deploy.ts
Rendering, uploads, origin checks, logging, authentication, sessions, rate limits, analytics, and content directories.
config/deploy.ts configures page rendering, file uploads, request origin checks, logging, email, the UI, user authentication, sessions, anonymous identities, OAuth 2.0, rate limits, analytics, and content directories. Settings are listed in the order they appear in websiteDeployCfg.
streamRender
Prop
Type
upload
Configure the file size limit, file delivery, and storage backend.
Prop
Type
delivery
Configure the path and cache response headers used when serving uploaded files through the Worker.
Prop
Type
cache
Prop
Type
storage
Configure the default storage backend and the settings for KV and R2.
Prop
Type
kv
Prop
Type
r2
Prop
Type
cors
Specify the HTTP methods allowed for cross-origin requests to each path. The type is Record<Path, HttpMethod[]>. Object keys must be site paths starting with /. Supported methods are GET, POST, PUT, PATCH, DELETE, OPTIONS, and HEAD.
The template defaults to an empty object. The source comments include this example:
cors: {
// '/test': ['GET', 'POST'],
}hosts
Prop
Type
Local development allows localhost and 127.0.0.1 by default. Production allows the host in VITE_SITE_URL by default, so only add extra rules here. Duplicate entries are ignored.
| Pattern | Meaning |
|---|---|
saavo.dev | Matches the exact host |
*.saavo.dev | Matches subdomains |
localhost:5173 | Matches the exact host and port |
localhost* | Matches localhost on different ports |
https://*.example.com | Uses only the host part of the URL for matching |
skipOriginCheck
List endpoints exempt from request origin checks by path prefix and HTTP method. The type is Record<Path, HttpMethod[]>.
| Path | HTTP method | Purpose |
|---|---|---|
/api/webhooks/stripe | POST | Stripe webhook |
/api/auth/oauth2/github | GET | GitHub OAuth callback |
/api/auth/oauth2/google | GET | Google OAuth callback |
trustedOrigins
Prop
Type
Rules containing :// match the full origin. Rules without :// match only the host. Wildcards use picomatch syntax.
| Pattern | Meaning |
|---|---|
saavo.dev | Matches the exact host |
*.staging.example.com | Matches hosts using a wildcard |
https://partner.example.com | Matches the exact origin |
https://*.example.com | Matches origins using a wildcard |
chrome-extension:// | Matches the browser extension origin prefix |
chrome-extension://* | Matches Chrome or Edge extensions |
moz-extension://* | Matches Firefox extensions |
chrome-extension://bamaajojgmohmjlnlfeojgibdojjkljk | Matches the exact ID of a published extension |
logger
Configure how system, audit, and alert logs are written and how long they are retained.
Prop
Type
system
Prop
Type
audit
Prop
Type
alert
Prop
Type
emailProvider
Prop
Type
ui
Configure the default theme, sign-in behavior, and redirect paths after signup, sign-in, and sign-out.
Prop
Type
redirectTo
Prop
Type
oauthRedirectTo
Prop
Type
auth
Configure sign-in, email verification, two-factor authentication (2FA), and bot verification.
Prop
Type
useTurnstile
Define when Turnstile is triggered. You can also set the entire configuration to false to disable Turnstile.
Prop
Type
emailVerification
Prop
Type
twoFactorAuth
Prop
Type
sessions
Cookie names and lifetimes for each session type. duration uses DateIntervalType.
saasSession
Prop
Type
authStepUpSession
Prop
Type
emailVerificationSession
Prop
Type
passwordResetSession
Prop
Type
twoFactorSetupSession
Prop
Type
oauthAuthRequestSession
Prop
Type
anonymousIdentity
Assign an anonymous identity to browsers that are not signed in, independently of sign-in sessions. Identity tokens are signed and stored in cookies. Application code reads the validated identity from the request context.
Prop
Type
cookie
token
Prop
Type
networkBucket
Prop
Type
fingerprint
Fingerprints only help network-bucket distinguish visitors. They cannot identify visitors on their own. The template's frontend pages do not send this request header.
Prop
Type
oauth2
Configure the built-in OAuth 2.0 authorization server.
