Temporal Web UI environment variables reference
For the settings in the Web UI Server configuration file, see the Temporal Web UI configuration reference.
Environment variables configure the Temporal Web UI Server when you run it from the temporalio/ui Docker image.
Each variable sets a key in the configuration file.
The variables are defined in the docker.yaml configuration template in the ui-server repository. Each variable on this page lists its configuration key and its default.
docker run \
-e TEMPORAL_ADDRESS=127.0.0.1:7233 \
-e TEMPORAL_UI_PORT=8080 \
-e TEMPORAL_UI_PUBLIC_PATH=path/to/webui \
-e TEMPORAL_UI_ENABLED=true \
-e TEMPORAL_CLOUD_UI=false \
-e TEMPORAL_DEFAULT_NAMESPACE=default \
-e TEMPORAL_FEEDBACK_URL=https://feedback.here \
-e TEMPORAL_CONFIG_REFRESH_INTERVAL=0s \
-e TEMPORAL_SHOW_TEMPORAL_SYSTEM_NAMESPACE=false \
-e TEMPORAL_DISABLE_WRITE_ACTIONS=false \
-e TEMPORAL_AUTH_ENABLED=true \
-e TEMPORAL_AUTH_TYPE=oidc \
-e TEMPORAL_AUTH_PROVIDER_URL=https://accounts.google.com \
-e TEMPORAL_AUTH_ISSUER_URL=https://accounts.google.com \
-e TEMPORAL_AUTH_CLIENT_ID=xxxxx-xxxx.apps.googleusercontent.com \
-e TEMPORAL_AUTH_CLIENT_SECRET=xxxxxxxxxxxxxxx \
-e TEMPORAL_AUTH_CALLBACK_URL=https://xxxx.com:8080/auth/sso/callback \
-e TEMPORAL_AUTH_SCOPES=openid,email,profile \
-e TEMPORAL_TLS_CA=../ca.cert \
-e TEMPORAL_TLS_CERT=../cluster.pem \
-e TEMPORAL_TLS_KEY=../cluster.key \
-e TEMPORAL_TLS_ENABLE_HOST_VERIFICATION=true \
-e TEMPORAL_TLS_SERVER_NAME=tls-server \
-e TEMPORAL_CODEC_ENDPOINT=https://codec.server \
-e TEMPORAL_CODEC_PASS_ACCESS_TOKEN=false \
-e TEMPORAL_CODEC_INCLUDE_CREDENTIALS=false \
-e TEMPORAL_HIDE_LOGS=false \
temporalio/ui:<tag>
Server variables
TEMPORAL_ADDRESS
Address of the Frontend Service that the Web UI Server connects to.
- Configuration key:
temporalGrpcAddress - Default:
127.0.0.1:7233
TEMPORAL_UI_PORT
Port that the Web UI Server listens on for the browser UI and the HTTP API.
- Configuration key:
port - Default:
8080
TEMPORAL_UI_PUBLIC_PATH
Subpath to serve the Web UI from, such as /custom-path.
Leave it empty to serve the Web UI from the root path.
- Configuration key:
publicPath - Default: empty
TEMPORAL_UI_ENABLED
Set to false to stop serving the browser UI.
The Web UI Server still serves its APIs.
- Configuration key:
enableUi - Default:
true
TEMPORAL_CLOUD_UI
Set to true to use the Temporal Cloud version of the Web UI.
- Configuration key:
cloudUi - Default:
false
TEMPORAL_CONFIG_REFRESH_INTERVAL
How often the Web UI Server reloads its configuration, such as 1m.
Set it to 0s to turn off reloading.
Settings that the Web UI Server reads only at startup, such as TEMPORAL_UI_PORT and TEMPORAL_UI_PUBLIC_PATH, still need a restart.
- Configuration key:
refreshInterval - Default:
0s
TEMPORAL_FORWARD_HEADERS
Comma-separated list of HTTP headers that the Web UI Server forwards from HTTP API requests to the Temporal Service's gRPC API.
- Configuration key:
forwardHeaders - Default: empty
TEMPORAL_HIDE_LOGS
Set to true to stop the Web UI Server from printing its logs to the console.
- Configuration key:
hideLogs - Default:
false
TEMPORAL_UI_SERVER_TLS_CERT
Path to the certificate that the Web UI Server uses to serve the Web UI over HTTPS.
The Web UI Server starts in TLS mode only when you set both this variable and TEMPORAL_UI_SERVER_TLS_KEY.
