.env.example lists every option.
Core / Required
Set these before starting either service. The encryption key and internal token are shared across both services.string
required
PostgreSQL connection string for the shared application database.Both the control plane and the worker connect to this database. Use a connection pooler (e.g. PgBouncer) for high-traffic deployments and set
DATABASE_POOL_SIZE to match your pooler’s limits.number
default:"5"
Optional. Maximum number of database connections per process. Defaults to
5. Increase this value when using a connection pooler such as PgBouncer, and set it to match your pooler’s per-client connection limit.string
required
Base64-encoded 32-byte key used to encrypt all tenant integration credentials before they are stored in the database. Generate a secure value with:Set the same value on both the control plane and the worker. Rotating this key requires re-encrypting all stored credentials.
string
required
Shared bearer token that the worker presents when making authenticated internal requests to the control plane. Generate a random value:Set the same value on both services.
string
required
Secret used by Better Auth to sign and verify session tokens. Use a long, random string. Changing this value invalidates all active sessions.
string
Optional. Stable public HTTPS origin for integration OAuth callbacks and webhooks, for example
https://superlog.example.com. Defaults to BETTER_AUTH_URL. It must be reachable by external providers.string
Comma-separated capabilities that every new workspace starts with. Set to
automations,simplified_navigation to give new workspaces the automations product described in these docs. Applies only to workspaces created after it is set.string
Public app URL used in links that the worker sends, such as Slack messages.
string
Optional. Comma-separated sign-in emails that get platform-wide support access. Leave empty unless you operate the deployment for other teams.
Sandboxes and models
Runs execute in Daytona sandboxes. SetDAYTONA_API_KEY for any run, and AI_GATEWAY_API_KEY for automations on included usage.
string
required
API key for Daytona. Required to create run sandboxes and to store workspace secrets in Daytona’s write-only vault.
string
Vercel AI Gateway key that funds automation runs on included usage. Workspaces with their own API key or ChatGPT subscription do not need it. Without it, automations need a workspace key or subscription.
string
OpenAI API key the worker uses for tag mode. Workspace model keys in Settings → Models apply to automations only.
string
default:"gpt-5.6-sol"
Overrides the tag mode model. Defaults to
gpt-5.6-sol.string
Optional. Override the Daytona API endpoint. Leave unset to use the Daytona default.
string
Optional. Specify a Daytona target environment. Leave unset to use the Daytona default.
Authentication
Sign-in uses Better Auth. Email and password sign-in is always available. Google and GitHub sign-in are optional.string
required
Public origin of the app, for example
https://superlog.example.com.string
Google OAuth 2.0 client ID for Google login. Create an OAuth app in Google Cloud Console and set the authorized redirect URI to:
string
Google OAuth 2.0 client secret paired with
AUTH_GOOGLE_CLIENT_ID.string
GitHub OAuth app client ID for GitHub login. Set the authorization callback URL to:
string
GitHub OAuth app client secret paired with
AUTH_GITHUB_CLIENT_ID.Invitation email
Invitation emails are sent through Resend. Without it, invitations are still created and their links can be copied from Settings → Workspace.string
default:"Responder <no-reply@superlog.sh>"
Sender address and display name for outgoing invitation emails. Use a domain you control and have verified with Resend.
string
Optional. Reply-to address added to outgoing invitation emails. When set, replies from recipients are delivered to this address instead of the sender address. Leave unset to omit a reply-to header.
Integrations (First-Party Apps)
These integrations need an app registered with the provider. Callback and webhook URLs use your public origin. Dash0, PostHog, Grafana, Axiom, ClickStack, Langfuse, Upstash, Supabase, Datadog, and custom MCP servers need no deployment-level configuration.GitHub
Create a public GitHub App and configure it as described in the integrations guide. The private key value should be the full PEM string (newlines escaped as\n or using a multi-line secret).
OAuth callback:
{RESPONDER_PUBLIC_URL}/api/integrations/github/callbackWebhook URL:
{RESPONDER_PUBLIC_URL}/api/webhooks/github
Slack
Configure a distributed Slack app with bot and user scopes as described in the integrations guide.
OAuth callback:
{RESPONDER_PUBLIC_URL}/api/integrations/slack/callbackEvents URL:
{RESPONDER_PUBLIC_URL}/api/webhooks/slackInteractivity URL:
{RESPONDER_PUBLIC_URL}/api/webhooks/slack/actions
Sentry
Create a public Sentry integration withissue.created and issue.unresolved subscriptions.
Redirect URL:
{RESPONDER_PUBLIC_URL}/api/integrations/sentry/callbackWebhook URL:
{RESPONDER_PUBLIC_URL}/api/webhooks/sentry
Linear
Create a Linear OAuth app withread and write scopes.
OAuth callback:
{RESPONDER_PUBLIC_URL}/api/integrations/linear/callback
Vercel
Create a Vercel Integration with read-only scopes (no write, no secret/token access).
Redirect URL:
{RESPONDER_PUBLIC_URL}/api/integrations/vercel/callback
Discord
Create a Discord application with a bot, enable Requires OAuth2 Code Grant, and grant View Channels permission.
OAuth callback:
{RESPONDER_PUBLIC_URL}/api/integrations/discord/callbackInteractions endpoint:
{RESPONDER_PUBLIC_URL}/api/webhooks/discord
AWS Integration
AWS support requires a stable broker IAM role that Superlog assumes to access customer AWS accounts. The CloudFormation template variables are optional but recommended for production — they let Superlog generate a short-lived presigned S3 URL instead of offering a file download.string
ARN of the stable broker IAM role that Superlog assumes in order to call
sts:AssumeRole on customer ResponderInvestigationRole roles. Required for AWS context to work on self-hosted deployments. The broker must allow sts:AssumeRole only on roles named ResponderInvestigationRole.string
Name of the private S3 bucket that hosts the CloudFormation stack template. When all three
AWS_INTEGRATION_TEMPLATE_* values are set, Superlog generates a presigned URL for CloudFormation Quick Create instead of offering a file download.string
S3 object key of the CloudFormation template within
AWS_INTEGRATION_TEMPLATE_BUCKET.string
AWS region of
AWS_INTEGRATION_TEMPLATE_BUCKET, used to construct the presigned URL.Google Cloud Integration
Google Cloud setup uses a one-time OAuth flow to provision customer-owned Workload Identity Federation resources. Superlog does not store a long-lived token — the setup token is used and revoked during the background setup job.string
Client ID of the Google OAuth web client used during Google Cloud project setup. The Google Cloud project that owns this client must have the Cloud Resource Manager, Service Usage, and IAM APIs enabled.
string
Client secret paired with
GCP_OAUTH_CLIENT_ID.The Google Cloud integration also requires
AWS_INTEGRATION_PRINCIPAL_ARN. Superlog uses the same AWS broker role to federate a short-lived Google Cloud identity via Workload Identity Federation. Self-hosted deployments must run on AWS with permission to assume that role.{RESPONDER_PUBLIC_URL}/api/integrations/gcp/callback
Billing (Optional)
Billing meters each workspace’s monthly usage allowance through Autumn. Without it, usage is not metered or limited.string
default:"false"
Set to
true to meter usage. Automations and tag mode draw on each workspace’s monthly allowance. Configure it on both services.string
Secret key for the Autumn billing service. Required when
BILLING_ENABLED=true. Configure this on both the control plane and the worker.