NodeOPCUA API Documentation
    Preparing search index...

    Interface OPCUAServerOptions

    interface OPCUAServerOptions {
        advertisedEndpoints?: AdvertisedEndpoint | AdvertisedEndpoint[];
        allowAnonymous?: boolean;
        allowAnonymousSubscriptionTransferOnUnsecuredChannel?: boolean;
        alternateEndpoints?: OPCUAServerEndpointOptions[];
        alternateHostname?: string | string[];
        auditEventRoles?: RoleIdLike[] | null;
        buildInfo?: {
            buildDate?: Date;
            buildNumber?: string;
            manufacturerName?: string;
            productName?: string;
            productUri?: string | null;
            softwareVersion?: string;
        };
        capabilitiesForMDNS?: string[];
        certificateFile?: string;
        certificateKeyPairProvider?: ICertificateKeyPairProvider;
        defaultSecureTokenLifetime?: number;
        disableDiscovery?: boolean;
        discoveryServerEndpointUrl?: string;
        endpoints?: OPCUAServerEndpointOptions[];
        host?: string;
        hostname?: string;
        isAuditing?: boolean;
        maxAllowedSessionNumber?: number;
        maxConnectionsPerEndpoint?: number;
        nodeset_filename?: string
        | string[];
        nodesetLoaderOptions?: NodeSetLoaderOptions;
        nodesets?: string | NodesetSource[];
        onCreateMonitoredItem?: CreateMonitoredItemHook;
        onDeleteMonitoredItem?: DeleteMonitoredItemHook;
        port?: number;
        privateKeyFile?: string;
        registerServerMethod?: RegisterServerMethod;
        resourcePath?: string;
        reverseConnect?: ReverseConnectOptions;
        securityModes?: MessageSecurityMode[];
        securityPolicies?: SecurityPolicy[];
        sendCertificateChainInCreateSession?: boolean;
        serverCapabilities?: Partial<IServerCapabilities>;
        serverCertificateManager?: OPCUACertificateManager;
        serverInfo?: ApplicationDescriptionOptions;
        skipOwnNamespace?: boolean;
        timeout?: number;
        transportSettings?: IServerTransportSettings;
        unresolvedPermissionPolicy?: UnresolvedPermissionPolicy;
        userCertificateManager?: OPCUACertificateManager;
        userManager?: UserManagerOptions;
    }

    Hierarchy (View Summary)

    Index
    advertisedEndpoints?: AdvertisedEndpoint | AdvertisedEndpoint[]

    Additional endpoint URL(s) to advertise.

    Use when the server is behind Docker port-mapping, a reverse proxy, or a NAT gateway. Each URL is parsed to extract hostname and port. Each entry can be a plain URL string (inherits all security settings from the main endpoint) or an AdvertisedEndpointConfig object with per-URL overrides. The server still listens on port.

    "opc.tcp://localhost:48481"
    
    ["opc.tcp://localhost:48481", { url: "opc.tcp://public:4840", securityModes: [MessageSecurityMode.SignAndEncrypt] }]
    
    allowAnonymous?: boolean

    tells if the server default endpoints should allow anonymous connection.

    true
    
    allowAnonymousSubscriptionTransferOnUnsecuredChannel?: boolean

    OPC UA Part 4 §5.13.7 (TransferSubscriptions) rules that a Subscription created by an anonymous session may only be transferred to another session when the SecureChannel MessageSecurityMode is Sign or SignAndEncrypt and the client certificate's ApplicationUri is the one of the original session. The conformant behaviour is the default: with false, an anonymous transfer over a MessageSecurityMode.None channel is refused with Bad_UserAccessDenied (the CTT 1.05 script "Subscription Transfer / Err-017" checks exactly this).

    Set it to true to relax the rule and accept anonymous-to-anonymous transfers over an unsecured channel, the behaviour of node-opcua before 2.183.0. The relaxation only affects anonymous sessions: the cross-user ownership check (a transfer is refused unless the destination session operates on behalf of the same user as the subscription owner) is always enforced.

    false
    
    alternateEndpoints?: OPCUAServerEndpointOptions[]
    alternateHostname?: string | string[]

    alternate hostname or IP to use

    auditEventRoles?: RoleIdLike[] | null

    the Roles whose Sessions receive Audit Events.