- Configuration key:
uiServerTLS.certFile - Default: empty
TEMPORAL_UI_SERVER_TLS_KEY
Path to the private key for the certificate in TEMPORAL_UI_SERVER_TLS_CERT.
- Configuration key:
uiServerTLS.keyFile - Default: empty
TEMPORAL_UI_DISTRIBUTION
How the Web UI was installed: cli, docker, helm, or server.
When TEMPORAL_NOTIFY_ON_NEW_VERSION is true, the Web UI Server uses this value to choose which release to check for updates.
- Configuration key:
distribution - Default:
docker
TEMPORAL_UI_DISTRIBUTION_VERSION
Version of the distribution that installed the Web UI, such as the Temporal CLI version.
Only the cli distribution uses this value.
- Configuration key:
distributionVersion - Default: empty
CORS and CSRF variables
These variables control which origins can call the Web UI Server APIs and how the Web UI Server sets its cross-site request forgery (CSRF) cookie.
For the matching configuration keys, see cors.
TEMPORAL_CORS_ORIGINS
Comma-separated list of origins that can make cross-origin requests to the Web UI Server APIs.
A value of * allows every origin.
- Configuration key:
cors.allowOrigins - Default:
http://localhost:8080
TEMPORAL_CORS_UNSAFE_ALLOW_ALL_ORIGINS
Set to true to accept cross-origin requests from any origin and ignore TEMPORAL_CORS_ORIGINS.
Use it only for local development.
- Configuration key:
cors.unsafeAllowAllOrigins - Default:
false
TEMPORAL_CSRF_COOKIE_INSECURE
Set to true to send the CSRF cookie over connections the browser considers insecure, such as plain HTTP.
Use it only when something other than HTTPS secures the connection, such as a VPN.
- Configuration key:
cors.cookieInsecure - Default:
false
Web UI behavior variables
TEMPORAL_DEFAULT_NAMESPACE
Namespace that the Web UI opens first.
- Configuration key:
defaultNamespace - Default:
default
TEMPORAL_FEEDBACK_URL
URL that the Feedback button in the Web UI opens. When empty, the button opens the Web UI's GitHub issues page.
- Configuration key:
feedbackUrl - Default: empty
TEMPORAL_SHOW_TEMPORAL_SYSTEM_NAMESPACE
Set to true to show the Temporal System Namespace in the Web UI.
The System Namespace holds the Workflow Executions that the Temporal Service runs internally.
- Configuration key:
showTemporalSystemNamespace - Default:
false
TEMPORAL_DISABLE_NEWS_FETCH
Set to true to stop the Web UI from requesting the news feed.
The Web UI also hides the button that opens the news feed panel.
- Configuration key:
disableNewsFetch - Default:
false
TEMPORAL_NOTIFY_ON_NEW_VERSION
Set to true to show a notice in the Web UI when a newer release is available.
The Web UI Server checks the release that matches TEMPORAL_UI_DISTRIBUTION.
- Configuration key:
notifyOnNewVersion - Default:
false
TEMPORAL_NAV_COLLAPSED_BY_DEFAULT
Set to true to collapse the left navigation and the saved views navigation when the Web UI loads.
- Configuration key:
navCollapsedByDefault - Default:
false
TEMPORAL_HIDE_WORKFLOW_QUERY_ERRORS
Set to true to hide server errors from Workflow Queries in the Web UI.
- Configuration key:
hideWorkflowQueryErrors - Default:
false
TEMPORAL_REFRESH_WORKFLOW_COUNTS_DISABLED
Set to true to stop the Web UI from refreshing the Workflow status counts on the Workflows page.
- Configuration key:
refreshWorkflowCountsDisabled - Default:
false
Workflow and Activity action variables
These variables disable actions in the Web UI that change Workflow Executions or Activities. Each variable hides or disables the matching control in the Web UI.
TEMPORAL_DISABLE_WRITE_ACTIONS
Set to true to disable every action in the Web UI that changes a Workflow Execution or Activity, including batch actions.
This variable overrides the other variables in this section.
- Configuration key:
disableWriteActions - Default:
false
TEMPORAL_WORKFLOW_TERMINATE_DISABLED
Set to true to prevent users from terminating Workflow Executions from the Web UI.
- Configuration key:
workflowTerminateDisabled - Default:
false
TEMPORAL_WORKFLOW_CANCEL_DISABLED
Set to true to prevent users from canceling Workflow Executions from the Web UI.
