Version 1.0.0
Gateway environment variables
Every variable the gateway reads: whether it is required, its default, the profile it applies to, and its effect.
Internal, subject to change without notice. This page covers the operation of a deployment, not the contract the gateway offers to third-party programs. The vendor makes no commitment here: these names can change from one version to the next, with no deprecation step. A change then shows up at startup or on update, in a message that names what is missing.
The part the vendor does commit to is the relay.
Every variable the gateway reads is listed here. A variable absent from this page is read by none of its modules.
No value is published, not even as an example. The “Secret” column says which ones carry a secret; their value lives in the deployment’s secret manager, never in documentation or in a file in the repository.
The “Profile” column distinguishes the two ways the product is shipped: the deployment the customer hosts themselves, and the one the vendor operates. See Deployment profiles.
Every variable
Section titled “Every variable”| Name | Required | Default | Secret | Profile | Effect |
|---|---|---|---|---|---|
DATABASE_URL | yes | none | yes | both | The PostgreSQL database the gateway queries. Without it, the gateway refuses to start rather than assume a local database: an assumption would hide a missing configuration. The sslmode parameter is rejected there: certificate validation is set by the code, not by the URL. |
DATABASE_CA_CERT_PATH | no | none | no | both | Path to the certificate authority to present in order to validate the database certificate. Without it, validation stays active and relies on the system authorities. An unreadable path stops startup. Cannot be set at the same time as DATABASE_CA_CERT. |
DATABASE_CA_CERT | no | none | no | both | The PEM contents of that same authority, for platforms that can only pass environment variables and offer no disk on which to mount a file. Same effect as DATABASE_CA_CERT_PATH, of which it is the second entry rather than a second mechanism: a value that carries no certificate stops startup, and so does setting both variables together, because nothing would say which one prevails. An authority’s certificate is public: it is not a secret. |
DATABASE_TLS_SERVER_NAME | no | none | no | vendor-operated | The name the database certificate is checked against when DATABASE_URL reaches the database by IP address, typically a private network address, while the certificate carries a DNS name. The check remains complete: only the name compared changes. A value that is an IP address, that does not have the shape of a hostname, or that is set while DATABASE_URL already names the database by name stops startup. Hosted offering only: an on-premise artifact refuses to start if it is set. |
PORT | no | 6001 | no | both | The listening port. A value that is not a number falls back to the default. |
TLS_CERT_FILE | no | none | no | both | Path to the service certificate. Set together with the key, the gateway terminates transport encryption itself; without both, it serves in the clear and announces this at startup. Only one of the two stops startup: no incomplete configuration falls back to the clear. |
TLS_KEY_FILE | no | none | yes | both | Path to the service certificate’s private key. Always goes with TLS_CERT_FILE. |
UPSTREAM_TLS_CLIENT_CERT_FILE | no | none | no | both | Path to the client certificate the gateway presents to the inference engine when that engine is reached over https. Without it, outbound traffic goes out with no client certificate. |
UPSTREAM_TLS_CLIENT_KEY_FILE | no | none | yes | both | Path to the outbound client certificate’s private key. Always goes with the certificate. |
UPSTREAM_TLS_CA_FILE | no | none | no | both | Path to the certificate authority that validates the inference engine’s certificate. Useful when the engine carries a certificate issued by an internal authority. |
HTTPS_PROXY | no | none | no | both | The corporate proxy through which the gateway goes out over https. Declared as a full URL; a bare host and port are rejected at startup. Failing that, HTTP_PROXY also applies to https targets, as the Unix convention dictates. |
HTTP_PROXY | no | none | no | both | The corporate proxy through which the gateway goes out over http, and the fallback for https targets when HTTPS_PROXY is not set. A URL whose protocol is neither http nor https stops startup. |
NO_PROXY | no | none | no | both | The host patterns reached without going through the proxy, separated by commas. This is how an inference engine hosted on the internal network bypasses the corporate proxy. |
NODE_EXTRA_CA_CERTS | no | none | no | both | Path to the internal authority store, the one required by a corporate proxy that decrypts traffic. Read at startup so that an unreadable file is a refusal to start: Node, for its part, settles for a warning and starts anyway. |
REQUEST_TIMEOUT_SECONDS | no | 1800 | no | both | The number of seconds after which the transport cuts off an in-flight request. It is a safety net set well beyond the maximum duration of an agent command: a value that would drop back below that duration stops startup. |
OIDC_ISSUER | no | none | no | customer deployment | The corporate directory issuer to which the gateway delegates authentication: an absolute https URL, with no query or fragment. Without it and without OIDC_CLIENT_ID, a gateway in a customer deployment authenticates no one and rejects every request. |