    OPC 10000-2 v1.05.06 §4.14: "the ability to subscribe for Audit Events is restricted to appropriate users and/or applications". An event MonitoredItem delivers an Event only to a Session that holds ReceiveEvents on its EventType and on its SourceNode (OPC 10000-3 PermissionType bit 11), and at start-up the server rewrites that one bit on AuditEventType and all its subtypes so that these Roles, and only these, hold it. Every other permission the nodesets declare is kept: the types stay browsable and readable by every Session. Opc.Ua.NodeSet2.xml already grants ReceiveEvents on the standard audit types to SecurityAdmin alone, which is the default here.

    • [WellKnownRoles.Anonymous] hands Audit Events to every Session, the behaviour of node-opcua before ReceiveEvents was enforced.
    • null leaves the RolePermissions exactly as the loaded nodesets declare them.

    A subtype created after start-up (Namespace.addEventType) is not covered and needs RolePermissions of its own.

    [WellKnownRoles.SecurityAdmin]
    
    buildInfo?: {
        buildDate?: Date;
        buildNumber?: string;
        manufacturerName?: string;
        productName?: string;
        productUri?: string | null;
        softwareVersion?: string;
    }
    capabilitiesForMDNS?: string[]

    supported server capabilities for the Multicast (mDNS)

    ["NA"]
    the possible values are any of node-opcua-discovery.serverCapabilities)
    certificateFile?: string

    the server certificate full path filename

    the certificate should be in PEM format

    certificateKeyPairProvider?: ICertificateKeyPairProvider

    Optional pre-built certificate + private-key provider. When supplied, OPCUASecureObject.getCertificate() / .getCertificateChain() / .getPrivateKey() delegate to this object verbatim, and the disk-backed path (fs.existsSync + readCertificateChain + readPrivateKey) is not used.

    Intended for browser builds (bundled via esbuild) and test fixtures that want to stage a cert+key pair without staging PKI folders on disk.

    When present, certificateFile / privateKeyFile become optional and may be omitted. When absent, those two fields remain required strings and a DiskCertificateKeyPairProvider is created automatically.

    defaultSecureTokenLifetime?: number

    the default secure token life time in ms.

    disableDiscovery?: boolean

    true, if discovery service on secure channel shall be disabled

    discoveryServerEndpointUrl?: string
    "opc.tcp://localhost:4840"]
    
    host?: string

    Host IP address or hostname where the TCP server listens for connections. If omitted, defaults to listening on all network interfaces:

    • Unspecified IPv6 address (::) if IPv6 is available,
    • Unspecified IPv4 address (0.0.0.0) otherwise. Use this to bind the server to a specific interface or IP.
    hostname?: string

    the primary hostname of the endpoint.

    getFullyQualifiedDomainName()
    
    isAuditing?: boolean

    if server shall raise AuditingEvent

    true
    
    maxAllowedSessionNumber?: number

    the maximum number of simultaneous sessions allowed.

    10
    

    use serverCapabilities: { maxSessions: } instead

    maxConnectionsPerEndpoint?: number

    the maximum number authorized simultaneous connections per endpoint

    10
    
    nodeset_filename?: string | string[]

    the nodeset.xml file(s) to load

    use OPCUAServerOptions.nodesets: it takes the same file paths, plus NodesetSource values for a gzip stream, an HTTP response or a string of XML. Renaming the key is the whole migration. Still honoured; entries given here load before those of nodesets.

    nodesetLoaderOptions?: NodeSetLoaderOptions

    how the nodesets load: yieldEveryBytes keeps the process responsive while a streamed model loads, imageStore replays precompiled images, permissions and accessRestrictions say what of the declared access policy is applied.

    nodesets?: string | NodesetSource[]

    the NodeSet2 documents to load: file paths, and NodesetSource values for a document that is not a file. A string is a path, as it was in nodeset_filename; anything else is a source: a gzip file inflated on the way, an HTTP response, a string of XML. They load in one call, in dependency order whatever the order given, so a source may require a model given as a path and the other way round.

    When neither nodesets nor nodeset_filename is given, the standard nodeset is loaded.

    example:

    import { nodesets, nodesetSourceFromGzipFile, nodesetSourceFromUrl, OPCUAServer } from "node-opcua";
    const server = new OPCUAServer({
    nodesets: [
    nodesets.standard,
    nodesets.di,
    nodesetSourceFromGzipFile("plant_model.xml.gz"),
    nodesetSourceFromUrl("https://models.example.com/plant.xml")
    ],
    nodesetLoaderOptions: { yieldEveryBytes: 1024 * 1024 }
    });
    onCreateMonitoredItem?: CreateMonitoredItemHook
    onDeleteMonitoredItem?: DeleteMonitoredItemHook
    port?: number

    the TCP port to listen to.

