Reference for the environment variables that configure the gateway, core, auth and billing services
Tokamak is configured entirely through environment variables. In the shipped Docker Compose stack they live in a single .env file that the services consume through their Compose configuration.
Defaults below are the values compiled into each service. Deployment templates override some of them — where that matters it is called out.
The core service's configuration struct still declares variables for features that were removed from the product (project management, Slack, the GitHub bot, sandboxes, knowledge and memory, and the MCP tools engine). Setting them has no effect — the code paths they configured are gone. The executable service configuration remains authoritative; legacy fields do not establish a working feature.
Core service port. The shipped deployment templates set this to 8090, which is what gateway and auth expect by default.
METRICS_PORT
9091
Prometheus metrics port
STREAM_TIMEOUT
3600s
Longest one upstream exchange may last, streaming or not
STREAM_IDLE_TIMEOUT
300s
End an upstream exchange after this long with nothing from the upstream: no response headers, then no body bytes. A non-streaming answer is bounded by it too. 0 turns the check off; otherwise 30s to 1h
STREAM_KEEPALIVE_INTERVAL
15s
Write an SSE : keep-alive comment when a stream has been silent this long, so proxies in front keep the connection open. 0 turns it off; otherwise 1s to 5m
STREAM_EARLY_COMMIT_AFTER
30s
How long a streaming request on Chat Completions, Messages or Responses waits for the provider's response headers before Tokamak starts the stream itself (a 200 plus keep-alives; a later provider error is sent as an error event). Keep it under the shortest idle timeout in front of core. 0 turns it off, and so does STREAM_KEEPALIVE_INTERVAL=0; otherwise 10s to 90s
JSON admission limits per scope (organization, user, team, key, provider, account), each {"concurrent","rpm","tpm"} with 0 meaning not enforced; overrides keyed by scope (organization:42, provider:lab-shared); enforce.disable_cooldown, disable_concurrency and disable_rate stop one kind of refusal without stopping its accounting. Editable live under Traffic limits in the platform console
INFERENCE_COOLDOWN_MAX
60s
Longest one upstream 429 can park a model (or a pooled or organization account) for every caller; 1s to 15m, editable live
INFERENCE_DIALECT_REFUSALS
—
Comma list of chat, messages, responses or all: those routes write credit, budget and traffic refusals as their own dialect's error object (see Error codes). Read at startup; an unknown name fails startup
Redis is optional. Core uses it only to share Claude Pool credential affinity across replicas; without REDIS_URL, or when Redis does not answer within 25 ms, each replica keeps its own.
Variable
Default
Description
REDIS_URL
—
Comma-separated host:port list — not a redis:// URL
Encrypts organizations' provider keys, as it does Claude Pool tokens; _KEY_ID, _KEY_PREVIOUS and _KEY_ID_PREVIOUS rotate it. Without it, no provider key can be saved or used. The Claude Pool switch does not need to be on.
TOKAMAK_BYOK_ALLOW_ENDPOINT_OVERRIDE
false
Development and tests only. Lets the next variable send organization keys somewhere other than the provider's official API
TOKAMAK_BYOK_ENDPOINT_OVERRIDES
—
Development and tests only, for example anthropic=http://byokstub:9877/v1,openai=http://byokstub:9877/v1. Ignored unless the previous variable is true
Sensitive. Derives cloak stand-ins (HMAC over the secret, the organization and its cloak key version). Keep it stable: changing it changes every stand-in. Empty means cloak rules mask instead.
See Invitation email delivery for the auth SMTP variables and Billing and payment setup for database, provider, receipt and return-URL settings. The complete operator billing reference is tokamak-services/docs/reference/env.md in the repository. A configured payment provider and an organization activated for credit enforcement are separate states.
Shared logging variables are used across services; exporter and profiling support depends on the service. Inspect its executable configuration before enabling a collector.