Environment Variables
Environment variables take precedence over the YAML file — the standard pattern for injecting secrets via a K8s Secret / systemd EnvironmentFile / Docker --env-file without putting them in the config file itself.
| Variable | Default | Description |
|---|---|---|
CONFIG_FILE | see note below | Path to YAML config |
HOST | 0.0.0.0 | Bind address |
PORT | 8000 | Bind port |
LOG_LEVEL | info | Uvicorn log level |
RELOAD | false | Hot-reload (dev only) |
MONGODB_URI | — | Overrides storage.mongodb.uri (K8s Secret injection) |
JWT_SECRET | — | Overrides jwt.secret — set this in any multi-replica/production deployment |
TWO_FACTOR_SECRET_KEY | — | Overrides two_factor.secret_encryption_key — set this in any multi-replica/production deployment |
LLM_CREDENTIAL_KEY | — | Overrides llm.credential_encryption_key — set this in any multi-replica/production deployment. Applies to platform-only deployments too: this package encrypts SSO connection client secrets under it |
AUTH_API_KEY | — | Overrides auth.api_key, the bootstrap credential. Set this. Unset does not mean “no bootstrap key” — it means authentication is disabled and every caller becomes an anonymous superadmin (see the caution below) |
DEFAULT_ADMIN_EMAIL | — | Overrides auth.default_admin_email. Read once, at first boot, to seed the initial superadmin; ignored afterwards |
DEFAULT_ADMIN_PASSWORD | — | Overrides auth.default_admin_password. Same first-boot-only rule; must be at least 8 characters or seeding is skipped |
DEPLOYMENT_MODE | self_hosted | Overrides deployment.mode (self_hosted or cloud) — identifies which deployment this process is, not a per-org setting. See Billing / quota enforcement |
SERVER_COOKIE_DOMAIN | — | Seeds (does not override) server.cookie_domain, first boot only. server is platform-managed, so this is a one-time bootstrap for a split-domain deployment; PATCH /admin/settings always wins afterwards |
See Full Reference for what each corresponding YAML field controls.
Validation
Section titled “Validation”Configuration is validated by Pydantic at startup. Invalid values (wrong type, missing required fields, out-of-range numbers) raise a clear error before the server binds to any port.