DocsAPI Reference

Environment Variables

Reference for the environment variables that configure the gateway, core, auth and billing services


Tokamak is configured entirely through environment variables. In the shipped Docker Compose stack they live in a single .env file that the services consume through their Compose configuration.

Defaults below are the values compiled into each service. Deployment templates override some of them — where that matters it is called out.

For production-focused guidance, see Configuration.

The core service's configuration struct still declares variables for features that were removed from the product (project management, Slack, the GitHub bot, sandboxes, knowledge and memory, and the MCP tools engine). Setting them has no effect — the code paths they configured are gone. The executable service configuration remains authoritative; legacy fields do not establish a working feature.


Gateway

The gateway is the public backend listener; frontends have separate origins or proxy routes.

VariableDefaultDescription
HTTP_PORT8080Public API port
METRICS_PORT9092Prometheus metrics port
TOKAMAK_CORE_URLhttp://tokamak-core:8090Where to reach the core service
TOKAMAK_AUTH_URLhttp://tokamak-auth:8092Where to reach the auth service
CORS_ALLOWED_ORIGINS—Comma-separated allowed origins
AUTHZ_DELEGATION_PRIVATE_KEY—Ed25519 key used to sign delegation JWTs. An ephemeral key is generated if unset, which breaks across restarts and replicas — set it in production.
AUTHZ_DELEGATION_KEY_ID—Key ID published in the delegation JWKS

Auth

VariableDefaultDescription
HTTP_PORT8092Auth service port (cluster-private)
METRICS_PORT9093Prometheus metrics port
TOKAMAK_AUTH_DB_DSNfalls back to DB_POSTGRESQL_WRITE_DSNPostgreSQL connection string
TOKAMAK_AUTH_DB_SCHEMAtokamak_authSchema the auth service owns
TOKAMAK_AUTH_UPSTREAM_URLfalls back to TOKAMAK_CORE_URL, then http://tokamak-core:8090Upstream core service
TOKAMAK_AUTH_ENCRYPTION_SECRET—Encryption secret for stored credentials
JWT_SIGNING_SECRET—HS256 signing key (minimum 32 characters)
JWT_ISSUERtokamak-authToken issuer claim
JWT_ACCESS_TOKEN_TTL1hAccess token lifetime
JWT_REFRESH_TOKEN_TTL168hRefresh token lifetime
TOKAMAK_AUTH_JWT_AUDIENCE—Required audience claim, when set
SYSTEM_ADMIN_EMAIL—Comma-separated emails seeded a platform/owner assignment on startup

Auth runs its own migrations on boot regardless of AUTO_MIGRATE.

Keycloak (optional)

Keycloak is not started by the Compose stack — these point at an existing installation.

VariableDefaultDescription
KEYCLOAK_ENABLEDfalseEnable OIDC validation
KEYCLOAK_BASE_URL—Required when enabled
KEYCLOAK_REALM—Required when enabled
KEYCLOAK_CLIENT_ID—Client ID
KEYCLOAK_JWKS_URLderived from base URL and realmJWKS endpoint
KEYCLOAK_ISSUERderived from base URL and realmExpected issuer
KEYCLOAK_CLOCK_SKEW60sClock skew tolerance

Core

Core is cluster-private and holds the business logic.

Server

VariableDefaultDescription
HTTP_PORT8080Core service port. The shipped deployment templates set this to 8090, which is what gateway and auth expect by default.
METRICS_PORT9091Prometheus metrics port
STREAM_TIMEOUT3600sLongest one upstream exchange may last, streaming or not
STREAM_IDLE_TIMEOUT300sEnd an upstream exchange after this long with nothing from the upstream: no response headers, then no body bytes. A non-streaming answer is bounded by it too. 0 turns the check off; otherwise 30s to 1h
STREAM_KEEPALIVE_INTERVAL15sWrite an SSE : keep-alive comment when a stream has been silent this long, so proxies in front keep the connection open. 0 turns it off; otherwise 1s to 5m
STREAM_EARLY_COMMIT_AFTER30sHow long a streaming request on Chat Completions, Messages or Responses waits for the provider's response headers before Tokamak starts the stream itself (a 200 plus keep-alives; a later provider error is sent as an error event). Keep it under the shortest idle timeout in front of core. 0 turns it off, and so does STREAM_KEEPALIVE_INTERVAL=0; otherwise 10s to 90s
CORS_EXTRA_ORIGINS—Additional CORS origins (comma-separated)
ENABLE_SWAGGERtrueServe the Swagger UI
SERVICE_NAMEllm-apiService name in logs and traces
SERVICE_NAMESPACEtokamakNamespace for OpenTelemetry
ENVIRONMENTdevelopmentdevelopment or production
TOKAMAK_RUN_MODE—Overrides the compiled run mode

