Ir para o conteúdo
decodecodeveloper docs
Storefront → Blocks → Reference

Configuration reference

Every environment variable, binding and setup option a v7 site reads, in one place.

Esta página ainda não foi traduzida para o português — o conteúdo abaixo está em inglês.
Current Site Editor workflow. Studio saves repository-backed content edits to a working branch. Publish pushes and synchronizes that branch, opens or updates a pull request, and squash-merges it; Request review leaves the PR unmerged. The deployment integration applies the merged content. The runtime POST /.decofile endpoint below is a separate v7 capability for clients and delivery integrations, not the current Studio Publish action. See connecting a site and publishing changes.

This page collects every environment variable and Cloudflare binding v7 reads, and the options of the setup functions, route configs and Worker entry. Each table links back to the page that explains the feature. On Cloudflare Workers, set variables under vars in wrangler.jsonc (or as secrets for sensitive values); on Next.js and in Node tooling, set them in the process environment.

Environment variables and bindings

Runtime

NameRead byDefaultWhat it does
NODE_ENVall packagesdevelopment turns on dev behaviour: no loader cache, no auth on POST /.decofile, stack traces in invoke errors, observability off.
DECO_PREVIEW@decocms/blockstrue makes isDevMode() return true outside development.
DECO_SITE_NAME@decocms/tanstack, observability, Vite pluginThe site's name: infers its Deco-hosted preview hosts, names the service in telemetry, and is passed to generate --site in development.
DECO_SITE@decocms/blocks/middlewarestorefrontThe site name in buildDecoState.
DECO_CRYPTO_KEY@decocms/blocks/sdk/cryptoKey that decrypts secrets stored encrypted in the decofile (app credentials). A secret. See Apps.

Studio and the admin protocol

NameRead byDefaultWhat it does
DECO_RELEASE_RELOAD_TOKEN@decocms/blocks-adminRequired for POST /.decofile outside development: the Authorization header must equal it exactly. Without it, runtime reload requests get 401; this is separate from Studio's GitHub publication. See Site Editor and the v7 admin protocol.

Draft preview

NameRead byDefaultWhat it does
DECO_ALLOWED_PREVIEW_HOSTS@decocms/blocksthe Site block's previewHostsComma-separated request hosts (with port) allowed to render drafts. Replaces the Site block's list. none turns draft preview off.
DECO_PREVIEW_API_DOMAINS@decocms/blocksStudio's domains and localhostComma-separated domains drafts may be fetched from. A leading . matches subdomains.

See Previews and draft preview.

Fast Deploy (TanStack)

NameKindDefaultWhat it does
DECO_FAST_DEPLOYvariable1 or true turns Fast Deploy on, together with DECO_KV.
DECO_KVKV bindingThe namespace holding content snapshots.
DECO_DEPLOYMENT_IDvariableBUILD_HASH, then the build-time hashThe deployment whose snapshot this Worker reads and writes. Passed per deploy.
DECO_SEEDED_DEPLOYbuild variableSet by deployment pipelines that seed KV before activation; makes decoVitePlugin stub bundled content out in "auto" mode.
CF_ACCOUNT_ID, CF_API_TOKEN, CF_KV_NAMESPACE_IDCLI variablesCLOUDFLARE_ACCOUNT_ID, CLOUDFLARE_API_TOKEN, the namespace in wrangler.jsoncCredentials for deco-sync-blocks-to-kv and deco-migrate-blocks-to-kv.

See Deploying and Fast Deploy.

Caching

NameRead byDefaultWhat it does
BUILD_HASH@decocms/tanstackthe build-time hashVersion added to every edge cache key. Rename with cacheVersionEnv.
PURGE_TOKEN@decocms/tanstackBearer token for POST /_cache/purge and /_cache/purge-loaders. Rename with purgeTokenEnv.
DECO_LOADER_CACHE_MAX_BYTES@decocms/blocks32 MBSize cap of the in-memory loader cache.
DECO_CACHE_DISABLE@decocms/blockstrue disables the loader cache and shortens route cache times.

See Caching.

Observability

NameKindDefaultWhat it does
DECO_OTELvariableautoon, off, or unset (on when deployed, off in development).
DECO_OTEL_TRACES_ENDPOINTvariableCollector endpoint for spans (OTLP/HTTP).
DECO_OTEL_METRICS_ENDPOINTvariableCollector endpoint for metrics.
DECO_OTEL_LOGS_ENDPOINTvariableCollector endpoint for logs.
DECO_OTEL_HEADERSvariableExtra OTLP headers, k=v,k2=v2.
DECO_OTEL_AUTH_TOKENsecretAuthorization header value for the collector.
DECO_OTEL_TRACES_SAMPLING_RATEvariable0.01Fraction of traces exported.
DECO_OTEL_LOGS_MIN_LEVELvariableinfoLowest log level posted.
DECO_OTEL_ERROR_PROMOTION, DECO_OTEL_ERROR_PROMOTION_RATEvariablesoff, 0.1Export a share of unsampled error traces.
DECO_ENV_NAMEvariableproductiondeployment.environment on telemetry.
DECO_METRICSAnalytics Engine bindingMetrics to Analytics Engine.
CF_VERSION_METADATAversion_metadata bindingservice.version on telemetry.
OTEL_LOG_OUTGOING_FETCHvariabletrue logs every outgoing fetch.