OIDC_CLIENT_ID | no | none | no | customer deployment | The gateway’s OAuth 2 client identifier with the directory. A half-set configuration (one of the two without the other) rejects everything and says so in the operator log. |
OIDC_CLIENT_SECRET | no | none | yes | customer deployment | The client secret, to be set only if the directory requires a confidential client. Where PKCE is enough, not holding one is preferable. |
OIDC_AUDIENCE | no | la valeur d'OIDC_CLIENT_ID | no | customer deployment | The audience expected in the token presented. |
OIDC_REDIRECT_URI | no | none | no | customer deployment | The authorization flow’s return address, when a sign-in flow is served. |
ADMIN_API_KEY | yes | none | yes | vendor-operated | The key for the administration account bootstrapped at startup. Specific to the vendor-operated profile: in a customer deployment, identities come from the directory and this variable does not exist in the shipped artifact. |
LEMNISCATE_LICENSE | no | none | yes | customer deployment | The deployment license itself, in base64. It carries the customer name, the expiry date, the seat count and the licensed capabilities, all signed: the gateway verifies its signature at startup. It takes precedence over LEMNISCATE_LICENSE_FILE when both are set. Absent, the gateway starts and says so in the operator log: no request is then measured against seats or capabilities, the gateway’s own commercial control being a separate mechanism, still to be built. Set but invalid, it stops startup and names the cause: nobody sets a license by accident. Specific to customer deployments: the vendor-operated profile knows no license, its commercial limits going through billing. |
LEMNISCATE_LICENSE_FILE | no | none | no | customer deployment | The path to a file containing that same license, for operators who mount a secret on disk rather than set it in the environment. Same effect as LEMNISCATE_LICENSE, of which it is the second entry rather than a second mechanism. An unreadable path stops startup and names the file, rather than acting as if no license had been supplied. |
LEMNISCATE_AGENT_EXECUTION_LAUNCHER | no | none | no | both | The agent command launcher the gateway offers. This version offers none: nothing written is the default and the only accepted value, and any value (including direct, removed on 2026-08-06) stops startup and says why. Agent commands run in the per-session container, never in the gateway: the gateway holds the inference provider keys and the database access, and its hardening profile grants it write access nowhere. |
PATH | no | none | no | both | Copied as-is to the processes the agent launcher starts. The list of variables passed through is an allowlist and is closed: anything not on it does not cross the boundary. |
LANG | no | none | no | both | Copied as-is to the processes the agent launcher starts. |
LC_ALL | no | none | no | both | Copied as-is to the processes the agent launcher starts. |
TZ | no | none | no | both | Copied as-is to the processes the agent launcher starts. |
LEMNISCATE_DOCS_DIR | no | none | no | both | The directory where the documentation archive shipped with the server was unpacked. Nothing written means: no documentation served, which is the default. When set, the gateway reads lemniscate.json at the root of that directory and serves the tree under the base that file declares: an archive is only usable under the path it was built for. A missing directory, an incomplete archive or an archive frozen for another path stop startup rather than becoming “no documentation”. |
CONTROL_PLANE_ORGANIZATION | yes | none | no | both | The organization whose policy this gateway serves to workstations. Without it, the gateway refuses to start rather than assume an organization: an assumption would make it answer “nothing is restricted” to an entire fleet, with nothing appearing broken. The expected name is the one recorded in the database, the one the workstation receives as orgSlug. |
Spellings also accepted
Section titled “Spellings also accepted”The Unix convention has it that the same setting can be set in uppercase or lowercase. The gateway reads both, and keeps the first one declared in this order.
| Name | Also read as |
|---|---|
HTTPS_PROXY | https_proxy |
HTTP_PROXY | http_proxy |
NO_PROXY | no_proxy |
A variable whose name is not written in the product
Section titled “A variable whose name is not written in the product”the provider key: The name of this variable is not written in the code: the operator chooses it, by declaring their provider in the administration console. The gateway reads the variable so named in order to inject the provider key into the outbound request. Absent, it returns a 500 rejection that names the expected variable.
What this page does not cover
Section titled “What this page does not cover”The variables the gateway copies to the agent processes it launches are in the table above, along with their effect. The list is an allowlist and is closed: anything not on it does not cross that boundary.
The administration console’s variables are another set, documented with it. Both
components read the same database, which does not mean they share the same configuration: for
example, the gateway refuses to start without DATABASE_URL where the console falls back to
a local development database.