pypi · nava-rebar
REBAR_ROOT — Path to the repo root that holds the .tickets-tracker store (defaults to the git toplevel of the working dir).
REBAR_MCP_READONLY — Set to 1 to expose only the read tools (no write/mutation tools).
REBAR_MCP_ALLOW_LLM — Set to 1 to enable the billable LLM tools (review_code / scan_spec / verify_completion / review_plan); off by default.
REBAR_MCP_ALLOW_JIRA_SYNC — Set to 1 to allow the live (mutating) Jira reconcile mode; otherwise reconcile is dry-run only.
REBAR_MCP_TRANSPORT — Transport for the MCP server: 'stdio' (default) or 'http' (the optional Streamable-HTTP transport).
REBAR_MCP_HTTP_HOST — Bind host for the Streamable-HTTP transport (default 127.0.0.1).
REBAR_MCP_HTTP_PORT — Bind port for the Streamable-HTTP transport (1-65535; default 8000).
REBAR_MCP_HTTP_PATH — URL path the Streamable-HTTP transport serves on (default /mcp).
REBAR_MCP_HTTP_ALLOWED_HOSTS — Comma-separated allowlist of exact host:port values accepted by the Streamable-HTTP DNS-rebinding protection; empty defaults to loopback.
REBAR_MCP_HTTP_ALLOWED_ORIGINS — Comma-separated allowlist of exact Origin values accepted by the Streamable-HTTP DNS-rebinding protection; empty defaults to loopback.
REBAR_MCP_HTTP_TLS_AT_EDGE — Set to 1 to acknowledge TLS is terminated at the edge; required to bind the Streamable-HTTP transport to a non-loopback host.
REBAR_MCP_ALLOW_UNAUTHENTICATED_HTTP — Set to 1 to acknowledge running the Streamable-HTTP transport without a token verifier; required to boot the HTTP transport while auth is off.
REBAR_MCP_AUTH_ENABLED — Set to 1 to enable MCP authentication (the composite token verifier + Resource-Server wiring); off by default.
REBAR_MCP_AUTH_STRATEGIES — Comma-separated, ordered list of token-verifier strategies to compose (closed set: static, jwt, introspection, proxy, custom).
REBAR_MCP_AUTH_ISSUER_URL — OAuth authorization-server issuer URL advertised in the Protected-Resource Metadata (RFC 9728) when auth is enabled.
REBAR_MCP_AUTH_RESOURCE_SERVER_URL — The single resource identifier (RFC 8707 audience) for this server; the composite verifier re-checks every accepted token against it.
REBAR_MCP_AUTH_REQUIRED_SCOPES — Comma-separated scopes a caller must hold; the SDK returns 403 insufficient_scope when a principal lacks one.
REBAR_MCP_AUTH_STATIC_TOKENS_FILE — Path to the JSON secrets file for the static-bearer verifier (stores only SHA-256 digests of the accepted tokens).
REBAR_MCP_AUTH_JWT_JWKS_URI — HTTPS JWKS endpoint the `jwt` verifier fetches signing keys from (an OIDC provider's .well-known/jwks.json).
REBAR_MCP_AUTH_JWT_ISSUER — Expected `iss` claim for the `jwt` verifier; falls back to REBAR_MCP_AUTH_ISSUER_URL when unset.
REBAR_MCP_AUTH_JWT_ALGORITHMS — Comma-separated PINNED, asymmetric-only JWS algorithms for the `jwt` verifier (default RS256,ES256); a symmetric algorithm on a JWKS source is refused.
REBAR_MCP_AUTH_JWT_LEEWAY — Clock-skew leeway in seconds applied to exp/nbf validation by the `jwt` verifier (default 60).
REBAR_MCP_AUTH_JWT_JWKS_REFETCH_COOLDOWN — Minimum seconds between JWKS refetches triggered by an unknown key id (the concurrency-safe flood guard; default 30).
REBAR_MCP_AUTH_JWT_JWKS_TIMEOUT — HTTP timeout in seconds for the `jwt` verifier's JWKS fetch (default 10).
REBAR_MCP_AUTH_JWT_EXPECTED_TYP — When set, the `jwt` verifier requires the JWT header `typ` to equal this (e.g. at+JWT per RFC 9068); unset skips the check.
REBAR_MCP_AUTH_JWT_ALLOW_PRIVATE_JWKS_HOST — Set to 1 to permit a private/link-local/loopback JWKS host (SSRF guard is on by default); off by default.
REBAR_MCP_AUTH_INTROSPECTION_ENDPOINT — The `introspection` verifier's RFC 7662 endpoint URL (must be https://); the opaque token is POSTed here on every request (no caching).
REBAR_MCP_AUTH_INTROSPECTION_CLIENT_ID — The client id the `introspection` verifier presents to the Authorization Server via HTTP Basic (client_secret_basic).
REBAR_MCP_AUTH_INTROSPECTION_CLIENT_SECRET_ENV — The NAME of the env var holding the introspection client secret (never the secret itself); must be present + non-empty at startup or the server refuses to start (fail-closed).
REBAR_MCP_AUTH_INTROSPECTION_ALLOW_PRIVATE_HOST — Set to 1 to permit a private/link-local/loopback introspection endpoint host (SSRF guard is on by default); off by default.
REBAR_MCP_AUTH_INTROSPECTION_ALLOW_MISSING_AUD — Set to 1 to accept an active introspection response that OMITS `aud` (many AS do); off by default (fail-closed reject).
REBAR_MCP_AUTH_PROXY_SECRET_ENV — The NAME of the env var holding the trusted-proxy shared secret (never the secret itself); must be present + non-empty at startup or the `proxy` verifier refuses to start (fail-closed).
REBAR_MCP_AUTH_PROXY_SECRET_HEADER — The header the fronting proxy sends its shared secret on; the identity is trusted only when this matches (constant-time; default x-proxy-auth).
REBAR_MCP_AUTH_PROXY_IDENTITY_HEADER — The header carrying the proxy-authenticated principal identity, trusted only when the secret header validates (default x-forwarded-user).
REBAR_MCP_AUTH_PROXY_SCOPES — Comma-separated fixed scope set granted to proxy-authenticated principals; empty by default (the principal holds no scopes).
REBAR_MCP_AUTH_CUSTOM_IMPORT — The `custom` strategy's `module:factory` import string, resolving to a factory that returns a TokenVerifier; a TRUSTED operator config value that loads and executes the operator-configured code at startup (fail-closed on any load error).