Skip to content

Settings

Four bootstrap values live outside the database (DB__PROVIDER, DB__CONNECTION, DB__MIGRATOR_CONNECTION, BOOKEND_MASTER_KEY), alongside a few optional container environment variables described in the Installation Guide (for example Licensing__PublicKeyPath). Everything else is a row in settings, edited through the setup wizard, the Settings screen, or PUT /v1/settings/{namespace} (administrators only). Secret values are AES-GCM encrypted with the master key and never returned by the API; saving a blank secret keeps the stored value. Changes apply within 30 seconds; the few settings flagged restart required take effect after the api restarts.

Settings in the left navigation has five tabs:

Tab Who What
Rules everyone Every check Bookend runs. Administrators switch rules off or on and add bank rules in one sentence.
Documents administrators The template studio: teaching documents Bookend does not recognize.
Approval record administrators LAR profiles: how Bookend reads your approval record.
Core boarding administrators Core field maps: where each value lands in your core.
Other options administrators Every remaining setting by namespace (“Show options for”), test buttons for smtp, core and inference, and Reopen the setup wizard….

Reopening the setup wizard keeps settings and data but returns the install to setup: until an administrator activates it again (step 10), every user is sent to the wizard and scheduled heartbeats pause.

Settings → Rules: a form to add a bank rule and the built-in rules with on/off switches.Settings → Rules: a form to add a bank rule and the built-in rules with on/off switches.
Settings → Rules. Built-in rules can be switched off as bank policy (recorded in evidence); bank rules are added without code.

Defaults are in parentheses. Unknown keys, read-only keys and values of the wrong type are refused with field errors.

Namespace Keys Notes
app public_url the URL users type; sign-in links and emails are built from it
auth access_token_minutes (15, max 60), refresh_token_hours (8, max 720), otp_ttl_minutes (15), password_min_length (12, 8 to 128), login_password_enabled (true), login_otp_enabled (true), login_totp_enabled (false), oidc_enabled, oidc_authority, oidc_client_id, oidc_client_secret (secret), oidc_provider_name, allowed_email_domains (JSON array, empty = any), otp_link_path (/auth/otp), signing_key (secret), signing_key_id sign-in policy, MFA and single sign-on; see Users and roles. The RS256 signing key and its id are generated on first boot and read-only
smtp host, port (587), tls_mode (none / starttls / ssl; starttls), username, password (secret), from_address, from_name (Bookend) read on every send, no restart; the test button sends a real message to you and records the result
documents max_package_mb (200), retention_days (2555), last_retention (read-only), watch_folder (/data/watch, restart required), watch_interval_seconds (60), watch_stable_seconds (5), page_render_dpi (110), taxonomy (JSON, read-only) the nightly retention sweep purges the stored bytes of loans sealed longer ago than retention_days; rows, hashes and evidence stay
fields catalog (JSON, read-only) the canonical field catalog the rules and maps refer to
extraction templates (JSON) the bank’s own document templates, taught in Settings → Documents; see Teaching documents
ai endpoint, model, api_key (secret) optional OpenAI-compatible endpoint that can draft a template from a sample; never used at runtime
execution templates (JSON) signature, initials, date and notary zones per document type
inference url (http://inference:9090) the inference container; the test button calls its health check
pipeline max_attempts (8), retry_base_seconds (5) exponential backoff for stage retries, capped at 10 minutes
rules ruleset_version (v1.0, read-only), money_tolerance_cents (0), rate_tolerance (0.00001), date_tolerance_days (0), name_normalization (lenient / strict; lenient), disabled (JSON), custom (JSON), catalog (JSON, read-only) disabled and custom are managed on the Rules tab; see Reconciliation rules
review reason_codes (JSON array), justification_min_length (10) override policy
core provider (file.export / jackhenry.jxchange; file.export), file_export_path (/data/exports), jxchange.endpoint, jxchange.username, jxchange.password (secret), jxchange.institution_id the test button probes the active adapter
boarding allow_wire_before_boarded (false) wires normally wait for a boarded loan
metering heartbeat_enabled (true), air_gapped (false), endpoint, api_key (secret, optional) see Metering and licensing
license key (secret); institution, tier, expires_at (read-only) the license JWT and the values read from it
evidence last_verification (JSON, read-only) written by the nightly evidence sweep
setup state, completed_steps, smtp_tested, core_tested, lar_profile_id, activated_at (all read-only) wizard bookkeeping; lar_profile_id is the approval-record profile used for intake
Settings → Other options: setting groups with keys, values and descriptions.Settings → Other options: setting groups with keys, values and descriptions.
Settings → Other options. Every remaining key by namespace, with its current value and what it does.

The document taxonomy, field catalog and rule catalog are JSON settings rather than code (ADR 0003). They ship with each release and are read-only through the API, and every reconciliation run records the ruleset version and thresholds it used. What a bank changes without a release: rule switches and bank rules (Rules tab), taught document templates (Documents tab), execution templates, tolerances, reason codes, retention and the integration settings.

Every settings write is a row in the data audit (GET /v1/audit?source=data&table=settings) with the actor and the before and after values. Secret values appear there only in encrypted form.

System → Audit: who changed which setting, when, from what to what.System → Audit: who changed which setting, when, from what to what.
System → Audit. Every settings change with actor, time and before/after values.