Skip to content

Environment variables

This page is generated from code by npm run docs:reference. Do not edit it by hand.

Values are configuration examples from .env.example, not necessarily runtime defaults. Defaults are extracted from configuration code and Compose. Required variables depend on the integration and feature.

Variable Default Example value Requirement Description
ACTAGATE_ASSIST_DAILY_LIMIT 1000 1000 Optional; may be required by the integration Daily AI usage limit.
ACTAGATE_ASSIST_MODEL claude-opus-5 claude-opus-5 Optional; may be required by the integration Model name for AI requests.
ACTAGATE_ASSIST_PROVIDER No fixed default; depends on integration anthropic Optional; may be required by the integration AI provider. Omitted values use keyword suggestions.
ACTAGATE_AWS_IDENTITY_STORE_ID No fixed default; depends on integration d-replace-me Optional; may be required by the integration Identity Store ID.
ACTAGATE_AWS_SSO_INSTANCE_ARN No fixed default; depends on integration arn:aws:sso:::instance/ssoins-replace-me Optional; may be required by the integration IAM Identity Center instance ARN.
ACTAGATE_TRUST_PROXY_HEADERS No fixed default; depends on integration true Optional; may be required by the integration Enable when a trusted proxy overwrites forwarded headers.
ANTHROPIC_API_KEY - - Optional; may be required by the integration Injected from Secrets Manager
ANTHROPIC_AWS_WORKSPACE_ID No fixed default; depends on integration wrkspc_replace-me Optional; may be required by the integration Anthropic workspace ID for access through AWS.
ANTHROPIC_WORKSPACE_ID No fixed default; depends on integration wrkspc_replace-me Optional; may be required by the integration Anthropic workspace ID.
APP_DATABASE_PASSWORD - - Compose: required Injected from Secrets Manager
APP_DATABASE_USER actagate_app actagate_app Optional; may be required by the integration Database user for the application.
APP_DISPLAY_NAME Actagate Actagate Optional; may be required by the integration Product display name.
ATTACHMENT_ALLOWED_EXTENSIONS No fixed default; depends on integration pdf,png,jpg,jpeg,xlsx,docx,csv,txt Optional; may be required by the integration Comma-separated list of allowed attachment extensions.
AWS_ACCESS_KEY_ID - - Optional; may be required by the integration Injected from Secrets Manager
AWS_EC2_METADATA_DISABLED No fixed default; depends on integration true Optional; may be required by the integration true skips EC2 credential lookup.
AWS_REGION No fixed default; depends on integration ap-northeast-1 Optional; may be required by the integration AWS region.
AWS_SECRET_ACCESS_KEY - - Optional; may be required by the integration Injected from Secrets Manager
AWS_SESSION_TOKEN - - Optional; may be required by the integration Injected from Secrets Manager
BACKUP_INTERVAL_SECONDS 86400 86400 Optional; may be required by the integration Backup interval in seconds.
BACKUP_RETENTION_COUNT 7 7 Optional; may be required by the integration Number of retained backups.
BEDROCK_MODEL_ID No fixed default; depends on integration Unset Optional; may be required by the integration Bedrock model ID.
BEDROCK_PROMPT_CACHE auto auto Optional; may be required by the integration Bedrock prompt cache setting.
COMPOSE_PROJECT_NAME No fixed default; depends on integration actagate Optional; may be required by the integration Compose project name.
DATABASE_URL - - Web / Slack bot: required Injected from Secrets Manager
ENTRA_CLIENT_ID No fixed default; depends on integration 22222222-2222-2222-2222-222222222222 Optional; may be required by the integration Client ID for Graph execution.
ENTRA_CLIENT_SECRET - - Optional; may be required by the integration Injected from Secrets Manager
ENTRA_TENANT_ID No fixed default; depends on integration 11111111-1111-1111-1111-111111111111 Optional; may be required by the integration Tenant ID for Graph execution.
GOOGLE_ADMIN_SUBJECT No fixed default; depends on integration admin@example.com Optional; may be required by the integration Delegated administrator email for Google execution.
GOOGLE_DOMAIN No fixed default; depends on integration example.com Optional; may be required by the integration Domain for Google execution.
GOOGLE_OIDC_CLIENT_ID No fixed default; depends on integration Unset Optional; may be required by the integration Client ID for Google sign-in.
GOOGLE_OIDC_CLIENT_SECRET - - Optional; may be required by the integration Injected from Secrets Manager
GOOGLE_SA_KEY_JSON - - Optional; may be required by the integration Injected from Secrets Manager
LLM_API_KEY - - Optional; may be required by the integration Injected from Secrets Manager
LLM_BASE_URL No fixed default; depends on integration https://llm.example.com/v1 Optional; may be required by the integration Base URL for the OpenAI-compatible API.