    26543
    
    privateKeyFile?: string

    the server private key full path filename

    This file should contains the private key that has been used to generate the server certificate file.

    the private key should be in PEM format

    If the key is encrypted, serverCertificateManager must be an OPCUACertificateManager constructed with a matching privateKeyPassphrase (or privateKeyProvider) — otherwise initialize() fails closed.

    registerServerMethod?: RegisterServerMethod

    strategy used by the server to declare itself to a discovery server

    • HIDDEN: the server doesn't expose itself to the external world
    • MDNS: the server publish itself to the mDNS Multicast network directly
    • LDS: the server registers itself to the LDS or LDS-ME (Local Discovery Server)
    .HIDDEN - by default the server
    will not register itself to the local discovery server
    resourcePath?: string

    resource Path is a string added at the end of the url such as "/UA/Server"

    reverseConnect?: ReverseConnectOptions

    Reverse Connect (OPC UA Part 6 §7.1.3).

    When set, the server dials OUTBOUND to each listed client reverse-connect listener and sends a ReverseHello ("RHE"), letting the client establish the SecureChannel over that socket. This is useful when the server sits behind a firewall with no open inbound ports.

    All fields are optional and, when omitted, the server behaves exactly as before (no outbound dialing).

    securityModes?: MessageSecurityMode[]

    the possible security mode that the server will expose

    [MessageSecurityMode.None, MessageSecurityMode.Sign, MessageSecurityMode.SignAndEncrypt]
    
    securityPolicies?: SecurityPolicy[]

    the possible security policies that the server will expose

    [SecurityPolicy.None, SecurityPolicy.Basic128Rsa15, SecurityPolicy.Basic256Sha256, SecurityPolicy.Aes128_Sha256_RsaOaep, SecurityPolicy.Aes256_Sha256_RsaPss  ]
    
    sendCertificateChainInCreateSession?: boolean

    What CreateSessionResponse.serverCertificate carries when the server certificate is CA-issued: false sends the leaf certificate only, true sends the whole chain (leaf, then its issuers).

    A client computing the legacy ActivateSession signature (OPC 10000-4 §6.1.8) "may use the entire chain passed in ServerCertificate", and some deployed clients do, so the leaf alone is the safer default. The endpoint descriptions and the OpenSecureChannel sender certificate keep the chain either way, and the server accepts a client signature over the leaf or over the chain whichever is chosen.

    Also settable at runtime: OPCUAServer.sendCertificateChainInCreateSession.

    false
    
    serverCapabilities?: Partial<IServerCapabilities>
    serverCertificateManager?: OPCUACertificateManager

    Server Certificate Manager

    this certificate manager will be used by the server to access and store certificates from the connecting clients

    the server Info

    this object contains the value that will populate the Root/ObjectS/Server/ServerInfo OPCUA object in the address space.

    skipOwnNamespace?: boolean

    skipOwnNamespace to true, if you don't want the server to create a dedicated namespace for its own (namespace=1). Use this flag if you intend to load the server own namespace from an external source.

    false
    
    timeout?: number

    the HEL/ACK transaction timeout in ms.

    Use a large value ( i.e 15000 ms) for slow connections or embedded devices.

    10000
    
    transportSettings?: IServerTransportSettings
    unresolvedPermissionPolicy?: UnresolvedPermissionPolicy

    how a Session's permission is resolved when neither the target Node nor its namespace declares any RolePermissions:

    • "allow" (default): grant every permission. This is how node-opcua has always behaved, and what most address spaces expect, since almost no server declares RolePermissions on its own Nodes.
    • "deny" : grant nothing. Fail-closed, for products that drive access entirely from declared policy. Expect to set DefaultRolePermissions on every namespace, otherwise the address space becomes unreadable to remote Sessions.

    This governs remote Sessions only. In-process callers keep every permission regardless.

    "allow"
    
    userCertificateManager?: OPCUACertificateManager

    user Certificate Manager this certificate manager holds the X509 certificates used by client that uses X509 certificate token to impersonate a user

    userManager?: UserManagerOptions

    an object that implements user authentication methods