Inference admission

VariableDefaultDescription
INFERENCE_TRAFFIC_POLICYbuilt-in limitsJSON admission limits per scope (organization, user, team, key, provider, account), each {"concurrent","rpm","tpm"} with 0 meaning not enforced; overrides keyed by scope (organization:42, provider:lab-shared); enforce.disable_cooldown, disable_concurrency and disable_rate stop one kind of refusal without stopping its accounting. Editable live under Traffic limits in the platform console
INFERENCE_COOLDOWN_MAX60sLongest one upstream 429 can park a model (or a pooled or organization account) for every caller; 1s to 15m, editable live
INFERENCE_DIALECT_REFUSALS—Comma list of chat, messages, responses or all: those routes write credit, budget and traffic refusals as their own dialect's error object (see Error codes). Read at startup; an unknown name fails startup

Database

VariableDefaultRequiredDescription
DB_POSTGRESQL_WRITE_DSN—YesPostgreSQL write connection string
DB_POSTGRESQL_READ1_DSN—Read replica (falls back to the write DSN)
TOKAMAK_CORE_DB_SCHEMAllm_apiSchema the core service owns
AUTO_MIGRATEtrueRun core migrations on startup

Redis

Redis is optional. Core uses it only to share Claude Pool credential affinity across replicas; without REDIS_URL, or when Redis does not answer within 25 ms, each replica keeps its own.

VariableDefaultDescription
REDIS_URL—Comma-separated host:port list — not a redis:// URL
REDIS_MODEsinglesingle, sentinel, or cluster
REDIS_PASSWORD—Password
REDIS_DB0Database index
REDIS_SENTINEL_MASTER_NAME—Required when REDIS_MODE=sentinel
REDIS_SENTINEL_PASSWORD—Sentinel password
REDIS_POOL_SIZE10Connection pool size
REDIS_MIN_IDLE_CONNS2Minimum idle connections

Service wiring and authorization

VariableDefaultDescription
TOKAMAK_AUTH_URLhttp://tokamak-auth:8092Where core reaches the auth service
TOKAMAK_AUTH_SERVICE_TOKENsvc_tokamak_auth_service_token_devService token for core → auth calls. Change this in production.
TOKAMAK_DELEGATION_JWKS_URL—The gateway's JWKS endpoint, used to verify delegation tokens
TOKAMAK_DELEGATION_AUDIENCEtokamak-coreExpected audience on delegation tokens
RBAC_CENTRAL_ENABLEDtrueUse the centralized RBAC engine
SYSTEM_ADMIN_EMAIL—Comma-separated platform-owner emails
ADMIN_IMPERSONATION_ENABLEDtrueAllow admin impersonation

Core refuses to start if JWT_SIGNING_SECRET or KEYCLOAK_BASE_URL is set, since token validation belongs to the auth service. Set them on auth instead.

API keys

VariableDefaultDescription
APIKEY_SECRET—Encryption key for stored API keys
API_KEY_DEFAULT_TTL2160hDefault API key lifetime (90 days)
API_KEY_MAX_TTL2160hMaximum API key lifetime
API_KEY_MAX_PER_USER100Maximum keys per user
API_KEY_PREFIXsk_livePrefix on issued keys

Providers and model catalog

VariableDefaultDescription
MODEL_SYNC_ENABLEDtruePeriodically sync provider model lists
MODEL_SYNC_INTERVAL_MINUTES60Sync interval
MODEL_PROVIDER_SECRETjan-model-provider-secret-2024Encryption secret for stored provider credentials. Change this in production.
ANTHROPIC_PROXY_BASE_URLhttps://api.anthropic.com/v1Upstream base URL for the Anthropic dialect
REMOTE_LLM_ENABLEDfalseRegister a provider from environment variables at boot
REMOTE_LLM_PROVIDER_URL—Base URL for that provider
REMOTE_API_KEY—Credential for that provider

Organization provider keys (bring your own key)

VariableDefaultDescription
TOKAMAK_CLAUDE_POOL_TOKEN_ENCRYPTION_KEY—Encrypts organizations' provider keys, as it does Claude Pool tokens; _KEY_ID, _KEY_PREVIOUS and _KEY_ID_PREVIOUS rotate it. Without it, no provider key can be saved or used. The Claude Pool switch does not need to be on.
TOKAMAK_BYOK_ALLOW_ENDPOINT_OVERRIDEfalseDevelopment and tests only. Lets the next variable send organization keys somewhere other than the provider's official API
TOKAMAK_BYOK_ENDPOINT_OVERRIDES—Development and tests only, for example anthropic=http://byokstub:9877/v1,openai=http://byokstub:9877/v1. Ignored unless the previous variable is true

See Bring your own key (platform).