See Observability.

Analytics

NameRead byDefaultWhat it does
DECO_ANALYTICS_ENABLEDStats (@decocms/blocks/hooks)Must be exactly true for the first-party analytics tag to render.
DECO_ANALYTICS_ORIGINStatssame originOrigin the tag loads from.
DECO_ANALYTICS_SITE_KEYStatsSite key, for sites not served through Deco's edge.
ONEDOLLAR_ENABLEDOneDollarStats (@decocms/apps-website)enabledfalse disables it.
ONEDOLLAR_COLLECTOR, ONEDOLLAR_STATIC_SCRIPTOneDollarStatsCollector and script URL overrides.

Apps

NameAppWhat it does
VTEX_APP_KEY, VTEX_APP_TOKENVTEXFallback credentials when the deco-vtex block has none.
VTEX_RESILIENCE_DISABLEDVTEXtrue turns off retries and the circuit breaker in createVtexFetch.
SHOPIFY_STOREFRONT_TOKENShopifyFallback Storefront API token.
WAKE_TOKENWakeThe Storefront API token. Required; Wake reads it only from the environment.
RESEND_API_KEYResendFallback API key.

Apps whose credentials are stored as encrypted secrets also need DECO_CRYPTO_KEY. See each app's page under Apps.

Development

NameRead byWhat it does
DECO_SITE_NAME + DECO_ENV_NAMEVite pluginWhen both are set in vite dev, the plugin starts the v7 tunnel registered with legacy admin.deco.cx; it does not import a repository into Studio.
DECO_HOSTVite pluginfalse selects the older tunnel relay.
WORKERS_CI_COMMIT_SHAVite pluginUsed as the build hash on Cloudflare Workers Builds.

A complete wrangler.jsonc

wrangler.jsonc
{
  "name": "my-store",
  "main": "src/worker-entry.ts",
  "compatibility_date": "2026-02-14",
  "compatibility_flags": ["nodejs_compat", "no_handle_cross_request_promise_resolution"],
  "kv_namespaces": [{ "binding": "DECO_KV", "id": "<your namespace id>" }],
  "vars": {
    "DECO_SITE_NAME": "my-store",
    "DECO_ENV_NAME": "production",
    "DECO_FAST_DEPLOY": "1"
  },
  "observability": {
    "enabled": true,
    "logs": { "enabled": true, "head_sampling_rate": 1 },
    "traces": { "enabled": true, "head_sampling_rate": 0.01 }
  },
  "version_metadata": { "binding": "CF_VERSION_METADATA" }
}
  • nodejs_compat is required: request context uses AsyncLocalStorage.
  • no_handle_cross_request_promise_resolution lets the framework's caches share an in-flight request across concurrent visitors; without it, the Worker can hang.
  • Set DECO_RELEASE_RELOAD_TOKEN, PURGE_TOKEN, DECO_CRYPTO_KEY and DECO_OTEL_AUTH_TOKEN as secrets (wrangler secret put), not in vars.

createSiteSetup

From @decocms/blocks/setup. See Blocks and sections.

OptionTypeDefaultWhat it does
sectionsRecord<string, () => Promise<any>>requiredSection modules keyed ./sections/<path>.tsx, as import.meta.glob returns them. Registered as site/sections/<path>.tsx.
blocksRecord<string, unknown>requiredThe decofile, usually blocks from .deco/blocks.gen.
productionOriginsstring[]Absolute URLs on these origins in content are made relative.
customMatchersArray<() => void>Functions that register your own matchers. Built-in matchers are always registered.
onResolveError(error, resolveType, context) => voidCalled when a loader or section fails during resolution.
onDanglingReference(resolveType) => anywarns, returns nullCalled for a loader or action key nothing registered.
initPlatform(blocks) => voidRuns with the content at setup and again whenever it changes, to configure a platform.

createAdminSetup

From @decocms/blocks-admin/setup. TanStack only; Next.js passes these to createNextSetup. See Site Editor and the v7 admin protocol.

OptionTypeDefaultWhat it does
meta() => Promise<any>requiredLoads the schema lazily, usually () => import("../.deco/meta.gen.json").then((m) => m.default).
cssstringrequiredURL of your stylesheet for preview pages, from a ?url import.
fontsstring[][]Font stylesheet URLs for previews.
previewWrapperReact.ComponentTypeWraps every preview, to provide context (TanStack: PreviewProviders).
getCommerceLoaders() => Record<string, (props, request?) => Promise<any>>Loaders made invokable at /deco/invoke.

For a preview theme, body class or language, call setRenderShell({ theme: "light", bodyClass, lang }) from @decocms/blocks-admin.

createNextSetup

From @decocms/nextjs/setup. Returns ensureSetup(). See Next.js App Router.

