Self-hosted Mercure Installation for Guided Shopping

Mercure general settings

Publisher JWT Keypublisher_jwtThe JWT key used for authenticating publishers
Subscriber JWT Keysubscriber_jwtThe JWT key used for authenticating subscribers
CORS Origincors_originsList of domains allowed to connect to the Mercure hub as value of the cors_origins. For other cases, check troubleshoot cors errors
UIuiEnable the UI and expose the demo
DemodemoEnable the UI but do not expose the demo
AnonymousanonymousAllow subscribers with no valid JWT to connect

Mercure installation

There are two recommended ways of Mercure installations:

1. Docker

If you host Mercure yourself, the easiest way is to do it via docker. The image can be found at dunglas/mercure.

Configure Mercure docker

The docker image allows you to use the following env variables to configure Mercure.


Use different publisher and subscriber keys for security reasons.

- MERCURE_PUBLISHER_JWT_KEY: your-256-bit-publisher-key
- MERCURE_SUBSCRIBER_JWT_KEY: your-256-bit-subscriber-key
   cors_origins ""  
   anonymous 0  
   ui 1

You can also configure it like the self-installed version via the Caddyfile.

// Sample Caddyfile
    # Debug mode (disable it in production!)
    # HTTP/3 support
route {
    redir / /.well-known/mercure/ui/
    encode gzip
    mercure {
        # Enable the demo endpoint (disable it in production!)
        # Publisher JWT key
        publisher_jwt MySecret
        # Subscriber JWT key
        subscriber_jwt MySecret
        # CORS
        cors_origins http://localhost:3000 http://localhost:8080 http://shopware.test
        publish_origins localhost:3000 localhost:8080 shopware.test
        # Allow anonymous subscribers (double-check that it's what you want)
        # Enable the subscription API (double-check that it's what you want)
    respond "Not Found" 404

2. Self-installation

The installation guide explains all steps that are required for installing the Mercure.

Production configuration

mercure {
publisher_jwt my-publisher-key HS256  
subscriber_jwt my-subscriber-key HS256  
cors_origins ""  
demo 0  
ui 0