• English
  • Octop Environment Variables: Complete Config Reference

    Every setting in config.json has a matching environment variable. When you set one, it takes priority over the value in the file — the file itself is never modified. This makes environment variables the preferred approach for Docker deployments, CI pipelines, and any situation where you want to keep secrets out of the filesystem.

    Variable reference

    VariableTypeDefaultDescription
    OCTOP_HOMEpath~/.octopInstallation root. All data — database, secrets, agent workspaces, plugins — is stored here.
    OCTOP_BIND_HOSTstring127.0.0.1Interface Octop listens on. Set to 0.0.0.0 for LAN or container access.
    OCTOP_PORTint8088TCP port Octop binds to.
    OCTOP_LOG_LEVELstringinfoLog verbosity: debug, info, warning, or error.
    OCTOP_LOG_RETENTION_DAYSint14Keep rotated octop.log.YYYY-MM-DD files for this many days.
    OCTOP_LOG_MAX_BYTESint104857600 (100 MiB)Roll the active log when it exceeds this size, in addition to daily rotation.
    OCTOP_LOG_COMPRESSbooltruelogrotate-style compress + delaycompress: gzip older rotated plains on the next cycle.
    OCTOP_ACCESS_TOKEN_TTLint (seconds)86400JWT access-token lifetime. Default is 24 hours.
    OCTOP_LOGIN_MAX_ATTEMPTSint5Failed login attempts before an account is locked out.
    OCTOP_LOGIN_LOCKOUT_SECONDSint900How long (seconds) a lockout lasts after too many failed attempts.
    OCTOP_CAPTCHA_PROVIDERslugsliderLogin captcha: slider, turnstile, hcaptcha, recaptcha-v3, or tencent. recaptcha (v2) still works if already stored, but is unlisted. Boot snapshot; restart after you change it.
    OCTOP_CAPTCHA_SITE_KEYstring(empty)Public site key (Tencent: CaptchaAppId). Required when the env snapshot is a strong provider.
    OCTOP_CAPTCHA_SECRETstring(empty)Siteverify secret (Tencent: AppSecretKey). Never logged; GET /api/envs redacts it.
    OCTOP_CAPTCHA_CAM_SECRET_IDstring(empty)Tencent only: CAM API SecretId for DescribeCaptchaResult. Required when the env snapshot is tencent.
    OCTOP_CAPTCHA_CAM_SECRET_KEYstring(empty)Tencent only: CAM API SecretKey. Never logged; GET /api/envs redacts it.
    OCTOP_CAPTCHA_V3_MIN_SCOREfloat0.5Minimum recaptcha-v3 score. The admin UI is read-only for this value.
    OCTOP_DEFAULT_TIMEZONEIANA tzAsia/ShanghaiTimezone for dashboard timestamps, cron scheduling, and the agent harness.
    OCTOP_CORS_ORIGINScomma-sep(empty)Comma-separated list of origins permitted to make cross-origin requests.
    OCTOP_ENABLE_DASHBOARDbooltrueServe the built-in React SPA at /.
    OCTOP_ENABLE_API_DOCSboolfalseExpose the interactive Scalar API docs at /api/docs.
    OCTOP_REQUIRE_SETUP_PASSWORDbooltrueRequire a password gate during the first-run setup wizard. Set to false for unattended bootstraps using OCTOP_ADMIN_USERNAME / OCTOP_ADMIN_PASSWORD.
    OCTOP_DATABASE_URLstring(empty)Full PostgreSQL DSN (e.g. postgresql://user:pass@host:5432/octop). Overrides all individual OCTOP_DATABASE_* fields below.
    OCTOP_DATABASE_DRIVERstringsqliteStorage backend: sqlite or postgresql.
    OCTOP_DATABASE_SQLITE_PATHpathoctop.dbSQLite file path. Relative paths resolve from OCTOP_HOME.
    OCTOP_DATABASE_HOSTstring127.0.0.1PostgreSQL host. Used only when OCTOP_DATABASE_DRIVER=postgresql.
    OCTOP_DATABASE_PORTint5432PostgreSQL port.
    OCTOP_DATABASE_NAMEstringoctopPostgreSQL database name.
    OCTOP_DATABASE_USERstringoctopPostgreSQL user.
    OCTOP_DATABASE_PASSWORDstring(empty)PostgreSQL password. Always set this via environment rather than config.json in production.
    OCTOP_ADMIN_USERNAMEstring(empty)Pre-fills the first admin username during octop init. Use with OCTOP_ADMIN_PASSWORD for unattended bootstraps. Docker first boot defaults to admin if unset.
    OCTOP_ADMIN_PASSWORDstring(empty)Pre-fills the first admin password during octop init.
    OCTOP_DEFAULT_PASSWORDstring(empty)Docker / image first-boot admin password. Written to /data/.octop/credential.txt. Unset generates a 16-character random password. Weak or common values fall back to a random password so first init never fails. Does not replace the bare-metal setup wizard.
    OCTOP_ADMIN_DISPLAY_NAMEstring(empty)Pre-fills the display name of the first admin account during octop init.
    OCTOP_HISTORY_V2_ENABLEDboolfalseEnable segmented history archive for the next completed turn.
    OCTOP_BROWSER_IDLE_TIMEOUT_MINUTESint30Idle minutes before Octop reaps a local Chrome started from the workbench.
    OCTOP_USERstring(empty)Default --user value for CLI subcommands, so you can omit the flag.
    OCTOP_AGENTstring(empty)Default --agent value for CLI subcommands.
    OCTOP_SERVICE_MODEstring(auto)Override the service backend used by octop service. Accepted values: systemd or launchd. Normally auto-detected from the host OS.
    OCTOP_SERVICE_SCOPEstring(auto)Control whether octop service installs a user-level or system-level unit on Linux. Accepted values: user or system. Equivalent to passing --scope to octop service start.
    OCTOP_MAX_UPLOAD_MBint100Max upload size in MiB for chat attachments, IM inbound files, and knowledge documents (clamped to 1–1024). Does not apply to plugin ZIPs, workspace uploads, or backup import (backup import is 512 MB).
    OCTOP_BACKUP_AUTO_ENABLEDboolfalseEnable automatic backups inside a running octop run process.
    OCTOP_BACKUP_SCHEDULEstringcron:0 4 * * *Automatic backup schedule.
    OCTOP_BACKUP_RETENTION_COUNTint7How many automatic backup archives to keep.
    OCTOP_BACKUP_INCLUDE_CONFIGbooltrueInclude config.json and env in new archives.
    OCTOP_BACKUP_INCLUDE_WORKSPACESbooltrueInclude agent workspaces.
    OCTOP_BACKUP_INCLUDE_SKILL_PACKAGESbooltrueInclude global skill packages.
    OCTOP_BACKUP_INCLUDE_PLUGINSbooltrueInclude installed plugins.
    OCTOP_BACKUP_INCLUDE_KNOWLEDGEbooltrueInclude knowledge-base files.
    OCTOP_BACKUP_INCLUDE_CHATSboolfalseInclude chat history and trajectories.

