Environment variables
This page is generated from code by npm run docs:reference. Do not edit it by hand.
Reference
Section titled “Reference”Values are configuration examples from .env.example, not necessarily runtime defaults. Defaults are extracted from configuration code and Compose. Required variables depend on the integration and feature.
| Variable | Default | Example value | Requirement | Description |
|---|---|---|---|---|
ACTAGATE_ASSIST_DAILY_LIMIT |
1000 |
1000 |
Optional; may be required by the integration | Daily AI usage limit. |
ACTAGATE_ASSIST_MODEL |
claude-opus-5 |
claude-opus-5 |
Optional; may be required by the integration | Model name for AI requests. |
ACTAGATE_ASSIST_PROVIDER |
No fixed default; depends on integration | anthropic |
Optional; may be required by the integration | AI provider. Omitted values use keyword suggestions. |
ACTAGATE_AWS_IDENTITY_STORE_ID |
No fixed default; depends on integration | d-replace-me |
Optional; may be required by the integration | Identity Store ID. |
ACTAGATE_AWS_SSO_INSTANCE_ARN |
No fixed default; depends on integration | arn:aws:sso:::instance/ssoins-replace-me |
Optional; may be required by the integration | IAM Identity Center instance ARN. |
ACTAGATE_TRUST_PROXY_HEADERS |
No fixed default; depends on integration | true |
Optional; may be required by the integration | Enable when a trusted proxy overwrites forwarded headers. |
ANTHROPIC_API_KEY |
- | - | Optional; may be required by the integration | Injected from Secrets Manager |
ANTHROPIC_AWS_WORKSPACE_ID |
No fixed default; depends on integration | wrkspc_replace-me |
Optional; may be required by the integration | Anthropic workspace ID for access through AWS. |
ANTHROPIC_WORKSPACE_ID |
No fixed default; depends on integration | wrkspc_replace-me |
Optional; may be required by the integration | Anthropic workspace ID. |
APP_DATABASE_PASSWORD |
- | - | Compose: required | Injected from Secrets Manager |
APP_DATABASE_USER |
actagate_app |
actagate_app |
Optional; may be required by the integration | Database user for the application. |
APP_DISPLAY_NAME |
Actagate |
Actagate |
Optional; may be required by the integration | Product display name. |
ATTACHMENT_ALLOWED_EXTENSIONS |
No fixed default; depends on integration | pdf,png,jpg,jpeg,xlsx,docx,csv,txt |
Optional; may be required by the integration | Comma-separated list of allowed attachment extensions. |
AWS_ACCESS_KEY_ID |
- | - | Optional; may be required by the integration | Injected from Secrets Manager |
AWS_EC2_METADATA_DISABLED |
No fixed default; depends on integration | true |
Optional; may be required by the integration | true skips EC2 credential lookup. |
AWS_REGION |
No fixed default; depends on integration | ap-northeast-1 |
Optional; may be required by the integration | AWS region. |
AWS_SECRET_ACCESS_KEY |
- | - | Optional; may be required by the integration | Injected from Secrets Manager |
AWS_SESSION_TOKEN |
- | - | Optional; may be required by the integration | Injected from Secrets Manager |
BACKUP_INTERVAL_SECONDS |
86400 |
86400 |
Optional; may be required by the integration | Backup interval in seconds. |
BACKUP_RETENTION_COUNT |
7 |
7 |
Optional; may be required by the integration | Number of retained backups. |
BEDROCK_MODEL_ID |
No fixed default; depends on integration | Unset | Optional; may be required by the integration | Bedrock model ID. |
BEDROCK_PROMPT_CACHE |
auto |
auto |
Optional; may be required by the integration | Bedrock prompt cache setting. |
COMPOSE_PROJECT_NAME |
No fixed default; depends on integration | actagate |
Optional; may be required by the integration | Compose project name. |
DATABASE_URL |
- | - | Web / Slack bot: required | Injected from Secrets Manager |
ENTRA_CLIENT_ID |
No fixed default; depends on integration | 22222222-2222-2222-2222-222222222222 |
Optional; may be required by the integration | Client ID for Graph execution. |
ENTRA_CLIENT_SECRET |
- | - | Optional; may be required by the integration | Injected from Secrets Manager |
ENTRA_TENANT_ID |
No fixed default; depends on integration | 11111111-1111-1111-1111-111111111111 |
Optional; may be required by the integration | Tenant ID for Graph execution. |
GOOGLE_ADMIN_SUBJECT |
No fixed default; depends on integration | admin@example.com |
Optional; may be required by the integration | Delegated administrator email for Google execution. |
GOOGLE_DOMAIN |
No fixed default; depends on integration | example.com |
Optional; may be required by the integration | Domain for Google execution. |
GOOGLE_OIDC_CLIENT_ID |
No fixed default; depends on integration | Unset | Optional; may be required by the integration | Client ID for Google sign-in. |
GOOGLE_OIDC_CLIENT_SECRET |
- | - | Optional; may be required by the integration | Injected from Secrets Manager |
GOOGLE_SA_KEY_JSON |
- | - | Optional; may be required by the integration | Injected from Secrets Manager |
LLM_API_KEY |
- | - | Optional; may be required by the integration | Injected from Secrets Manager |
LLM_BASE_URL |
No fixed default; depends on integration | https://llm.example.com/v1 |
Optional; may be required by the integration | Base URL for the OpenAI-compatible API. |
LLM_MODEL |
No fixed default; depends on integration | replace-me |