OptionTypeDefaultWhat it does
sectionsRecord<string, () => Promise<any>>requiredSection modules keyed ./sections/<path>.tsx; use the generated sectionImports.
blocksRecord<string, unknown>Content, usually the generated block manifest. Merged over blocksDir.
blocksDirstring | false".deco/blocks"Directory read at runtime. false when you pass blocks.
conventions{ meta, syncComponents, loadingFallbacks }Section conventions from .deco/sections.gen.ts.
meta() => Promise<unknown>The schema. Without it, /live/_meta returns 503.
renderShell{ css?: string; fonts?: string[] }Preview stylesheet and fonts.
previewWrapperReact.ComponentTypeWraps previews.
productionOrigins, customMatchers, onResolveError, onDanglingReferenceAs in createSiteSetup.
extend(blocks) => void | Promise<void>Runs last, with the loaded content.

cmsRouteConfig and cmsHomeRouteConfig

From @decocms/tanstack. Spread into createFileRoute("/$") and createFileRoute("/"). See TanStack Start on Cloudflare Workers.

OptionTypeDefaultWhat it does
siteNamestringrequired (/$); defaultTitle (/)Used in page titles.
defaultTitlestringrequiredTitle when a page has none.
defaultDescriptionstringDescription when a page has none.
ignoreSearchParamsstring[]["skuId"]Query parameters that don't trigger a reload. /$ only.
pendingComponentcomponentnoneShown during slow navigations. Without it, the previous page stays visible.
pendingMs, pendingMinMsnumber200, 300When the pending component shows, and for how long at least.
errorComponentcomponentbuilt-in error pageShown when loading fails.
ssrboolean | "data-only"full SSRTanStack Start's SSR mode. /$ only.
resolveGlobalsbooleantrueMerge the Site block's global sections and theme into every page.

createDecoWorkerEntry

From @decocms/tanstack: createDecoWorkerEntry(serverEntry, options).

OptionTypeDefaultWhat it does
admin{ handleMeta, handleDecofileRead, handleDecofileReload, handleRender, corsHeaders }Admin protocol handlers from @decocms/blocks-admin. Without it, /live/_meta, /.decofile and /live/previews aren't served.
buildSegment(request) => SegmentKeyThe visitor's cache segment. See Caching.
detectProfile(url) => CacheProfileName | nullbuilt-in rulesChoose a cache profile per URL.
deviceSpecificKeysbooleantrueSplit the cache by mobile/desktop when there's no buildSegment.
geoCacheKey"auto" | "off" | "country" | "region" | "city""auto"Geography in the cache key.
autoInjectGeoCookiesbooleantrueExpose Cloudflare geolocation to matchers.
safeCookiesstring[]VTEX session cookies and _deco_bucketCookies that don't prevent caching.
stripTrackingParamsbooleantrueRemove tracking parameters from cache keys.
bypassPathsstring[]/_build, /deco/, /live/, /.decofileNever cached. Your entries are added to the defaults.
extraBypassPathsstring[][]More paths never cached.
staticPathsstring[]["/fonts/"]Path prefixes of non-fingerprinted files (fonts, icons) that get long-lived immutable cache headers.
fingerprintedAssetPatternRegExphashed files under /assets/Assets cached for a year.
cacheVersionEnvstring | false"BUILD_HASH"Variable with the deploy version for cache keys.
purgeTokenEnvstring | false"PURGE_TOKEN"Variable with the purge token. false disables purging.
cacheStorage(env, request) => CacheStorage | nullCache API + memoryShared cache storage.
cdnCacheControl"serverfn-segment" | "no-store" | "match-profile" | (profile) => string | null"serverfn-segment"CDN-Cache-Control policy.
renderJsonbooleantrueServe ?renderJson. See Storefront as an API.
asJsonbooleantrueServe ?asJson.
pageJsonCorsstring[] | "*" | false"*"CORS for page JSON.
proxyHandler(request, url) => Response | null | Promise<…>Proxy paths to another origin (checkout, for example).
previewShellstringbuilt from the render shellHTML for the empty preview frame.
securityHeadersRecord<string, string> | falsenosniff, HSTS, referrer and permissions policies, frame-ancestors for StudioHeaders on HTML responses.
cspstring[] | falseContent Security Policy directives.
cspMode"report-only" | "enforce""report-only"enforce adds a per-request nonce on uncached HTML.
speculationRulesSpeculationRulesConfigoffSee Speculation rules.
observabilityOtelOptions | falseonSee Observability.
outboundUserAgentstring | falseDeco/<version> (+https://deco.cx)User-Agent added to outgoing fetch calls that have none.

decoVitePlugin

From @decocms/tanstack/vite.

OptionTypeDefaultWhat it does
fastDeployboolean | "auto""auto"Remove the bundled content from the server bundle (production builds only). "auto" does so only when DECO_SEEDED_DEPLOY is set. See Deploying and Fast Deploy.

For current Studio onboarding, use Connect a site. The built-in v7 tunnel's legacy destination is retained here as an implementation reference, not recommended onboarding for the discontinued admin.