---
title: "Orleans.Lattice.Api.Backup.Grpc configuration"
url: "https://nsta1.github.io/Orleans.Lattice/docs/lattice.api.backup.grpc/configuration.html"
source: "https://github.com/NSTA1/Orleans.Lattice/blob/release/9.9/docs/lattice.api.backup.grpc/configuration.md"
package: "Orleans.Lattice.Api.Backup.Grpc"
version: "9.9.0"
documents: "Orleans.Lattice 9.9.0 (release line 9.9)"
built: "2026-10-04"
all-pages: "https://nsta1.github.io/Orleans.Lattice/llms.txt"
bundle: "https://nsta1.github.io/Orleans.Lattice/docs/lattice.api.backup.grpc/llms-full.txt"
---
# Orleans.Lattice.Api.Backup.Grpc configuration

Part of the [Api.Backup.Grpc documentation](README.md).

The package has one public server-side options type, `LatticeBackupApiGrpcOptions`, bound through `AddLatticeBackupApiGrpc(configure)`. The client (`LatticeBackupApiGrpcClient`) carries no options of its own - transport concerns live on the `CallInvoker` / `GrpcChannel` the caller supplies.

## `LatticeBackupApiGrpcOptions`

| Property | Type | Default | Meaning |
|---|---|---|---|
| `RequireAuthorization` | `bool` | `true` | Whether the authorization interceptor enforces `ILatticeBackupApiAuthorizer` on protected inbound calls. The unauthenticated `GetAuthScheme` discovery RPC is exempt. Default-deny: the binding fails closed unless a host registers a permissive authorizer or turns enforcement off. Set to `false` only when an outer authentication boundary already guards the endpoint. |
| `CredentialHeaderName` | `string` | `authorization` | The inbound request-header (gRPC metadata) name carrying the caller's credential token, bridged into the ambient Lattice credential so the backup access gate can resolve the caller's subject. The default bridge reads it on every call, but it only has an effect when auth-backed backup control is active (the `Orleans.Lattice.Auth` add-on is registered); the core no-op gate ignores the bridged credential. |
| `CredentialScheme` | `string` | `Bearer` | The authentication scheme stamped on the bridged credential, matched by a registered credential authenticator to resolve the caller's subject. A case-insensitive scheme prefix on the header value (for example `"Bearer "`) is stripped before the remaining token is used. |
| `ActiveTenantHeaderName` | `string` | `lattice-active-tenant` | The inbound request-header (gRPC metadata) name carrying the tenant the caller is acting as, lifted onto the ambient active-tenant scope for the duration of the call so a tenant-scoped caller captures and restores only within its own namespace, and a `ListBackups` call that sets `BackupCatalogRequest.ActiveTenantOnly` is narrowed to that tenant's own trees. Defaults to `LatticeActiveTenantAssertion.DefaultHeaderName`. Set to `null` or an empty string to disable header-based tenant selection. The asserted tenant is only a claim, re-validated by the tenancy add-on; without that add-on it resolves the reserved default tenant and changes nothing. |
| `AdvertisedAuthSchemes` | `IList<AuthSchemeDescriptor>` | empty | The auth schemes the endpoint advertises from its unauthenticated `GetAuthScheme` RPC, in preference order. Empty by default (the endpoint advertises nothing, so a client falls back to manual or Basic selection). Each descriptor must carry only public configuration - never a secret. |

`AdvertisedAuthSchemes` is a read-only list property: populate it in the configure delegate (for example `o.AdvertisedAuthSchemes.Add(descriptor)`).

## Fail-closed defaults

Out of the box the binding registers `DenyAllBackupApiAuthorizer` and leaves `RequireAuthorization` at `true`, so every protected call is rejected with `PermissionDenied` until the host opts in - either by registering a permissive authorizer (or the built-in `AllowAllBackupApiAuthorizer`) or by setting `RequireAuthorization = false` behind a trusted boundary. `GetAuthScheme` remains reachable without a credential so clients can discover how to sign in. See [Architecture](architecture.md) for how the transport gate and the facade's own scope authorization combine.

## Client transport

The typed client is configured entirely through the `CallInvoker` the caller passes to `LatticeBackupApiGrpcClient.Create`:

- **Address, TLS, retries, deadlines** - set on the `GrpcChannel` / `CallInvoker`.
- **Call credentials** - attach on the channel or per call; the header name and scheme the server reads are `CredentialHeaderName` / `CredentialScheme` above.
- **Serialization** - the `IServiceProvider` passed to `Create` must have Orleans serialization registered (`AddSerializer()`) so the client and server marshallers match.
