proxy-config-reference

August 3, 2026 ยท View on GitHub

Generated by labby docs generate. Do not edit by hand.

Values are non-secret unless marked otherwise. Literal bearer tokens belong in the environment file, never TOML.

TOML pathTypeDefaultSecretEnvironment overrideDescription
proxy.exposuretailscale|localtailscalefalse-Publication controller
proxy.authtailnet|bearer|oauth|nonetailnetfalse-Authentication policy
proxy.pathabsolute non-root path/mcpfalse-Public MCP endpoint path
proxy.portrandom|u16randomfalse-External Tailscale HTTPS port selection
proxy.port_range_startu1649152false-First random external-port candidate
proxy.port_range_endu1665535false-Last random external-port candidate
proxy.bearer_token_envenvironment variable nameLABBY_PROXY_BEARER_TOKENfalseLABBY_PROXY_BEARER_TOKENEnvironment key containing the static bearer secret
proxy.oauth_scopesstring[][mcp:read, mcp:write]false-Scopes required by the exact OAuth resource lease
proxy.inherit_envenvironment variable name[][]false-Additional ambient variables inherited by the scrubbed child
proxy.shutdown_grace_msu64 (1..=60000)3000false-Grace period preference for supervised shutdown