Skip to content
HomeFeedbackOpen Pairfob

Environment ​

Operator-facing variables only. Leave unspecified variables unset. Do not put secrets in a global ~/.zshrc you then paste into logs.

Enroll and origin ​

VariableWhen
PAIRFOB_ORIGINDefault https://pairfob.com (this project's official instance). Leave unset
PAIRFOB_JOIN_TOKENForbidden. Setting it fails startup

Local state ​

VariableDefaultNotes
PAIRFOB_STATE_DIR~/.config/pairfobIdentity, devices, logs
PAIRFOB_ALLOWED_ROOTSuser HomeAllowed roots for web paths. Setting it replaces Home
PAIRFOB_MULTI_SESSIONonLets the phone list and switch to named Herdr sessions (herdr --session <name>) from the Sessions header and Settings. 0 turns it off; HERDR_SOCKET_PATH set to a non-default path keeps it off unless 1 is set. Pairfob still starts only the default server. Notifications still come from the default session only. See Named Herdr sessions

Install ​

VariableNotes
PAIRFOB_DOWNLOAD_BASEBinary download root, default https://pairfob.com/dl
PAIRFOB_INSTALL_PREFIXSame as install.sh --prefix

Push ​

VariableNotes
PAIRFOB_PUSH1 enables. Off by default
PAIRFOB_VAPID_SUBJECTA mailto: or https: URL you control

The user service does not inherit your current shell. Write these into the service file, then pairfob service restart. See Notifications.

Keep off ​

VariableWhy
PAIRFOB_HERDR_AUTOSTART0 skips starting Herdr automatically
PAIRFOB_DEV_FAKE_RUNTIMEDemo data, not real Herdr
PAIRFOB_DEV_AUTO_ADMITSkips computer confirm. Outside isolated tests this hands the computer to anyone with the code

Keys stay on your computer and paired devices. pairfob.com forwards ciphertext only. · Report an issue