> ## Documentation Index
> Fetch the complete documentation index at: https://docs.superlog.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Environment variables

> Environment variables for the Superlog control plane and worker: database, sign-in, sandboxes, models, integrations, and billing.

The control plane and worker are configured through environment variables. Both services share a Postgres database and must use the same encryption key and internal token. Inject secrets through your platform's secret store. The repository's [`.env.example`](https://github.com/superloglabs/responder-oss/blob/main/.env.example) lists every option.

***

## Core / Required

Set these before starting either service. The encryption key and internal token are shared across both services.

<Warning>
  `CREDENTIAL_ENCRYPTION_KEY` and `INTERNAL_INGEST_TOKEN` must be **identical** on both the control plane and the worker. If they differ, the worker cannot decrypt integration credentials and authenticated internal requests will fail.
</Warning>

<ParamField path="DATABASE_URL" type="string" required>
  PostgreSQL connection string for the shared application database.

  ```text theme={null}
  postgresql://user:pass@host:5432/responder
  ```

  Both the control plane and the worker connect to this database. Use a connection pooler (e.g. PgBouncer) for high-traffic deployments and set `DATABASE_POOL_SIZE` to match your pooler's limits.
</ParamField>

<ParamField path="DATABASE_POOL_SIZE" type="number" default="5">
  Optional. Maximum number of database connections per process. Defaults to `5`. Increase this value when using a connection pooler such as PgBouncer, and set it to match your pooler's per-client connection limit.
</ParamField>

<ParamField path="CREDENTIAL_ENCRYPTION_KEY" type="string" required>
  Base64-encoded 32-byte key used to encrypt all tenant integration credentials before they are stored in the database. Generate a secure value with:

  ```bash theme={null}
  openssl rand -base64 32
  ```

  Set the same value on **both** the control plane and the worker. Rotating this key requires re-encrypting all stored credentials.
</ParamField>

<ParamField path="INTERNAL_INGEST_TOKEN" type="string" required>
  Shared bearer token that the worker presents when making authenticated internal requests to the control plane. Generate a random value:

  ```bash theme={null}
  openssl rand -hex 32
  ```

  Set the same value on both services.
</ParamField>

<ParamField path="BETTER_AUTH_SECRET" type="string" required>
  Secret used by Better Auth to sign and verify session tokens. Use a long, random string. Changing this value invalidates all active sessions.
</ParamField>

<ParamField path="RESPONDER_PUBLIC_URL" type="string">
  Optional. Stable public HTTPS origin for integration OAuth callbacks and webhooks, for example `https://superlog.example.com`. Defaults to `BETTER_AUTH_URL`. It must be reachable by external providers.
</ParamField>

<ParamField path="RESPONDER_NEW_ORGANIZATION_CAPABILITIES" type="string">
  Comma-separated capabilities that every new workspace starts with. Set to `automations,simplified_navigation` to give new workspaces the automations product described in these docs. Applies only to workspaces created after it is set.
</ParamField>

<ParamField path="CONTROL_PLANE_URL" type="string">
  Public app URL used in links that the worker sends, such as Slack messages.
</ParamField>

<ParamField path="SUPERUSER_EMAILS" type="string">
  Optional. Comma-separated sign-in emails that get platform-wide support access. Leave empty unless you operate the deployment for other teams.
</ParamField>

***

## Sandboxes and models

Runs execute in Daytona sandboxes. Set `DAYTONA_API_KEY` for any run, and `AI_GATEWAY_API_KEY` for automations on included usage.

<ParamField path="DAYTONA_API_KEY" type="string" required>
  API key for Daytona. Required to create run sandboxes and to store workspace secrets in Daytona's write-only vault.
</ParamField>

<ParamField path="AI_GATEWAY_API_KEY" type="string">
  Vercel AI Gateway key that funds automation runs on included usage. Workspaces with their own API key or ChatGPT subscription do not need it. Without it, automations need a workspace key or subscription.
</ParamField>

<ParamField path="OPENAI_API_KEY" type="string">
  OpenAI API key the worker uses for tag mode. Workspace model keys in **Settings → Models** apply to automations only.
</ParamField>

<ParamField path="OPENAI_AGENT_MODEL" type="string" default="gpt-5.6-sol">
  Overrides the tag mode model. Defaults to `gpt-5.6-sol`.
</ParamField>

<ParamField path="DAYTONA_API_URL" type="string">
  Optional. Override the Daytona API endpoint. Leave unset to use the Daytona default.
</ParamField>

<ParamField path="DAYTONA_TARGET" type="string">
  Optional. Specify a Daytona target environment. Leave unset to use the Daytona default.
</ParamField>

***

## Authentication

Sign-in uses Better Auth. Email and password sign-in is always available. Google and GitHub sign-in are optional.

