# Configuration
URL: /docs/configuration

Every CLI flag, environment variable, and auth setting Tachyon supports.



Tachyon has no config file — every setting is a CLI flag, or the equivalent
environment variable.

## Flags and environment variables [#flags-and-environment-variables]

| Flag                       | Env var                          | Default        | Description                                                                               |
| -------------------------- | -------------------------------- | -------------- | ----------------------------------------------------------------------------------------- |
| `--listen`                 | `TACHYON_LISTEN`                 | `0.0.0.0:8108` | Address to listen on                                                                      |
| `--data-dir`               | `TACHYON_DATA_DIR`               | `./data`       | Directory for collections, segments, and the WAL                                          |
| `--sync-interval-ms`       | `TACHYON_SYNC_INTERVAL_MS`       | `0`            | WAL fsync interval — `0` fsyncs before acknowledging every write                          |
| `--max-memtable-docs`      | `TACHYON_MAX_MEMTABLE_DOCS`      | `100000`       | Documents held in memory before a flush to a new segment                                  |
| `--merge-trigger-segments` | `TACHYON_MERGE_TRIGGER_SEGMENTS` | `8`            | Segment count that triggers a background merge                                            |
| `--merge-fan-in`           | `TACHYON_MERGE_FAN_IN`           | `4`            | Segments folded together per merge                                                        |
| `--admin-key`              | `TACHYON_ADMIN_KEY`              | unset          | API key with full read/write access                                                       |
| `--search-key`             | `TACHYON_SEARCH_KEY`             | unset          | API key with read-only access                                                             |
| `--log`                    | `TACHYON_LOG`                    | `info`         | Log filter, `tracing-subscriber` `EnvFilter` syntax                                       |
| `--healthcheck`            | —                                | —              | Check a locally running instance is healthy, then exit (used as the Docker `HEALTHCHECK`) |

See [Persistence](/docs/persistence) for what the memtable/segment/merge
settings actually control.

## Authentication [#authentication]

If neither `--admin-key` nor `--search-key` is set, Tachyon runs **fully
open** — anyone who can reach the port has full read/write access. That's
fine on `localhost` during development, and not fine on a network anyone
else can reach.

Once either key is set, requests must present it in the
`x-tachyon-api-key` header. Every SDK takes the key once, as a client
option, rather than as a per-request header:

<Tabs items="['cURL', 'TypeScript', 'Python', 'C#']">
  <Tab value="cURL">
    ```bash
    curl localhost:8108/collections \
      -H 'x-tachyon-api-key: your-admin-key'
    ```
  </Tab>

  <Tab value="TypeScript">
    ```ts
    import { Tachyon } from 'tachyon-sdk';

    const client = new Tachyon({ url: 'http://localhost:8108', apiKey: 'your-admin-key' });

    await client.collections.list();
    ```
  </Tab>

  <Tab value="Python">
    ```python
    from tachyon_sdk import Tachyon

    client = Tachyon(url="http://localhost:8108", api_key="your-admin-key")

    client.collections.list()
    ```
  </Tab>

  <Tab value="C#">
    ```csharp
    using Tachyon.Sdk;

    var client = new TachyonClient(new TachyonClientOptions { Url = "http://localhost:8108", ApiKey = "your-admin-key" });

    await client.Collections.ListAsync();
    ```
  </Tab>
</Tabs>

* **Admin key** — full read and write access to every route.
* **Search key** — read-only: any request whose HTTP method isn't
  `GET`/`HEAD`/`OPTIONS` is rejected with `403 forbidden`, even with a valid
  search key. Safe to embed in a client application.
* A missing key on a route that requires one returns `401 unauthorized`.
* `/health`, and the built-in `/docs` and `/api-docs/openapi.json` Swagger
  routes, are always public regardless of auth configuration.

For a production deployment, set `--admin-key` for your own tooling and
`--search-key` for anything client-facing.
