# Configuration

This page lists every field of the `Config` passed to `JWTAuth.init()`, with defaults and validation rules.

## Fields

| Field | Type | Required | Default | Description |
|---|---|---|---|---|
| `privateKeyPath` | `string` | One of two | — | Private key file path; overrides `privateKey` when set |
| `privateKey` | `string` | One of two | — | Private key PEM content |
| `publicKeyPath` | `string` | One of two | — | Public key file path; overrides `publicKey` when set |
| `publicKey` | `string` | One of two | — | Public key PEM content |
| `accessTokenExpires` | `number` | Yes | — | Access Token lifetime in seconds; also the revocation blacklist TTL |
| `refreshTokenExpires` | `number` | Yes | — | Refresh ID lifetime in seconds, reset on every refresh |
| `isProd` | `boolean` | Yes | — | Controls cookie `secure`, `sameSite`, and `domain` |
| `domain` | `string` | When `isProd` | — | Production cookie domain |
| `redis.host` | `string` | Yes | `localhost` | Redis host |
| `redis.port` | `number` | Yes | `6379` | Redis port |
| `redis.password` | `string` | No | — | Redis password |
| `redis.db` | `number` | No | `0` | Redis database index |
| `checkUserExists` | `(userId: string) => Promise<boolean>` | Yes | — | Confirms the user still exists during refresh |
| `AccessTokenCookieKey` | `string` | Required by type | `access_token` | Access Token cookie name |
| `RefreshTokenCookieKey` | `string` | Required by type | `refresh_id` | Refresh ID cookie name |

## init Validation and Errors

| Situation | Result |
|---|---|
| Neither `publicKey` nor `publicKeyPath` | Throws `publicKey is required` |
| Neither `privateKey` nor `privateKeyPath` | Throws `privateKey is required` |
| Key path does not exist | The `readFileSync` error propagates unchanged |
| Redis connection fails | Logged with `console.error`, then thrown |

`init()` mutates the config object you pass: loaded keys are written back to `publicKey` / `privateKey`, and cookie names receive their defaults.

## Key Sources

```typescript
import { JWTAuth } from "@pardnchiu/jwt-auth";

// Read PEM content from environment variables, convenient for containers
await JWTAuth.init({
  privateKey: process.env.JWT_PRIVATE_KEY,
  publicKey: process.env.JWT_PUBLIC_KEY,
  accessTokenExpires: 900,
  refreshTokenExpires: 604800,
  isProd: true,
  domain: "example.com",
  AccessTokenCookieKey: "access_token",
  RefreshTokenCookieKey: "refresh_id",
  redis: { host: "redis", port: 6379, password: process.env.REDIS_PASSWORD },
  checkUserExists: async (userId) => true,
});
```

The package itself reads no environment variables.

## Process Signals

Importing the package registers `SIGINT` and `SIGTERM` handlers that call `JWTAuth.close()` and then `process.exit(0)`. If your app has its own graceful shutdown, note that this handler ends the process right after Redis disconnects.

Related: [Token Transport](/token-transport), [API Reference](/api-reference)
