OptionaladvertisedOptionalallowtells if the server default endpoints should allow anonymous connection.
OptionalallowOPC UA Part 4 §5.13.7 (TransferSubscriptions) rules that a Subscription created by an anonymous
session may only be transferred to another session when the SecureChannel MessageSecurityMode is
Sign or SignAndEncrypt and the client certificate's ApplicationUri is the one of the original
session. The conformant behaviour is the default: with false, an anonymous transfer over a
MessageSecurityMode.None channel is refused with Bad_UserAccessDenied (the CTT 1.05 script
"Subscription Transfer / Err-017" checks exactly this).
Set it to true to relax the rule and accept anonymous-to-anonymous transfers over an unsecured
channel, the behaviour of node-opcua before 2.183.0. The relaxation only affects anonymous
sessions: the cross-user ownership check (a transfer is refused unless the destination session
operates on behalf of the same user as the subscription owner) is always enforced.
OptionalalternateOptionalalternatealternate hostname or IP to use
Optionalauditthe Roles whose Sessions receive Audit Events.
OPC 10000-2 v1.05.06 §4.14: "the ability to subscribe for Audit Events is restricted to appropriate users and/or applications". An event MonitoredItem delivers an Event only to a Session that holds ReceiveEvents on its EventType and on its SourceNode (OPC 10000-3 PermissionType bit 11), and at start-up the server rewrites that one bit on AuditEventType and all its subtypes so that these Roles, and only these, hold it. Every other permission the nodesets declare is kept: the types stay browsable and readable by every Session. Opc.Ua.NodeSet2.xml already grants ReceiveEvents on the standard audit types to SecurityAdmin alone, which is the default here.
[WellKnownRoles.Anonymous] hands Audit Events to every Session, the behaviour of
node-opcua before ReceiveEvents was enforced.null leaves the RolePermissions exactly as the loaded nodesets declare them.A subtype created after start-up (Namespace.addEventType) is not covered and needs RolePermissions of its own.
OptionalbuildOptionalcapabilitiessupported server capabilities for the Multicast (mDNS)
Optionalcertificatethe server certificate full path filename
the certificate should be in PEM format
OptionalcertificateOptional pre-built certificate + private-key provider. When supplied,
OPCUASecureObject.getCertificate() / .getCertificateChain() /
.getPrivateKey() delegate to this object verbatim, and the disk-backed
path (fs.existsSync + readCertificateChain + readPrivateKey) is
not used.
Intended for browser builds (bundled via esbuild) and test fixtures that want to stage a cert+key pair without staging PKI folders on disk.
When present, certificateFile / privateKeyFile become optional and
may be omitted.
When absent, those two fields remain required strings and a
DiskCertificateKeyPairProvider is created automatically.
Optionaldefaultthe default secure token life time in ms.
Optionaldisabletrue, if discovery service on secure channel shall be disabled
OptionaldiscoveryOptionalendpointsOptionalhostHost IP address or hostname where the TCP server listens for connections. If omitted, defaults to listening on all network interfaces:
Optionalhostnamethe primary hostname of the endpoint.
Optionalisif server shall raise AuditingEvent
Optionalmaxthe maximum number of simultaneous sessions allowed.
Optionalmaxthe maximum number authorized simultaneous connections per endpoint
Optionalnodeset_the nodeset.xml file(s) to load
use OPCUAServerOptions.nodesets: it takes the same file paths, plus
NodesetSource values for a gzip stream, an HTTP response or a string of XML.
Renaming the key is the whole migration. Still honoured; entries given here load
before those of nodesets.
Optionalnodesethow the nodesets load: yieldEveryBytes keeps the process responsive while a streamed
model loads, imageStore replays precompiled images, permissions and
accessRestrictions say what of the declared access policy is applied.
Optionalnodesetsthe NodeSet2 documents to load: file paths, and NodesetSource values for a
document that is not a file. A string is a path, as it was in nodeset_filename;
anything else is a source: a gzip file inflated on the way, an HTTP response, a string of
XML. They load in one call, in dependency order whatever the order given, so a source may
require a model given as a path and the other way round.