Optional; may be required by the integration | Model name required by the OpenAI-compatible connection. |
LLM_PROVIDER |
anthropic |
openai-compatible |
Optional; may be required by the integration | Alias for ACTAGATE_ASSIST_PROVIDER, which takes precedence. |
LOG_MAX_FILES |
3 |
3 |
Optional; may be required by the integration | Number of retained container logs. |
LOG_MAX_SIZE |
10m |
10m |
Optional; may be required by the integration | Maximum container log size. |
MAIL_FROM |
no-reply@localhost |
"Actagate <no-reply@actagate.example.com>" |
smtp: required | Sender address for notification email. |
MAIL_TRANSPORT |
log |
log |
Optional; may be required by the integration | log writes development logs; smtp delivers email. |
MICROSOFT_OIDC_CLIENT_ID |
No fixed default; depends on integration | Unset | Optional; may be required by the integration | Client ID for Microsoft sign-in. |
MICROSOFT_OIDC_CLIENT_SECRET |
- | - | Optional; may be required by the integration | Injected from Secrets Manager |
MIGRATION_ADOPT_LEGACY_CHECKSUMS |
false |
false |
Optional; may be required by the integration | Enables checksum adoption for legacy migration history. |
MIGRATION_DATABASE_URL |
- | - | Optional; may be required by the integration | Injected from Secrets Manager |
MIGRATION_LOCK_TIMEOUT_SECONDS |
60 |
60 |
Optional; may be required by the integration | Migration lock timeout in seconds. |
NEXT_PUBLIC_DOCS_BASE_URL |
No fixed default; depends on integration | Unset | Optional; may be required by the integration | Public documentation site URL. When set, each /help guide links to it; empty hides the links. |
OIDC_ISSUER_BASE_URL |
No fixed default; depends on integration | Unset | Optional; may be required by the integration | Base URL for the cloud OIDC issuer. Omitted values disable it. |
OIDC_SIGNING_KEYS |
- | - | Optional; may be required by the integration | Injected from Secrets Manager |
POSTGRES_DB |
actagate |
actagate |
Optional; may be required by the integration | Database name. |
POSTGRES_PASSWORD |
- | - | Compose: required | Injected from Secrets Manager |
POSTGRES_USER |
actagate |
actagate |
Optional; may be required by the integration | Database user for migrations. |
SESSION_PASSWORD |
- | - | Web: required | Injected from Secrets Manager |
SETUP_TOKEN |
- | - | Optional; may be required by the integration | Injected from Secrets Manager |
SLACK_APP_TOKEN |
- | - | Slack bot: required | Injected from Secrets Manager |
SLACK_BOT_TOKEN |
- | - | Slack bot: required | Injected from Secrets Manager |
SLACK_CLIENT_ID |
Empty string | replace-me |
Optional; may be required by the integration | Slack sign-in client ID. |
SLACK_CLIENT_SECRET |
- | - | Optional; may be required by the integration | Injected from Secrets Manager |
SLACK_COMMAND_NAME |
/actagate |
/actagate |
Optional; may be required by the integration | Slash command name matching the manifest. |
SLACK_OIDC_REDIRECT_URI |
Empty string | https://actagate.example.com/api/auth/callback |
Optional; may be required by the integration | Slack sign-in callback URL. |
SLACK_SIGNING_SECRET |
- | - | Slack bot: required | Injected from Secrets Manager |
SLACK_TEAM_ID |
No fixed default; depends on integration | T0123456789 |
Compose: required | Connected Slack workspace ID. |
SLACK_WORKSPACE_NAME |
No fixed default; depends on integration | "Example Workspace" |
Compose: required | Workspace display name. |
SMTP_URL |
- | - | smtp: required | Injected from Secrets Manager |
SSO_SECRET_ENCRYPTION_KEY |
- | - | Optional; may be required by the integration | Injected from Secrets Manager |
STAMP_EMOJI |
actagate |
actagate |
Optional; may be required by the integration | Emoji name for approval reactions. |
STAMP_MINING_THRESHOLD |
5 |
5 |
Optional; may be required by the integration | Number of stamps needed for a catalog suggestion. |
STAMP_MINING_WINDOW_DAYS |
30 |
30 |
Optional; may be required by the integration | Number of days in the stamp aggregation window. |
STORAGE_BUCKET |
No fixed default; depends on integration | actagate-attachments |
Optional; may be required by the integration | S3 bucket for attachments. |
STORAGE_DRIVER |
fs |
fs |
Optional; may be required by the integration | Attachment storage driver: fs or s3. |
STORAGE_KMS_KEY_ID |
No fixed default; depends on integration | arn:aws:kms:ap-northeast-1:123456789012:key/replace-me |
Optional; may be required by the integration | KMS key ID for S3 encryption. |
STORAGE_ROOT |
./storage |
./storage |
Optional; may be required by the integration | Directory for attachments stored with fs. |
TRUSTED_PROXY_CIDRS |
No fixed default; depends on integration | Unset | Optional; may be required by the integration | Comma-separated list of trusted proxy CIDRs. |
TRUSTED_PROXY_HOPS |
No fixed default; depends on integration | Unset | Optional; may be required by the integration | XFF position counted from the right. CIDR configuration takes precedence. |
WEB_BASE_URL |
No fixed default; depends on integration | https://actagate.example.com |
Optional; may be required by the integration | Public Web URL used for email links and same-origin checks. |
WEB_PORT |
3000 |
3000 |
Optional; may be required by the integration | Public Web port. |