Skip to main content
The control plane and worker are configured through environment variables. Both services share a Postgres database and must use the same encryption key and internal token. Inject secrets through your platform’s secret store. The repository’s .env.example lists every option.

Core / Required

Set these before starting either service. The encryption key and internal token are shared across both services.
CREDENTIAL_ENCRYPTION_KEY and INTERNAL_INGEST_TOKEN must be identical on both the control plane and the worker. If they differ, the worker cannot decrypt integration credentials and authenticated internal requests will fail.
string
required
PostgreSQL connection string for the shared application database.
Both the control plane and the worker connect to this database. Use a connection pooler (e.g. PgBouncer) for high-traffic deployments and set DATABASE_POOL_SIZE to match your pooler’s limits.
number
default:"5"
Optional. Maximum number of database connections per process. Defaults to 5. Increase this value when using a connection pooler such as PgBouncer, and set it to match your pooler’s per-client connection limit.
string
required
Base64-encoded 32-byte key used to encrypt all tenant integration credentials before they are stored in the database. Generate a secure value with:
Set the same value on both the control plane and the worker. Rotating this key requires re-encrypting all stored credentials.
string
required
Shared bearer token that the worker presents when making authenticated internal requests to the control plane. Generate a random value:
Set the same value on both services.
string
required
Secret used by Better Auth to sign and verify session tokens. Use a long, random string. Changing this value invalidates all active sessions.
string
Optional. Stable public HTTPS origin for integration OAuth callbacks and webhooks, for example https://superlog.example.com. Defaults to BETTER_AUTH_URL. It must be reachable by external providers.
string
Comma-separated capabilities that every new workspace starts with. Set to automations,simplified_navigation to give new workspaces the automations product described in these docs. Applies only to workspaces created after it is set.
string
Public app URL used in links that the worker sends, such as Slack messages.
string
Optional. Comma-separated sign-in emails that get platform-wide support access. Leave empty unless you operate the deployment for other teams.

Sandboxes and models

Runs execute in Daytona sandboxes. Set DAYTONA_API_KEY for any run, and AI_GATEWAY_API_KEY for automations on included usage.
string
required
API key for Daytona. Required to create run sandboxes and to store workspace secrets in Daytona’s write-only vault.
string
Vercel AI Gateway key that funds automation runs on included usage. Workspaces with their own API key or ChatGPT subscription do not need it. Without it, automations need a workspace key or subscription.
string
OpenAI API key the worker uses for tag mode. Workspace model keys in Settings → Models apply to automations only.
string
default:"gpt-5.6-sol"
Overrides the tag mode model. Defaults to gpt-5.6-sol.
string
Optional. Override the Daytona API endpoint. Leave unset to use the Daytona default.
string
Optional. Specify a Daytona target environment. Leave unset to use the Daytona default.

Authentication

Sign-in uses Better Auth. Email and password sign-in is always available. Google and GitHub sign-in are optional.
string
required
Public origin of the app, for example https://superlog.example.com.
string
Google OAuth 2.0 client ID for Google login. Create an OAuth app in Google Cloud Console and set the authorized redirect URI to:
string
Google OAuth 2.0 client secret paired with AUTH_GOOGLE_CLIENT_ID.
string
GitHub OAuth app client ID for GitHub login. Set the authorization callback URL to:
string
GitHub OAuth app client secret paired with AUTH_GITHUB_CLIENT_ID.

Invitation email

Invitation emails are sent through Resend. Without it, invitations are still created and their links can be copied from Settings → Workspace.
string
API key for Resend. When omitted, invitations are created but not emailed.
string
default:"Responder <no-reply@superlog.sh>"
Sender address and display name for outgoing invitation emails. Use a domain you control and have verified with Resend.
string
Optional. Reply-to address added to outgoing invitation emails. When set, replies from recipients are delivered to this address instead of the sender address. Leave unset to omit a reply-to header.