LLM_MODEL No fixed default; depends on integration replace-me Optional; may be required by the integration Model name required by the OpenAI-compatible connection.
LLM_PROVIDER anthropic openai-compatible Optional; may be required by the integration Alias for ACTAGATE_ASSIST_PROVIDER, which takes precedence.
LOG_MAX_FILES 3 3 Optional; may be required by the integration Number of retained container logs.
LOG_MAX_SIZE 10m 10m Optional; may be required by the integration Maximum container log size.
MAIL_FROM no-reply@localhost "Actagate <no-reply@actagate.example.com>" smtp: required Sender address for notification email.
MAIL_TRANSPORT log log Optional; may be required by the integration log writes development logs; smtp delivers email.
MICROSOFT_OIDC_CLIENT_ID No fixed default; depends on integration Unset Optional; may be required by the integration Client ID for Microsoft sign-in.
MICROSOFT_OIDC_CLIENT_SECRET - - Optional; may be required by the integration Injected from Secrets Manager
MIGRATION_ADOPT_LEGACY_CHECKSUMS false false Optional; may be required by the integration Enables checksum adoption for legacy migration history.
MIGRATION_DATABASE_URL - - Optional; may be required by the integration Injected from Secrets Manager
MIGRATION_LOCK_TIMEOUT_SECONDS 60 60 Optional; may be required by the integration Migration lock timeout in seconds.
NEXT_PUBLIC_DOCS_BASE_URL No fixed default; depends on integration Unset Optional; may be required by the integration Public documentation site URL. When set, each /help guide links to it; empty hides the links.
OIDC_ISSUER_BASE_URL No fixed default; depends on integration Unset Optional; may be required by the integration Base URL for the cloud OIDC issuer. Omitted values disable it.
OIDC_SIGNING_KEYS - - Optional; may be required by the integration Injected from Secrets Manager
POSTGRES_DB actagate actagate Optional; may be required by the integration Database name.
POSTGRES_PASSWORD - - Compose: required Injected from Secrets Manager
POSTGRES_USER actagate actagate Optional; may be required by the integration Database user for migrations.
SESSION_PASSWORD - - Web: required Injected from Secrets Manager
SETUP_TOKEN - - Optional; may be required by the integration Injected from Secrets Manager
SLACK_APP_TOKEN - - Slack bot: required Injected from Secrets Manager
SLACK_BOT_TOKEN - - Slack bot: required Injected from Secrets Manager
SLACK_CLIENT_ID Empty string replace-me Optional; may be required by the integration Slack sign-in client ID.
SLACK_CLIENT_SECRET - - Optional; may be required by the integration Injected from Secrets Manager
SLACK_COMMAND_NAME /actagate /actagate Optional; may be required by the integration Slash command name matching the manifest.
SLACK_OIDC_REDIRECT_URI Empty string https://actagate.example.com/api/auth/callback Optional; may be required by the integration Slack sign-in callback URL.
SLACK_SIGNING_SECRET - - Slack bot: required Injected from Secrets Manager
SLACK_TEAM_ID No fixed default; depends on integration T0123456789 Compose: required Connected Slack workspace ID.
SLACK_WORKSPACE_NAME No fixed default; depends on integration "Example Workspace" Compose: required Workspace display name.
SMTP_URL - - smtp: required Injected from Secrets Manager
SSO_SECRET_ENCRYPTION_KEY - - Optional; may be required by the integration Injected from Secrets Manager
STAMP_EMOJI actagate actagate Optional; may be required by the integration Emoji name for approval reactions.
STAMP_MINING_THRESHOLD 5 5 Optional; may be required by the integration Number of stamps needed for a catalog suggestion.
STAMP_MINING_WINDOW_DAYS 30 30 Optional; may be required by the integration Number of days in the stamp aggregation window.
STORAGE_BUCKET No fixed default; depends on integration actagate-attachments Optional; may be required by the integration S3 bucket for attachments.
STORAGE_DRIVER fs fs Optional; may be required by the integration Attachment storage driver: fs or s3.
STORAGE_KMS_KEY_ID No fixed default; depends on integration arn:aws:kms:ap-northeast-1:123456789012:key/replace-me Optional; may be required by the integration KMS key ID for S3 encryption.
STORAGE_ROOT ./storage ./storage Optional; may be required by the integration Directory for attachments stored with fs.
TRUSTED_PROXY_CIDRS No fixed default; depends on integration Unset Optional; may be required by the integration Comma-separated list of trusted proxy CIDRs.
TRUSTED_PROXY_HOPS No fixed default; depends on integration Unset Optional; may be required by the integration XFF position counted from the right. CIDR configuration takes precedence.
WEB_BASE_URL No fixed default; depends on integration https://actagate.example.com Optional; may be required by the integration Public Web URL used for email links and same-origin checks.
WEB_PORT 3000 3000 Optional; may be required by the integration Public Web port.