Environment Variables

“Required” is contextual: startup validation requires Slack/model/default GitHub values plus credentials for the selected runtime and GitHub mode. Integration-specific values are required only when that integration is used. Never put real credentials in documentation.

Name Default Requirement Purpose Sensitivity Area

SLACK_BOT_TOKEN

empty

Runtime required

Slack Web API credential

Secret

Slack

SLACK_SIGNING_SECRET

empty

Required in HTTP mode

HTTP request verification

Secret

Slack

SLACK_APP_TOKEN

empty

Required in Socket Mode

Socket authentication

Secret

Slack

SLACK_ALLOW_UNSIGNED_REQUESTS

false

Optional

Development-only signature bypass

Sensitive control

Slack

OPENAI_API_KEY

empty

Required when Galileo key absent

Direct/fallback model credential

Secret

Model

OPENAI_MODEL

configured Roche model name

Optional

Model identifier

No

Model

GALILEO_ENABLED

false in code; true in example/Helm

Optional

Select gateway routing

No

Model

GALILEO_API_KEY

empty

Required for gateway unless OpenAI key used

Gateway credential

Secret

Model

GALILEO_GATEWAY_URL

Roche US gateway shown in example

Optional

OpenAI-compatible gateway URL

Internal endpoint

Model

PORTKEY_APPLICATION_NAME

slack-kb-agent

Optional

Portkey metadata application

No

Model

GITHUB_TOKEN

empty

Legacy/optional

Pipeline token when no authorization service credential is supplied

Secret

GitHub

GITHUB_AUTH_MODE

installation

Optional

installation, delegated, or hybrid

No

GitHub

GITHUB_HYBRID_INSTALLATION_FALLBACK

true

Hybrid only

Allow installation fallback

Sensitive control

GitHub

GITHUB_APP_ID

empty

Installation/hybrid required

GitHub App identity

Sensitive

GitHub

GITHUB_APP_CLIENT_ID

empty

Delegated/hybrid required

OAuth client identity

Sensitive

GitHub

GITHUB_APP_CLIENT_SECRET

empty

Delegated/hybrid required

OAuth exchange credential

Secret

GitHub

GITHUB_APP_PRIVATE_KEY

empty

Installation/hybrid required

Signs App JWTs

Secret

GitHub

GITHUB_APP_INSTALLATION_ID

empty

Installation/hybrid required

Installation selection

Sensitive

GitHub

GITHUB_OAUTH_CALLBACK_URL

empty

Delegated/hybrid required

OAuth callback URL

Internal URL

GitHub

TOKEN_ENCRYPTION_KEY

empty

Delegated/hybrid and Confluence storage required

Encrypt stored tokens

Secret

GitHub/Confluence

OAUTH_STATE_TTL_SECONDS

600

Optional

OAuth state lifetime

No

GitHub

AUTHORIZATION_DATABASE_PATH

empty

Optional

SQLite authorizations/state; empty is memory

Filesystem path

Persistence

DRAFT_DATABASE_PATH

empty

Optional

SQLite drafts; empty is memory

Filesystem path

Persistence

DEFAULT_KB_GITHUB_OWNER

empty

Runtime required

Default target owner

No

GitHub

DEFAULT_KB_GITHUB_REPO

empty

Runtime required

Default target repository

No

GitHub

DEFAULT_KB_BASE_BRANCH

main

Optional

PR base branch

No

GitHub

DEFAULT_KB_DOCS_PATH

docs/pages

Optional

Target content root

No

GitHub

DEFAULT_KB_SUBDIR

generated

Optional

Generated-content subdirectory

No

GitHub

KB_ALLOWED_REPOS

empty (deny all)

Operationally required

Comma-separated exact or owner wildcard targets

Authorization control

GitHub

KB_FILE_EXTENSION

mdx

Optional

md or mdx

No

GitHub

MAX_THREAD_LINKS

5

Optional

Parser link limit

No

Runtime

DRAFT_TTL_SECONDS

86400

Optional

Draft expiry timestamp

No

Persistence

PORT

3000

Optional

HTTP listen port

No

Runtime

JIRA_BASE_URL

empty

Jira required

Jira site root

Internal URL

Jira

JIRA_EMAIL

empty

Required for basic auth

Jira account identity

Personal/sensitive

Jira

JIRA_API_TOKEN

empty

Jira required

Jira credential

Secret

Jira

JIRA_DEFAULT_PROJECT_KEY

empty

Required unless flag supplied

Default project

No

Jira

JIRA_DEFAULT_ISSUE_TYPE

Task

Optional

Default issue type

No

Jira

JIRA_CREATE_BY_DEFAULT

false

Optional

Create Jira unless command overrides

No

Jira

JIRA_AUTH_TYPE

basic

Optional

basic or bearer

No

Jira

JIRA_API_VERSION

3

Optional

2 or 3

No

Jira

JIRA_DESCRIPTION_FORMAT

adf

Optional

adf or text

No

Jira

JIRA_VERIFY_SSL

true

Optional

TLS certificate verification

Security control

Jira

JIRA_CLOUDFLARE_ACCESS_CLIENT_ID

empty

Optional pair

Access service identity

Sensitive

Jira

JIRA_CLOUDFLARE_ACCESS_CLIENT_SECRET

empty

Optional pair

Access service credential

Secret

Jira

CONFLUENCE_MCP_URL

empty

Confluence required

MCP endpoint

Internal URL

Confluence

MULESOFT_CLIENT_ID

empty

Confluence required

Gateway identity

Sensitive

Confluence

MULESOFT_CLIENT_SECRET

empty

Confluence required

Gateway credential

Secret

Confluence

CONFLUENCE_MCP_TOOL

create_page

Optional

MCP tool name

No

Confluence

CONFLUENCE_SPACE_KEY

empty

Required unless command flag

Default space

No

Confluence

CONFLUENCE_PARENT_PAGE_ID

empty

Optional

Default parent page

No

Confluence

CONFLUENCE_TOKEN_DIRECTORY

/tmp/knowledge-assistant/confluence

Optional

Encrypted per-user PAT files

Sensitive path

Confluence

.env.example also lists MAX_THREAD_MESSAGES, but the Python Settings model does not define or use it. It currently has no application effect.