<ParamField path="BETTER_AUTH_URL" type="string" required>
  Public origin of the app, for example `https://superlog.example.com`.
</ParamField>

<ParamField path="AUTH_GOOGLE_CLIENT_ID" type="string">
  Google OAuth 2.0 client ID for Google login. Create an OAuth app in Google Cloud Console and set the authorized redirect URI to:

  ```text theme={null}
  https://superlog.example.com/api/auth/callback/google
  ```
</ParamField>

<ParamField path="AUTH_GOOGLE_CLIENT_SECRET" type="string">
  Google OAuth 2.0 client secret paired with `AUTH_GOOGLE_CLIENT_ID`.
</ParamField>

<ParamField path="AUTH_GITHUB_CLIENT_ID" type="string">
  GitHub OAuth app client ID for GitHub login. Set the authorization callback URL to:

  ```text theme={null}
  https://superlog.example.com/api/auth/callback/github
  ```
</ParamField>

<ParamField path="AUTH_GITHUB_CLIENT_SECRET" type="string">
  GitHub OAuth app client secret paired with `AUTH_GITHUB_CLIENT_ID`.
</ParamField>

***

## Invitation email

Invitation emails are sent through Resend. Without it, invitations are still created and their links can be copied from **Settings → Workspace**.

<ParamField path="RESEND_API_KEY" type="string">
  API key for [Resend](https://resend.com). When omitted, invitations are created but not emailed.
</ParamField>

<ParamField path="RESPONDER_FROM_EMAIL" type="string" default="Responder <no-reply@superlog.sh>">
  Sender address and display name for outgoing invitation emails. Use a domain you control and have verified with Resend.
</ParamField>

<ParamField path="RESPONDER_REPLY_TO_EMAIL" type="string">
  Optional. Reply-to address added to outgoing invitation emails. When set, replies from recipients are delivered to this address instead of the sender address. Leave unset to omit a reply-to header.
</ParamField>

***

## Integrations (First-Party Apps)

These integrations need an app registered with the provider. Callback and webhook URLs use your public origin. Dash0, PostHog, Grafana, Axiom, ClickStack, Langfuse, Upstash, Supabase, Datadog, and custom MCP servers need no deployment-level configuration.

### GitHub

Create a public GitHub App and configure it as described in the integrations guide. The private key value should be the full PEM string (newlines escaped as `\n` or using a multi-line secret).

| Variable | Description |
| - | - |
| `GITHUB_APP_ID` | Numeric GitHub App ID shown on the app's settings page |
| `GITHUB_APP_SLUG` | URL slug of the GitHub App |
| `GITHUB_APP_PRIVATE_KEY` | PEM-encoded private key for the GitHub App |
| `GITHUB_CLIENT_ID` | OAuth client ID (for user authorization during installation) |
| `GITHUB_CLIENT_SECRET` | OAuth client secret paired with `GITHUB_CLIENT_ID` |
| `GITHUB_WEBHOOK_SECRET` | Secret used to verify `X-Hub-Signature-256` on incoming webhooks |

OAuth callback: `{RESPONDER_PUBLIC_URL}/api/integrations/github/callback`\
Webhook URL: `{RESPONDER_PUBLIC_URL}/api/webhooks/github`

### Slack

Configure a distributed Slack app with bot and user scopes as described in the integrations guide.

| Variable | Description |
| - | - |
| `SLACK_CLIENT_ID` | Slack app client ID |
| `SLACK_CLIENT_SECRET` | Slack app client secret |
| `SLACK_SIGNING_SECRET` | Signing secret used to verify incoming Slack event payloads |

OAuth callback: `{RESPONDER_PUBLIC_URL}/api/integrations/slack/callback`\
Events URL: `{RESPONDER_PUBLIC_URL}/api/webhooks/slack`\
Interactivity URL: `{RESPONDER_PUBLIC_URL}/api/webhooks/slack/actions`

### Sentry

Create a public Sentry integration with `issue.created` and `issue.unresolved` subscriptions.

| Variable | Description |
| - | - |
| `SENTRY_APP_SLUG` | Sentry integration slug |
| `SENTRY_CLIENT_ID` | Sentry integration client ID |
| `SENTRY_CLIENT_SECRET` | Sentry integration client secret |

Redirect URL: `{RESPONDER_PUBLIC_URL}/api/integrations/sentry/callback`\
Webhook URL: `{RESPONDER_PUBLIC_URL}/api/webhooks/sentry`

### Linear

Create a Linear OAuth app with `read` and `write` scopes.

| Variable | Description |
| - | - |
| `LINEAR_CLIENT_ID` | Linear OAuth app client ID |
| `LINEAR_CLIENT_SECRET` | Linear OAuth app client secret |

OAuth callback: `{RESPONDER_PUBLIC_URL}/api/integrations/linear/callback`

### Vercel

Create a Vercel Integration with read-only scopes (no write, no secret/token access).