Integrations (First-Party Apps)

These integrations need an app registered with the provider. Callback and webhook URLs use your public origin. Dash0, PostHog, Grafana, Axiom, ClickStack, Langfuse, Upstash, Supabase, Datadog, and custom MCP servers need no deployment-level configuration.

GitHub

Create a public GitHub App and configure it as described in the integrations guide. The private key value should be the full PEM string (newlines escaped as \n or using a multi-line secret). OAuth callback: {RESPONDER_PUBLIC_URL}/api/integrations/github/callback
Webhook URL: {RESPONDER_PUBLIC_URL}/api/webhooks/github

Slack

Configure a distributed Slack app with bot and user scopes as described in the integrations guide. OAuth callback: {RESPONDER_PUBLIC_URL}/api/integrations/slack/callback
Events URL: {RESPONDER_PUBLIC_URL}/api/webhooks/slack
Interactivity URL: {RESPONDER_PUBLIC_URL}/api/webhooks/slack/actions

Sentry

Create a public Sentry integration with issue.created and issue.unresolved subscriptions. Redirect URL: {RESPONDER_PUBLIC_URL}/api/integrations/sentry/callback
Webhook URL: {RESPONDER_PUBLIC_URL}/api/webhooks/sentry

Linear

Create a Linear OAuth app with read and write scopes. OAuth callback: {RESPONDER_PUBLIC_URL}/api/integrations/linear/callback

Vercel

Create a Vercel Integration with read-only scopes (no write, no secret/token access). Redirect URL: {RESPONDER_PUBLIC_URL}/api/integrations/vercel/callback

Discord

Create a Discord application with a bot, enable Requires OAuth2 Code Grant, and grant View Channels permission. OAuth callback: {RESPONDER_PUBLIC_URL}/api/integrations/discord/callback
Interactions endpoint: {RESPONDER_PUBLIC_URL}/api/webhooks/discord

AWS Integration

AWS support requires a stable broker IAM role that Superlog assumes to access customer AWS accounts. The CloudFormation template variables are optional but recommended for production — they let Superlog generate a short-lived presigned S3 URL instead of offering a file download.
string
ARN of the stable broker IAM role that Superlog assumes in order to call sts:AssumeRole on customer ResponderInvestigationRole roles. Required for AWS context to work on self-hosted deployments. The broker must allow sts:AssumeRole only on roles named ResponderInvestigationRole.
string
Name of the private S3 bucket that hosts the CloudFormation stack template. When all three AWS_INTEGRATION_TEMPLATE_* values are set, Superlog generates a presigned URL for CloudFormation Quick Create instead of offering a file download.
string
S3 object key of the CloudFormation template within AWS_INTEGRATION_TEMPLATE_BUCKET.
string
AWS region of AWS_INTEGRATION_TEMPLATE_BUCKET, used to construct the presigned URL.

Google Cloud Integration

Google Cloud setup uses a one-time OAuth flow to provision customer-owned Workload Identity Federation resources. Superlog does not store a long-lived token — the setup token is used and revoked during the background setup job.
string
Client ID of the Google OAuth web client used during Google Cloud project setup. The Google Cloud project that owns this client must have the Cloud Resource Manager, Service Usage, and IAM APIs enabled.
string
Client secret paired with GCP_OAUTH_CLIENT_ID.
The Google Cloud integration also requires AWS_INTEGRATION_PRINCIPAL_ARN. Superlog uses the same AWS broker role to federate a short-lived Google Cloud identity via Workload Identity Federation. Self-hosted deployments must run on AWS with permission to assume that role.
OAuth callback: {RESPONDER_PUBLIC_URL}/api/integrations/gcp/callback

Billing (Optional)

Billing meters each workspace’s monthly usage allowance through Autumn. Without it, usage is not metered or limited.
string
default:"false"
Set to true to meter usage. Automations and tag mode draw on each workspace’s monthly allowance. Configure it on both services.
string
Secret key for the Autumn billing service. Required when BILLING_ENABLED=true. Configure this on both the control plane and the worker.

Monitoring and analytics (optional)