|
| 1 | +DATABASE_URL=postgres://openbot:openbot@localhost:5432/openbot |
| 2 | +# Credential vault encryption key. The example value is public and only suitable for local |
| 3 | +# development. Production refuses to start with this key. |
| 4 | +# openssl rand -base64 32 |
| 5 | +KEY_ENCRYPTION_KEY=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA= |
| 6 | +PORT=3001 |
| 7 | +TENANT_PACKAGE_DIR=../examples/fintech |
| 8 | +# What this deployment calls itself, when more than one shares an Intelligence project. A copy of a |
| 9 | +# deployment made for development uses the same project key, and threads are listed per Bot with |
| 10 | +# nothing to say which deployment a conversation came from. The name goes into every thread id this |
| 11 | +# deployment mints, so its own conversations stay identifiable. Unset, the tenant package's id is |
| 12 | +# used, which tells two packages apart but not two copies of one. |
| 13 | +# DEPLOYMENT_ID= |
| 14 | +# Google sign-in. Leave commented for local development with OPENBOT_DEV_NO_AUTH; uncomment all five |
| 15 | +# settings together so authentication is either fully configured or absent. |
| 16 | +# |
| 17 | +# BETTER_AUTH_SECRET must be a high-entropy secret of at least 32 characters. Generate one: |
| 18 | +# openssl rand -base64 32 |
| 19 | +# TRUSTED_ORIGINS is where the app is served from, which is port 3010 locally. |
| 20 | +# BETTER_AUTH_URL=http://localhost:3001 |
| 21 | +# BETTER_AUTH_SECRET= |
| 22 | +# GOOGLE_OAUTH_CLIENT_ID= |
| 23 | +# GOOGLE_OAUTH_CLIENT_SECRET= |
| 24 | +# INITIAL_ADMIN_EMAILS=admin@example.com |
| 25 | + |
| 26 | +# Local development only. This admits every request as one local administrator. Keep it explicit and |
| 27 | +# never expose a deployment to the internet in this state; production refuses to start with it. |
| 28 | +OPENBOT_DEV_NO_AUTH=true |
| 29 | +TRUSTED_ORIGINS=http://localhost:3010 |
| 30 | + |
| 31 | +# CopilotKit Intelligence. Required: the server refuses to start without all four because |
| 32 | +# Intelligence owns durable threads and memory and a deployment without it forgets every |
| 33 | +# conversation. There is no degraded mode. |
| 34 | +# |
| 35 | +# Do not run Intelligence yourself. These two point at the managed service and should be left |
| 36 | +# unchanged; the CLI below provisions a free licence for it. Running Intelligence on your own |
| 37 | +# infrastructure is an Enterprise Intelligence Platform feature deployed by Helm chart, and is not |
| 38 | +# self-serve: https://docs.showcase.copilotkit.ai/premium/self-hosting |
| 39 | +INTELLIGENCE_API_URL=https://api.intelligence.copilotkit.ai |
| 40 | +INTELLIGENCE_GATEWAY_WS_URL=wss://realtime.intelligence.copilotkit.ai |
| 41 | +# |
| 42 | +# Get both of the next two from the CopilotKit CLI: |
| 43 | +# |
| 44 | +# npx --yes copilotkit@latest login # browser sign-in |
| 45 | +# npx --yes copilotkit@latest project select # prints the cpk-... runtime key -> INTELLIGENCE_API_KEY |
| 46 | +# npx --yes copilotkit@latest license --write # writes COPILOTKIT_LICENSE_TOKEN into this file |
| 47 | +# |
| 48 | +# The runtime key is also under "API Keys" in your project at https://intelligence.copilotkit.ai |
| 49 | +INTELLIGENCE_API_KEY= |
| 50 | +COPILOTKIT_LICENSE_TOKEN= |
| 51 | + |
| 52 | +# Model key. Required by the proof-of-concept Bot, which speaks OpenAI's API directly, and by the |
| 53 | +# framework Bot unless you point it at another provider below. |
| 54 | +OPENAI_API_KEY= |
| 55 | + |
| 56 | +# Framework Bot provider: openai, anthropic or google. It reads that provider's own |
| 57 | +# key and refuses to start without it, so a deployment on Anthropic never needs an OpenAI key for it. |
| 58 | +# The proof-of-concept Bot is OpenAI only by construction: it speaks that API directly. |
| 59 | +# BOT_PROVIDER=openai |
| 60 | +# ANTHROPIC_API_KEY= |
| 61 | +# GOOGLE_API_KEY= |
| 62 | + |
| 63 | +# Which model. Defaults per provider: gpt-5.5, claude-sonnet-4-5, gemini-2.5-flash. |
| 64 | +# BOT_MODEL=gpt-5.5 |
| 65 | + |
| 66 | +# OpenAI only. Its newer models require the Responses API, which the framework Bot handles and the |
| 67 | +# proof-of-concept one cannot. |
| 68 | +# BOT_RESPONSES_API=false |
| 69 | + |
| 70 | +# The Bot computer. Absent means the feature is off and its routes are not mounted. |
| 71 | +AGENT_COMPUTER_URL=http://localhost:4100 |
| 72 | +# Secret every computer requires from its caller. `agent-computer` drives a browser holding real |
| 73 | +# logins, while policy, audit and sign-in live in the API server. The computer refuses to start |
| 74 | +# without this value and refuses every request that does not present it. Use a long random value; |
| 75 | +# `scripts/start.sh` sets a development one for you. |
| 76 | +COMPUTER_TOKEN= |
| 77 | +# Local only. Lets a Bot browse this machine's own services; never set this in a deployment. |
| 78 | +AGENT_COMPUTER_ALLOW_PRIVATE_HOSTS=true |
| 79 | +# |
| 80 | +# What a Bot may do on its computer, as one JSON object. Absent uses the built-in default, which |
