Database

database.conf configures how the Enterprise API stores organizations, tenants, services, keys, sessions, and related data.

MongoDB is the supported production driver. Amazon DocumentDB and Azure DocumentDB (formerly Azure Cosmos DB for MongoDB vCore) are supported through database profiles that disable MongoDB features those engines do not implement fully.

Do not leave the default profile = MONGODB_8 when the backend is Amazon DocumentDB or Azure DocumentDB. That profile attaches English locale collation to sorted find queries. Those engines reject it with CommandNotSupported (115): collation is not supported in the find command yet, including during issuer and KMS setup.

Example File

database.conf
databaseType = mongodb

mongodb = {
    # Refer to https://www.mongodb.com/docs/manual/reference/connection-string/
    connectionString = "mongodb://root:password@mongodb:27017/?&replicaSet=rs0"

    # For AWS DocumentDB, ensure retryWrites is set to false.
    # connectionString = "mongodb://root:password@localhost:27017?replicaSet=rs0&directConnection=true&retryWrites=false"

    # Connection String quick reference:
    # - if username/password contain special characters, they must be converted with percent encoding (RFC3986 2.1)
    #
    # Format: mongodb+srv://[username:password@]host[/[defaultauthdb][?options]]
    #
    # EXAMPLES:
    #
    # Standard:
    # 1. Standalone:   mongodb://user:password@host:port/
    # 2. Shared cluster: mongodb://user:password@host1:port1,host2:port2,host3:port3/   (`mongos` hosts in connection string)
    # 3. Replica set: mongodb://user:password@host1:port1,host2:port2,host3:port3/?&replicaSet=replicaSetName
    #
    # SRV format (see https://www.mongodb.com/docs/manual/reference/connection-string/#std-label-connections-dns-seedlist)
    # "DNS-constructed seed list to construct available servers list"
    # Examples: same as above, with `mongodb+srv://` instead of `mongodb://`

    database = "waltid-enterprise"

    # Database profile - determines feature capabilities
    # Options:
    #   MongoDB:        MONGODB_5, MONGODB_6, MONGODB_7, MONGODB_8 (recommended)
    #   AWS DocumentDB: AWS_DOCUMENTDB_4, AWS_DOCUMENTDB_5, AWS_DOCUMENTDB_8
    #   Azure CosmosDB: AZURE_COSMOSDB_4, AZURE_COSMOSDB_6, AZURE_COSMOSDB_7
    #   Custom:         CUSTOM (requires dbFeatures configuration)
    profile = MONGODB_8

    # Optional: Override collation from profile (set to "none" to disable)
    # collation = "en"

    # Only used when profile = CUSTOM
    # dbFeatures = {
    #     cursorWithinTransaction = true
    #     collationSupported = true
    #     multiDocumentTransactions = true
    #     changeStreams = true
    #     maxTransactionLogBytes = 0
    #     ddlOperationsInTransaction = true
    # }

    pool = {
        maxSize = 100
        minSize = 10
        maxWaitTimeMs = 5000
        maxConnectionIdleTimeMs = 60000
        maxConnectionLifeTimeMs = 1800000
    }

    ssl = {
        enable = false
        trustStoreLocation = ""
        trustStorePassword = ""
        invalidHostNameAllowed = false
        keyStoreLocation = ""
        keyStorePassword = ""
        keyPassword = ""
    }
}

Startup logs print the selected profile and whether collation is enabled, for example Using database profile: MongoDB 8.0 and collationSupported=true.

Fields

databaseType

String — Storage driver. Production deployments use mongodb.

mongodb.connectionString

String — MongoDB connection URI, including credentials, hosts, and driver options.

  • Percent-encode special characters in the username and password (RFC 3986).
  • Append options as query parameters, for example &readPreference=secondaryPreferred.
  • Amazon DocumentDB requires retryWrites=false on the URI.

mongodb.database

String — Database name on the server. Default in the example is "waltid-enterprise".

mongodb.profile

String — Selects which MongoDB-compatible features the API will use. Default is MONGODB_8.

ProfileUse whenCollationCursors in transactionsDDL in transactions
MONGODB_5, MONGODB_6, MONGODB_7, MONGODB_8Native MongoDBOn (en locale on sorted finds)YesYes
AWS_DOCUMENTDB_4, AWS_DOCUMENTDB_5, AWS_DOCUMENTDB_8Amazon DocumentDBOffNoNo
AZURE_COSMOSDB_4, AZURE_COSMOSDB_6, AZURE_COSMOSDB_7Azure DocumentDB / Cosmos DB for MongoDBOffNoNo
CUSTOMYou set dbFeatures yourselfFrom dbFeaturesFrom dbFeaturesFrom dbFeatures

Azure DocumentDB (the managed MongoDB-compatible service, formerly Cosmos DB for MongoDB vCore) uses the AZURE_COSMOSDB_* names. Pick the profile that matches the server version you run.

DocumentDB and Cosmos profiles also assume a 32MB transaction log on Amazon DocumentDB and skip collection/index creation inside transactions.

mongodb.collation

String, optional — Locale used for sorted find queries when the profile supports collation.

  • If omitted, the profile default applies (en on MongoDB profiles, none on DocumentDB/Cosmos profiles).
  • Set "none" or "" to send no collation, even on a MongoDB profile.
  • walt.id does not require MongoDB simple collation, collection default collation, or locale-aware unique indexes.
  • Collation is attached only to sorted finds. Inserts, updates, findOneAndDelete, index creation, and collection creation do not send a collation document.

Setting the DocumentDB cluster collation parameter to NONE is compatible with walt.id, but it is not the primary fix. Set the matching AWS_DOCUMENTDB_* or AZURE_COSMOSDB_* profile so the API does not send collation. Do not enable DocumentDB collation for walt.id: command coverage is still partial (update, findAndModify, and collection-level collation are not used by the API and are not fully supported on those engines).

mongodb.dbFeatures

Object — Used only when profile = CUSTOM.

FieldDefaultDescription
cursorWithinTransactiontrueWhether getMore / cursors work inside a transaction
collationSupportedtrueWhether sorted finds may include a collation document
multiDocumentTransactionstrueWhether multi-document transactions are available
changeStreamstrueWhether change streams are available
maxTransactionLogBytes0Transaction log size limit (0 means no known limit)
ddlOperationsInTransactiontrueWhether collections and indexes may be created inside a transaction

mongodb.pool

Object — MongoDB driver connection pool. Defaults are shown in the example.

FieldDefaultDescription
maxSize100Maximum connections in the pool
minSize10Minimum warm connections
maxWaitTimeMs5000How long to wait for a connection before failing
maxConnectionIdleTimeMs60000Idle connection lifetime (1 minute)
maxConnectionLifeTimeMs1800000Maximum connection lifetime (30 minutes)

mongodb.ssl

Object — TLS settings for the MongoDB connection.

FieldDescription
enableSet true to use TLS
trustStoreLocationPath to a JKS trust store
trustStorePasswordTrust store password
invalidHostNameAllowedWhen false (recommended in production), the certificate hostname must match the server
keyStoreLocationOptional JKS key store for mTLS
keyStorePasswordKey store password
keyPasswordPassword for the private-key entry. Defaults to keyStorePassword when omitted

An AWS trust store is bundled as config/aws-truststore.jks with password 123456. Replace it with your own trust store in production.

Docker and JVM overrides can set these properties without editing the file, for example -Dconfig.override.mongodb.ssl.enable=true. The same pattern works for mongodb.profile.

Last updated on September 28, 2026