authThrottle

Prop

Type

resourceProtection

emailSendService

Prop

Type

ticketCreate

The system checks the ticket creation count before uploading images and saving the ticket.

Prop

Type

oauth2AuthorizeUserBlock

Prop

Type

oauth2AuthorizeIpBlock

Prop

Type

oauth2TokenClientBlock

Prop

Type

oauth2TokenIpBlock

Prop

Type

analytics

Configure the project's built-in first-party analytics.

Prop

Type

retention

Configure analytics retention and processing limits for each scheduled cleanup run.

Prop

Type

site

The template's Worker tracks only one SaaS site. Configure its identifier, enabled status, the domains allowed to submit data, and how page views are grouped into visits.

Prop

Type

tracker

Control what the browser analytics script records and how it handles page URLs.

Prop

Type

collection

The server ignores visits that match these rules. The browser also skips loading analytics.js when the page path matches ignoredPathPrefixes. IP addresses and Distinct IDs require exact matches. User-Agent matching uses case-insensitive substrings.

Prop

Type

dashboard

Define the conversion funnels shown in the analytics dashboard. Changes require redeployment.

funnels

An array of conversion funnels. Each funnel must have a unique id and contain 2–8 steps.

Prop

Type

Each funnel step contains the following fields:

Prop

Type

Event steps can use filters to filter event properties. Path steps cannot. Each step supports up to 20 filters.

Prop

Type

Names and descriptions of the template's default funnels:

idnamedescription
affiliate-referral-conversionAffiliate referral conversionFrom a valid Affiliate referral-link click to a newly created account and a subsequent checkout start.
signup-conversionSignup conversionFrom viewing the localized signup page to creating a new account; restored accounts are excluded.
pricing-checkout-startPricing to checkoutFrom viewing the localized pricing page to creating a Stripe checkout session; this does not claim payment completion.
checkout-login-recoveryCheckout login recoveryFor signed-out purchase attempts, measures whether modal login is completed and checkout is subsequently started.

Time windows and step order for the template's default funnels:

idwindowwindowModestepOrderStep count
affiliate-referral-conversion7dfromFirstStepsequential3
signup-conversion1hfromFirstStepsequential2
pricing-checkout-start1hfromFirstStepsequential2
checkout-login-recovery1hfromFirstStepsequential3

Steps in affiliate-referral-conversion:

labeltypematchvaluefilters
Clicked Affiliate linkeventexactaffiliate_referral_clicked—
Created accounteventexactsignup_completedaccountAction equals created
Started checkouteventexactcheckout_session_created—

Steps in signup-conversion:

labeltypematchvaluefilters
Viewed signup pagepathendsWith/auth/signup—
Created accounteventexactsignup_completedaccountAction equals created

Steps in pricing-checkout-start:

labeltypematchvaluefilters
Viewed pricingpathendsWith/pricing—
Started checkouteventexactcheckout_session_createdprovider equals stripe

Steps in checkout-login-recovery:

labeltypematchvaluefilters
Purchase required logineventexactlogin_modal_openedreason equals checkout
Completed modal logineventexactlogin_completedentryPoint equals modal
Started checkouteventexactcheckout_session_created—

rateLimit

Limit requests to analytics collection endpoints, counting by both Website ID and trusted client IP address.

Prop

Type

content

Configure page paths and content directories for documentation and the blog.

docs

Prop

Type

blog

Prop

Type