| 81 | +# permits the acting tools and forbids nothing, and records every action either way. |
| 82 | +# |
| 83 | +# `deny` is evaluated first and beats `allow`. An empty `allow` permits nothing, a missing policy |
| 84 | +# permits nothing, and a rule that fails to parse denies rather than letting the action through. The |
| 85 | +# server refuses to start if this is set and malformed, so an invalid restriction never falls back to |
| 86 | +# permissive behavior. |
| 87 | +# |
| 88 | +# Workspace and browser profile per Bot. Each Bot's computer is its own container with its own |
| 89 | +# volumes, so one Bot cannot read another's files or use another's logins, and every action records |
| 90 | +# which Bot took it. A rule can still restrict a single Bot with `bot.id`. |
| 91 | +# |
| 92 | +# Attributes: tool.name, bot.id, actor.id, page.url, page.host, element.ref/role/name/type, |
| 93 | +# key, file.path, file.name, file.extension. |
| 94 | +# |
| 95 | +# Name every route to the same effect. A form submits from a keypress in any of its fields, so a rule |
| 96 | +# that only blocks a Submit button does not block Enter from another field. The example below refuses |
| 97 | +# Enter outright for that reason. |
| 98 | +# Functions: contains(haystack, needle) and matches(value, pattern), both case-insensitive. |
| 99 | +# `enforce` blocks; `dry-run` decides and records but lets everything through, so a new rule can be |
| 100 | +# tried against real traffic before it starts refusing anybody's work. |
| 101 | +# |
| 102 | +# AGENT_COMPUTER_POLICY={"mode":"enforce","deny":["(intent == \"activate\" && contains(element.name, \"submit\")) || (tool.name == \"computer_key\" && key == \"Enter\")"],"allow":["true"]} |
| 103 | + |
| 104 | +# How long one action waits for its element, in ms. Read by agent-computer, not the server. |
| 105 | +# ACTION_TIMEOUT_MS=10000 |
| 106 | + |
| 107 | +# --------------------------------------------------------------------------- |
| 108 | +# The computer's profile and where its traffic leaves from |
| 109 | +# --------------------------------------------------------------------------- |
| 110 | + |
| 111 | +# Chromium profile directory inside agent-computer, mounted from the `agent-profiles` volume in |
| 112 | +# docker-compose.yml. Pointing it somewhere unmounted disables login persistence. |
| 113 | +# PROFILES_DIR=/profiles |
| 114 | + |
| 115 | +# Which Bot this computer belongs to, and therefore which profile directory it uses. |
| 116 | +# COMPUTER_BOT_ID=shared |
| 117 | + |
| 118 | +# Per-Bot egress identity. A proxy the Bot's browser sends everything through, so the far side sees a |
| 119 | +# stable address it can allow-list or attribute to that Bot. `EGRESS_PROXY_<BOT>` names one Bot, |
| 120 | +# `EGRESS_PROXY_DEFAULT` covers the rest, and absent means the browser goes out directly. |
| 121 | +# |
| 122 | +# Credentials may be in the URL and are split out before Playwright sees them. Only the HOST is ever |
| 123 | +# reported back on the admin page or the API, so the password does not end up on a screen. |
| 124 | +# |
| 125 | +# This is attribution, not anonymity, and it is not a boundary by itself: it gives a security team a |
| 126 | +# per-Bot address for network rules alongside AGENT_COMPUTER_POLICY. |
| 127 | +# EGRESS_PROXY_DEFAULT=http://user:password@proxy.internal:8080 |
| 128 | +# EGRESS_PROXY_SALES_BOT=http://sales.proxy.internal:8080 |
| 129 | + |
| 130 | + |
| 131 | +# The managed teammate AG-UI endpoint. Required: use an HTTP(S) URL. |
| 132 | +MANAGED_AGENT_AG_UI_URL=http://localhost:4200/ag-ui |
| 133 | + |
| 134 | +# The second Bot in the box runs on http://localhost:4201/ag-ui, on a framework rather than |
| 135 | +# proof of concept, and is reached the same way: point MANAGED_AGENT_AG_UI_URL at it, or add it as a |
| 136 | +# Bot of its own in the tenant package or at /agents. |
| 137 | + |
| 138 | +# Which model the Bots use. agent-bot speaks /v1/chat/completions and cannot use gpt-5.6-*, which |
| 139 | +# require the Responses API. agent-langgraph can: set BOT_RESPONSES_API=true and give it a 5.6 model. |
| 140 | +# BOT_RESPONSES_API=false |
| 141 | + |
| 142 | +# One computer per Bot. Unset, every Bot shares the computer at AGENT_COMPUTER_URL, suitable on a |
| 143 | +# laptop and explicit about being one shared machine. Set, the supervisor gives each Bot a container |
| 144 | +# of its own, with its own /workspace and its own browser profile. |
| 145 | +COMPUTER_SUPERVISOR_URL= |
| 146 | +# Shared with the supervisor. Not the security boundary, its four verbs are, but it keeps anything |
| 147 | +# else that can reach the port from cycling a Bot's computer. |
| 148 | +SUPERVISOR_TOKEN= |
| 149 | +# Set to runsc to run every computer under gVisor, if the host has it. Unset, a computer is an |
| 150 | +# ordinary container and shares the host kernel, which is worth knowing when the Bot is not ours. |
| 151 | +COMPUTER_RUNTIME= |
0 commit comments