Internal
Environment Variables
Every environment variable SLAW uses for server configuration.
Server configuration
| Variable | Default | Description |
|---|---|---|
PORT | 3100 | Server port |
SLAW_BIND | loopback | Reachability preset: loopback, lan, tailnet, or custom |
SLAW_BIND_HOST | (unset) | Required when SLAW_BIND=custom |
HOST | 127.0.0.1 | Legacy host override; prefer SLAW_BIND for new setups |
DATABASE_URL | (embedded) | PostgreSQL connection string |
SLAW_HOME | ~/.slaw | Base directory for all SLAW data |
SLAW_INSTANCE_ID | default | Instance identifier (for multiple local instances) |
SLAW_DEPLOYMENT_MODE | local_trusted | Runtime mode override |
SLAW_DEPLOYMENT_EXPOSURE | private | Exposure policy when deployment mode is authenticated |
SLAW_API_URL | (auto-derived) | API base URL. When set externally (Kubernetes ConfigMap, load balancer, reverse proxy), the server preserves it instead of deriving it from the listen host and port. |
Secrets
| Variable | Default | Description |
|---|---|---|
SLAW_SECRETS_MASTER_KEY | (from file) | 32-byte encryption key (base64/hex/raw) |
SLAW_SECRETS_MASTER_KEY_FILE | ~/.slaw/.../secrets/master.key | Path to key file |
SLAW_SECRETS_STRICT_MODE | false | Require secret refs for sensitive env vars |
Agent runtime (injected into agent processes)
These are set automatically by the server when invoking agents:
| Variable | Description |
|---|---|
SLAW_AGENT_ID | Agent's unique ID |
SLAW_SQUAD_ID | Squad ID |
SLAW_API_URL | API base URL (inherits the server-level value) |
SLAW_API_KEY | Short-lived JWT for API auth |
SLAW_RUN_ID | Current heartbeat run ID |
SLAW_TASK_ID | Issue that triggered this wake |
SLAW_WAKE_REASON | Wake trigger reason |
SLAW_WAKE_COMMENT_ID | Comment that triggered this wake |
SLAW_APPROVAL_ID | Resolved approval ID |
SLAW_APPROVAL_STATUS | Approval decision |
SLAW_LINKED_ISSUE_IDS | Comma-separated linked issue IDs |
Control tower & cloud
| Variable | Default | Description |
|---|---|---|
SLAW_BOTFATHER_URL | (unset) | Botfather control-tower URL this instance reports to |
SLAW_BOTFATHER_ENROLLMENT_SECRET | (unset) | Pre-shared enrollment secret, sent on /enroll when the tower requires one. Prefer this over the config file. |
SLAW_CLOUD_TENANT_SERVER_TOKEN | (unset) | Shared token for the trusted x-slaw-cloud-* header path (Slaw Cloud) |
SLAW_CLOUD_TENANT_ALLOWED_IPS | (unset) | Comma/space-separated IPs or CIDRs allowed to use the cloud-tenant header path. When set, requests from other sources are refused. Strongly recommended whenever SLAW_CLOUD_TENANT_SERVER_TOKEN is set. |
caution
The cloud-tenant header path grants instance-admin from a shared token. Always set SLAW_CLOUD_TENANT_ALLOWED_IPS to your edge-proxy CIDRs, and ensure the proxy strips inbound x-slaw-cloud-* headers from client requests.
LLM provider keys (for adapters)
| Variable | Description |
|---|---|
ANTHROPIC_API_KEY | Anthropic API key (for the Claude Local adapter) |
OPENAI_API_KEY | OpenAI API key (for the Codex Local adapter) |
Next steps
- Deployment Modes —
SLAW_DEPLOYMENT_MODEin context - Secrets — secret-ref handling and strict mode
- Database —
DATABASE_URLconfiguration