When neither nodesets nor nodeset_filename is given, the standard nodeset is loaded.
example:
import { nodesets, nodesetSourceFromGzipFile, nodesetSourceFromUrl, OPCUAServer } from "node-opcua";
const server = new OPCUAServer({
nodesets: [
nodesets.standard,
nodesets.di,
nodesetSourceFromGzipFile("plant_model.xml.gz"),
nodesetSourceFromUrl("https://models.example.com/plant.xml")
],
nodesetLoaderOptions: { yieldEveryBytes: 1024 * 1024 }
});
OptionalonOptionalonOptionalportthe TCP port to listen to.
Optionalprivatethe server private key full path filename
This file should contains the private key that has been used to generate the server certificate file.
the private key should be in PEM format
If the key is encrypted, serverCertificateManager must be an
OPCUACertificateManager constructed with a matching
privateKeyPassphrase (or privateKeyProvider) — otherwise
initialize() fails closed.
Optionalregisterstrategy used by the server to declare itself to a discovery server
Optionalresourceresource Path is a string added at the end of the url such as "/UA/Server"
OptionalreverseReverse Connect (OPC UA Part 6 §7.1.3).
When set, the server dials OUTBOUND to each listed client reverse-connect listener and sends a ReverseHello ("RHE"), letting the client establish the SecureChannel over that socket. This is useful when the server sits behind a firewall with no open inbound ports.
All fields are optional and, when omitted, the server behaves exactly as before (no outbound dialing).
Optionalsecuritythe possible security mode that the server will expose
Optionalsecuritythe possible security policies that the server will expose
OptionalsendWhat CreateSessionResponse.serverCertificate carries when the server
certificate is CA-issued: false sends the leaf certificate only,
true sends the whole chain (leaf, then its issuers).
A client computing the legacy ActivateSession signature (OPC 10000-4 §6.1.8) "may use the entire chain passed in ServerCertificate", and some deployed clients do, so the leaf alone is the safer default. The endpoint descriptions and the OpenSecureChannel sender certificate keep the chain either way, and the server accepts a client signature over the leaf or over the chain whichever is chosen.
Also settable at runtime: OPCUAServer.sendCertificateChainInCreateSession.
OptionalserverOptionalserverServer Certificate Manager
this certificate manager will be used by the server to access and store certificates from the connecting clients
Optionalserverthe server Info
this object contains the value that will populate the Root/ObjectS/Server/ServerInfo OPCUA object in the address space.
OptionalskipskipOwnNamespace to true, if you don't want the server to create a dedicated namespace for its own (namespace=1). Use this flag if you intend to load the server own namespace from an external source.
Optionaltimeoutthe HEL/ACK transaction timeout in ms.
Use a large value ( i.e 15000 ms) for slow connections or embedded devices.
OptionaltransportOptionalunresolvedhow a Session's permission is resolved when neither the target Node nor its namespace declares any RolePermissions:
"allow" (default): grant every permission. This is how node-opcua has always behaved,
and what most address spaces expect, since almost no server declares RolePermissions on
its own Nodes."deny" : grant nothing. Fail-closed, for products that drive access entirely from
declared policy. Expect to set DefaultRolePermissions on every namespace, otherwise the
address space becomes unreadable to remote Sessions.This governs remote Sessions only. In-process callers keep every permission regardless.
Optionaluseruser Certificate Manager this certificate manager holds the X509 certificates used by client that uses X509 certificate token to impersonate a user
Optionaluseran object that implements user authentication methods
Additional endpoint URL(s) to advertise.
Use when the server is behind Docker port-mapping, a reverse proxy, or a NAT gateway. Each URL is parsed to extract hostname and port. Each entry can be a plain URL string (inherits all security settings from the main endpoint) or an
AdvertisedEndpointConfigobject with per-URL overrides. The server still listens onport.