# Configuration

> Configuration for pulumi-openfga.

<!-- Generated from the pulumi-openfga SDK. -->

Configuration for pulumi-openfga.

npm package `pulumi-openfga` version `0.5.6`.
Pulumi bridge `terraform-provider` version `1.4.0`.
Upstream provider `registry.opentofu.org/openfga/openfga` version `0.5.1`.

An explicit provider is `new openfga.Provider(name, args)`. Stack configuration is a `pulumi.Config` object named `openfga`.

A value marked secret is passed through `pulumi.secret` or listed in `additionalSecretOutputs` on the provider resource.

## Fields

| Property         | Type     | Source                                     | Secret | Description                                                                                                                                                                                                                                                     |
| ---------------- | -------- | ------------------------------------------ | ------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `apiAudience`    | `string` | provider args; stack config via config.get | no     | Audience for client credentials authentication. This can also be sourced from the `FGA_API_AUDIENCE` environment variable.                                                                                                                                      |
| `apiScopes`      | `string` | provider args; stack config via config.get | no     | Scopes for client credentials authentication. This can also be sourced from the `FGA_API_SCOPES` environment variable.                                                                                                                                          |
| `apiToken`       | `string` | provider args; stack config via config.get | no     | Access token for authentication to the OpenFGA server. This can also be sourced from the `FGA_API_TOKEN` environment variable.                                                                                                                                  |
| `apiTokenIssuer` | `string` | provider args; stack config via config.get | no     | The issuer URL or full token endpoint URL for client credentials authentication. If only the issuer URL is provided, the `oauth/token` path is used to retrieve an access token. This can also be sourced from the `FGA_API_TOKEN_ISSUER` environment variable. |
| `apiUrl`         | `string` | provider args; stack config via config.get | no     | URL of the OpenFGA server. This can also be sourced from the `FGA_API_URL` environment variable.                                                                                                                                                                |
| `clientId`       | `string` | provider args; stack config via config.get | no     | Client ID for client credentials authentication. This can also be sourced from the `FGA_CLIENT_ID` environment variable.                                                                                                                                        |
| `clientSecret`   | `string` | provider args; stack config via config.get | yes    | Client secret for client credentials authentication. This can also be sourced from the `FGA_CLIENT_SECRET` environment variable.                                                                                                                                |