    Docker .env example

    Create a .env file next to your docker-compose.yml and populate the variables relevant to your deployment:

    .env
    docker-compose.yml (snippet)
    .env
    # Network
    OCTOP_BIND_HOST=0.0.0.0
    OCTOP_PORT=8088
    
    # Database (PostgreSQL)
    OCTOP_DATABASE_DRIVER=postgresql
    OCTOP_DATABASE_HOST=postgres
    OCTOP_DATABASE_PORT=5432
    OCTOP_DATABASE_NAME=octop
    OCTOP_DATABASE_USER=octop
    OCTOP_DATABASE_PASSWORD=change-me-in-production
    
    # First-run admin bootstrap (Docker entrypoint reads OCTOP_DEFAULT_PASSWORD)
    OCTOP_ADMIN_USERNAME=admin
    OCTOP_DEFAULT_PASSWORD=change-me-in-production
    
    # Timezone and logging
    OCTOP_DEFAULT_TIMEZONE=America/New_York
    OCTOP_LOG_LEVEL=info
    NOTE

    For Docker Compose, put OCTOP_DATABASE_* in docker/.env and list those keys under environment: in docker-compose.yml. Compose uses .env for interpolation only; unset keys do not enter the container. Writing the same keys to the mounted ~/.octop/env also works.

    WARNING

    Never store OCTOP_DATABASE_PASSWORD, OCTOP_ADMIN_PASSWORD, or OCTOP_DEFAULT_PASSWORD directly in config.json for production deployments. Keep them in environment variables or a secrets manager, and ensure your .env file is excluded from version control (add it to .gitignore). Restrict config.json file permissions to the service account only (chmod 600 ~/.octop/config.json).