Skip to content
anchr.ing
Guide

Going live: promote test to production

Import your users, promote apps, webhooks and settings from test to prod, swap in the prod client ids and secrets, and optionally add a custom domain.

Test and production are separate environments with their own issuers, keys, users and secrets. Going live copies your configuration across, never users, and switches your apps' environment.

1. Bring your users

In the prod admin console, Users → Import takes a JSON list (dry-run first to check). Each row: email, email_verified (or verified), optional name, password_hash (bcrypt or argon2) and metadata:

[
  { "email": "ada@acme.example", "email_verified": true, "name": "Ada", "password_hash": "$2b$10$…" },
  { "email": "bob@acme.example", "verified": true }
]

Existing emails are skipped, so a rerun is safe. Imported hashes are rehashed on first sign-in; users without a hash sign in once by email code. Imports emit no webhooks.

2. Promote to production

Promote to production in the admin console copies apps (with their audiences and claims templates), webhooks, social connections, settings and branding, the logo and the metadata schema. Prod apps get new prod_ client ids, and each prod webhook gets its own signing secret, shown once in the result. Webhook URLs are copied as they are: replace an http://localhost receiver with the real one in prod.

3. Switch the environment

.env
AUTH_ENV=prod
VITE_AUTH_CLIENT_ID=prod_…          # the prod ids the promote created
ACME_CLI_CLIENT_ID=prod_…
ANCHRING_WEBHOOK_SECRET=…           # the prod webhook's own secret, shown once in the promote result

Audiences (acme-api, and so pat.audience) stay the same.

4. Check

Sign in, call the API, run your CLI's login, and watch events arrive in the webhook log.

A custom domain

A custom domain such as auth.acme.example for prod is the passkey domain of that host, so add it before any user registers a passkey. Custom domains are not self-service on anchr.ing yet. Once one is set up, pass the issuer to the SDK:

createAuth({ project: 'acme', env: 'prod', issuer: 'https://auth.acme.example', clientId: 'prod_…' });

Every option, error and token type: the SDK README.