Prop
Type
spam
Configure global rate limits and limits for authentication endpoints, email sending, ticket creation, and OAuth 2.0 endpoints.
globalBlock
Count requests by IP address and request path. Requests are temporarily rejected after reaching freeRetries. The count resets when lifetimeDuration expires.
Prop
Type
Pages frequently call /api/auth/current-user to refresh user state and poll /api/account/profile/email-verification for email verification results. The template therefore exempts these two paths by default.
authBlock
Limit access to sensitive authentication pages and endpoints. Opening these pages also counts toward the limit.
Prop
Type
authThrottle
Prop
Type
resourceProtection
emailSendService
Prop
Type
ticketCreate
The system checks the ticket creation count before uploading images and saving the ticket.
Prop
Type
oauth2AuthorizeUserBlock
oauth2AuthorizeIpBlock
oauth2TokenClientBlock
Prop
Type
oauth2TokenIpBlock
Prop
Type
analytics
Configure the project's built-in first-party analytics.
Prop
Type
retention
Configure analytics retention and processing limits for each scheduled cleanup run.
Prop
Type
site
The template's Worker tracks only one SaaS site. Configure its identifier, enabled status, the domains allowed to submit data, and how page views are grouped into visits.
Prop
Type
tracker
Control what the browser analytics script records and how it handles page URLs.
Prop
Type
collection
The server ignores visits that match these rules. The browser also skips loading analytics.js when the page path matches ignoredPathPrefixes. IP addresses and Distinct IDs require exact matches. User-Agent matching uses case-insensitive substrings.
Prop
Type
dashboard
Define the conversion funnels shown in the analytics dashboard. Changes require redeployment.
funnels
An array of conversion funnels. Each funnel must have a unique id and contain 2–8 steps.
Prop
Type
Each funnel step contains the following fields:
Prop
Type
Event steps can use filters to filter event properties. Path steps cannot. Each step supports up to 20 filters.
Prop
Type
Names and descriptions of the template's default funnels:
id | name | description |
|---|---|---|
affiliate-referral-conversion | Affiliate referral conversion | From a valid Affiliate referral-link click to a newly created account and a subsequent checkout start. |
signup-conversion | Signup conversion | From viewing the localized signup page to creating a new account; restored accounts are excluded. |
pricing-checkout-start | Pricing to checkout | From viewing the localized pricing page to creating a Stripe checkout session; this does not claim payment completion. |
checkout-login-recovery | Checkout login recovery | For signed-out purchase attempts, measures whether modal login is completed and checkout is subsequently started. |
Time windows and step order for the template's default funnels:
id | window | windowMode | stepOrder | Step count |
|---|---|---|---|---|
affiliate-referral-conversion | 7d | fromFirstStep | sequential | 3 |
signup-conversion | 1h | fromFirstStep | sequential | 2 |
pricing-checkout-start | 1h | fromFirstStep | sequential | 2 |
checkout-login-recovery | 1h | fromFirstStep | sequential | 3 |
Steps in affiliate-referral-conversion:
label | type | match | value | filters |
|---|---|---|---|---|
| Clicked Affiliate link | event | exact | affiliate_referral_clicked | — |
| Created account | event | exact | signup_completed | accountAction equals created |
| Started checkout | event | exact | checkout_session_created | — |
Steps in signup-conversion:
label | type | match | value | filters |
|---|---|---|---|---|
| Viewed signup page | path | endsWith | /auth/signup | — |
| Created account | event | exact | signup_completed | accountAction equals created |
Steps in pricing-checkout-start:
label | type | match | value | filters |
|---|---|---|---|---|
| Viewed pricing | path | endsWith | /pricing | — |
| Started checkout | event | exact | checkout_session_created | provider equals stripe |
Steps in checkout-login-recovery:
label | type | match | value | filters |
|---|---|---|---|---|
| Purchase required login | event | exact | login_modal_opened | reason equals checkout |
| Completed modal login | event | exact | login_completed | entryPoint equals modal |
| Started checkout | event | exact | checkout_session_created | — |
rateLimit
Limit requests to analytics collection endpoints, counting by both Website ID and trusted client IP address.
Prop
Type
content
Configure page paths and content directories for documentation and the blog.
docs
Prop
Type
blog
Prop
Type