Guardrails

VariableDefaultDescription
TOKAMAK_GUARDRAILS_CLOAK_SECRET—Sensitive. Derives cloak stand-ins (HMAC over the secret, the organization and its cloak key version). Keep it stable: changing it changes every stand-in. Empty means cloak rules mask instead.

See Guardrails (platform).

Media storage

VariableDefaultDescription
MEDIA_STORAGE_BACKENDs3s3 or local
MEDIA_S3_ENDPOINThttps://s3.menlo.aiS3-compatible endpoint
MEDIA_S3_PUBLIC_ENDPOINT—Public-facing S3 endpoint
MEDIA_S3_URL_ENABLEDfalseServe S3 URLs directly
MEDIA_S3_REGIONus-west-2S3 region
MEDIA_S3_BUCKET—Bucket name
MEDIA_S3_ACCESS_KEY_ID—Access key
MEDIA_S3_SECRET_ACCESS_KEY—Secret key
MEDIA_S3_USE_PATH_STYLEtrueUse path-style URLs
MEDIA_S3_PRESIGN_TTL168hPresigned URL lifetime
MEDIA_LOCAL_STORAGE_PATH—Filesystem path when the backend is local
MEDIA_LOCAL_STORAGE_BASE_URL—Base URL for locally stored media
MEDIA_MAX_BYTES52428800Maximum file size (50 MB)
MEDIA_PUBLIC_URLhttp://localhost:8080Public base URL for media
MEDIA_PROXY_DOWNLOADtrueProxy downloads through the API
MEDIA_RETENTION_DAYS30Days before media is deleted
RESPONSE_ROUTE_RETENTION_DAYS30Days a /v1/responses id is remembered for retrieve/delete/cancel routing; older rows are pruned daily
MEDIA_REMOTE_FETCH_TIMEOUT15sTimeout when ingesting media by URL

Request archives

VariableDefaultDescription
ARCHIVE_ENABLEDfalseArchive request/response payloads to S3
ARCHIVE_S3_BUCKET—Bucket name
ARCHIVE_S3_REGIONus-west-2Region
ARCHIVE_S3_ENDPOINT—S3-compatible endpoint
ARCHIVE_S3_ACCESS_KEY_ID—Access key
ARCHIVE_S3_SECRET_ACCESS_KEY—Secret key
ARCHIVE_S3_USE_PATH_STYLEfalseUse path-style URLs
ARCHIVE_S3_KEY_PREFIXarchivesKey prefix
ARCHIVE_COMPRESSIONtrueCompress archived payloads
ARCHIVE_BUFFER_SIZE100Write buffer size
ARCHIVE_WORKERS4Archive worker count
ARCHIVE_RETENTION_DAYS365Retention window
ARCHIVE_PRESIGN_TTL1hPresigned URL lifetime

Invitation email and billing

See Invitation email delivery for the auth SMTP variables and Billing and payment setup for database, provider, receipt and return-URL settings. The complete operator billing reference is tokamak-services/docs/reference/env.md in the repository. A configured payment provider and an organization activated for credit enforcement are separate states.

Logging and observability

Shared logging variables are used across services; exporter and profiling support depends on the service. Inspect its executable configuration before enabling a collector.

VariableDefaultDescription
LOG_LEVELinfodebug / info / warn / error
LOG_FORMATconsoleconsole or json
OTEL_ENABLEDfalseEnable OTLP export and DB/Redis instrumentation
OTEL_SERVICE_NAMEper serviceService name reported in traces
OTEL_EXPORTER_OTLP_ENDPOINT—OTLP collector endpoint
OTEL_EXPORTER_OTLP_HEADERS—Additional OTLP headers
OTEL_TRACES_SAMPLER_ARG1.0Trace sample ratio
PYROSCOPE_ENABLEDfalseEnable continuous profiling
PYROSCOPE_SERVER_ADDRESS—Pyroscope server address
PPROF_ENABLEDfalseExpose Go pprof endpoints
PPROF_ADDR—Address for the pprof listener

On this page