| Variable | Description |
| - | - |
| `VERCEL_INTEGRATION_SLUG` | Slug of your Vercel Integration |
| `VERCEL_CLIENT_ID` | Vercel integration client ID |
| `VERCEL_CLIENT_SECRET` | Vercel integration client secret |

Redirect URL: `{RESPONDER_PUBLIC_URL}/api/integrations/vercel/callback`

### Discord

Create a Discord application with a bot, enable **Requires OAuth2 Code Grant**, and grant View Channels permission.

| Variable | Description |
| - | - |
| `DISCORD_APPLICATION_ID` | Discord application ID |
| `DISCORD_BOT_TOKEN` | Bot token for the Discord application |
| `DISCORD_CLIENT_SECRET` | OAuth2 client secret |
| `DISCORD_PUBLIC_KEY` | Public key for verifying interaction signatures |

OAuth callback: `{RESPONDER_PUBLIC_URL}/api/integrations/discord/callback`\
Interactions endpoint: `{RESPONDER_PUBLIC_URL}/api/webhooks/discord`

***

## AWS Integration

AWS support requires a stable broker IAM role that Superlog assumes to access customer AWS accounts. The CloudFormation template variables are optional but recommended for production — they let Superlog generate a short-lived presigned S3 URL instead of offering a file download.

<ParamField path="AWS_INTEGRATION_PRINCIPAL_ARN" type="string">
  ARN of the stable broker IAM role that Superlog assumes in order to call `sts:AssumeRole` on customer `ResponderInvestigationRole` roles. Required for AWS context to work on self-hosted deployments. The broker must allow `sts:AssumeRole` only on roles named `ResponderInvestigationRole`.

  ```text theme={null}
  arn:aws:iam::123456789012:role/ResponderBrokerRole
  ```
</ParamField>

<ParamField path="AWS_INTEGRATION_TEMPLATE_BUCKET" type="string">
  Name of the private S3 bucket that hosts the CloudFormation stack template. When all three `AWS_INTEGRATION_TEMPLATE_*` values are set, Superlog generates a presigned URL for CloudFormation Quick Create instead of offering a file download.
</ParamField>

<ParamField path="AWS_INTEGRATION_TEMPLATE_KEY" type="string">
  S3 object key of the CloudFormation template within `AWS_INTEGRATION_TEMPLATE_BUCKET`.
</ParamField>

<ParamField path="AWS_INTEGRATION_TEMPLATE_REGION" type="string">
  AWS region of `AWS_INTEGRATION_TEMPLATE_BUCKET`, used to construct the presigned URL.
</ParamField>

***

## Google Cloud Integration

Google Cloud setup uses a one-time OAuth flow to provision customer-owned Workload Identity Federation resources. Superlog does not store a long-lived token — the setup token is used and revoked during the background setup job.

<ParamField path="GCP_OAUTH_CLIENT_ID" type="string">
  Client ID of the Google OAuth web client used during Google Cloud project setup. The Google Cloud project that owns this client must have the Cloud Resource Manager, Service Usage, and IAM APIs enabled.
</ParamField>

<ParamField path="GCP_OAUTH_CLIENT_SECRET" type="string">
  Client secret paired with `GCP_OAUTH_CLIENT_ID`.
</ParamField>

<Note>
  The Google Cloud integration also requires `AWS_INTEGRATION_PRINCIPAL_ARN`. Superlog uses the same AWS broker role to federate a short-lived Google Cloud identity via Workload Identity Federation. Self-hosted deployments must run on AWS with permission to assume that role.
</Note>

OAuth callback: `{RESPONDER_PUBLIC_URL}/api/integrations/gcp/callback`

***

## Billing (Optional)

Billing meters each workspace's monthly usage allowance through [Autumn](https://useautumn.com). Without it, usage is not metered or limited.

<ParamField path="BILLING_ENABLED" type="string" default="false">
  Set to `true` to meter usage. Automations and tag mode draw on each workspace's monthly allowance. Configure it on both services.
</ParamField>

<ParamField path="AUTUMN_SECRET_KEY" type="string">
  Secret key for the [Autumn](https://useautumn.com) billing service. Required when `BILLING_ENABLED=true`. Configure this on both the control plane and the worker.
</ParamField>

***

## Monitoring and analytics (optional)

| Variable | Purpose |
| - | - |
| `SENTRY_DSN`, `VITE_SENTRY_DSN` | Error monitoring for the services and the browser app. |
| `SENTRY_ENVIRONMENT`, `SENTRY_RELEASE`, `SENTRY_TRACES_SAMPLE_RATE` | Server error monitoring settings. `VITE_`-prefixed versions apply to the browser. |
| `SENTRY_ORG`, `SENTRY_PROJECT`, `SENTRY_AUTH_TOKEN` | Build-time source map upload. Never expose the auth token through a `VITE_` variable. |
| `POSTHOG_PROJECT_TOKEN`, `POSTHOG_HOST` | Product analytics from the services. `VITE_`-prefixed versions apply to the browser. |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.