Remote config
Contents
Boolean and multivariate flags are helpful for dynamic values that differ from user to user, but sometimes you need a simple way to pass configuration related to your application without having to make code changes or redeploy your app.
Remote config flags enable you to configure a simple flag that always returns the same payload wherever it is called. Remote config flags can also be stored as encrypted values and decrypted on the server side when requested. Encryption/decryption is handled automatically.
You can think of remote config flags as multivariate flags with a single variant which is served for all flag requests. By default, enabled remote config flags roll out to 100% of all users.
Using remote config in client-side apps
Non-encrypted remote config flags are served through the /flags endpoint like any other feature flag, using your project API key (the one starting with phc_), which is safe to expose publicly. Read the payload with your SDK's flag payload function. For example, in posthog-js:
This also works for CLIs, scripts, or anything else that can call /flags with your project API key.
Note: Flags with encrypted payloads are excluded from
/flagsentirely, so they can't be read client-side and require a server.
Using remote config on the server
Server-side SDKs fetch remote config payloads using your secret API key. This key is only required for local evaluation and server-side remote config – not for remote config in general. It returns encrypted payloads redacted, so use a personal API key if you need them decrypted. Unlike your project API key, it must never be exposed publicly.
There are 3 steps to use remote config flags on the server:
Step 1: Get a secret API key
Server-side SDKs need a secret API key to fetch your project's feature flag definitions for local evaluation and remote config. This can be a project secret API key (recommended) or the legacy feature flags secure API key. Keep it secret: don't use it in frontend code or expose it to users.
We recommend using a project secret API key with the feature_flag:read scope. Project secret API keys are hashed at rest, scoped to only what they need, and you can create up to 50 per project, so you can issue and roll keys per deployment without affecting the others.
Building a frontend, mobile, or CLI app? Local evaluation and the secret API key are for server-side use only. To evaluate flags from client-side code, use a client-side SDK or call the public
/flagsendpoint with your project API key instead. The project API key is safe to expose to users.
Note: Existing feature flags secure API keys (deprecated) and personal API keys continue to work. We recommend switching to a project secret API key. If you use encrypted payloads, keep a personal API key for those requests, since it's the only key that returns them decrypted.
How to create a project secret API key
Go to Project secret API keys in your project settings. You need project admin access to create a key.
Create a new key with the Local feature flag evaluation preset (the
feature_flag:readscope) and give it a label.Copy the key. It's only displayed once, so store it somewhere safe, like a secrets manager.
Use it to initialize the PostHog client. Recent SDK versions take it through a secret key option (for example,
secretKeyin Node andsecret_keyin Python). Older SDK versions and the Java SDK use the personal API key option instead (for example,personalApiKeyin Node), which recent versions keep as a deprecated alias.
Step 2: Initialize PostHog with your secret API key in options
Note: By default, initializing PostHog with your secret API key enables local evaluation, but this can be disabled in
posthog-nodeby settingenableLocalEvaluation: falsein your config.
Step 3: Use remote config flags
Note: Remote config flags are meant to always serve payloads and be called with the flag payload function in each SDK. If
getFeatureFlagis called instead, the SDK simply returnstrue
Encrypted payloads
Encrypted payloads are only available server-side, through the authenticated remote config API. Authenticate with a personal API key to receive the decrypted payload – secret API keys, including project secret API keys, return encrypted payloads redacted.