- Configuration key:
workflowCancelDisabled - Default:
false
TEMPORAL_WORKFLOW_SIGNAL_DISABLED
Set to true to prevent users from sending Signals to Workflow Executions from the Web UI.
- Configuration key:
workflowSignalDisabled - Default:
false
TEMPORAL_WORKFLOW_UPDATE_DISABLED
Set to true to prevent users from sending Updates to Workflow Executions from the Web UI.
- Configuration key:
workflowUpdateDisabled - Default:
false
TEMPORAL_WORKFLOW_RESET_DISABLED
Set to true to prevent users from resetting Workflow Executions from the Web UI.
- Configuration key:
workflowResetDisabled - Default:
false
TEMPORAL_WORKFLOW_PAUSE_DISABLED
Set to true to prevent users from pausing Workflow Executions from the Web UI.
- Configuration key:
workflowPauseDisabled - Default:
false
TEMPORAL_BATCH_ACTIONS_DISABLED
Set to true to prevent users from running batch actions on multiple Workflow Executions from the Web UI.
- Configuration key:
batchActionsDisabled - Default:
false
TEMPORAL_START_WORKFLOW_DISABLED
Set to true to prevent users from starting Workflow Executions from the Web UI.
- Configuration key:
startWorkflowDisabled - Default:
false
TEMPORAL_ACTIVITY_COMMANDS_DISABLED
Set to true to hide the commands for pending Activities in the Web UI.
These commands pause, unpause, and reset an Activity, and update its options.
- Configuration key:
activityCommandsDisabled - Default:
false
Authentication variables
These variables configure sign-in to the Web UI through an identity provider (IdP).
They control who can access the Web UI, not authorization against the Temporal Service.
For the matching configuration keys, see auth.
TEMPORAL_AUTH_ENABLED
Set to true to require users to sign in to the Web UI.
The other authentication variables take effect only when this variable is true.
- Configuration key:
auth.enabled - Default:
false
TEMPORAL_AUTH_REDIRECT_TO_PROVIDER
Set to true to skip the Web UI sign-in page and send users who aren't signed in directly to the IdP.
- Configuration key:
auth.redirectToProvider - Default:
false
TEMPORAL_MAX_SESSION_DURATION
Longest a user session can last, such as 8h or 168h.
After this duration, users must sign in again even if their tokens are still valid.
When empty, sessions have no maximum duration.
- Configuration key:
auth.maxSessionDuration - Default: empty
TEMPORAL_AUTH_LABEL
Label for the identity provider.
- Configuration key:
auth.providers.label - Default:
sso
TEMPORAL_AUTH_TYPE
Authentication type.
- Configuration key:
auth.providers.type - Default:
oidc
TEMPORAL_AUTH_PROVIDER_URL
IdP URL that the Web UI Server uses for OpenID Connect (OIDC) discovery, such as https://accounts.google.com.
- Configuration key:
auth.providers.providerUrl - Default: none
TEMPORAL_AUTH_ISSUER_URL
URL of the token issuer.
Set it only when the issuer differs from TEMPORAL_AUTH_PROVIDER_URL.
- Configuration key:
auth.providers.issuerUrl - Default: empty
TEMPORAL_AUTH_CLIENT_ID
OAuth client ID that the IdP issued for the Web UI. Required when authentication is enabled.
- Configuration key:
auth.providers.clientId - Default: none
TEMPORAL_AUTH_CLIENT_SECRET
OAuth client secret that the IdP issued for the Web UI.
- Configuration key:
auth.providers.clientSecret - Default: none
TEMPORAL_AUTH_CALLBACK_URL
URL that the IdP redirects users to after they sign in, such as https://xxxx.com:8080/auth/sso/callback.
- Configuration key:
auth.providers.callbackUrl - Default: none
TEMPORAL_AUTH_SCOPES
Comma-separated list of OIDC scopes to request, such as openid,email,profile.
- Configuration key:
auth.providers.scopes - Default: empty
TEMPORAL_AUTH_USE_ID_TOKEN_AS_BEARER
Set to true to send the ID token instead of the access token as the bearer token in the Authorization header.
- Configuration key:
auth.providers.useIdTokenAsBearer - Default:
false
TEMPORAL_AUTH_REFRESH_TOKEN_DURATION
Lifetime of the refresh tokens that the IdP issues, such as 24h.
Set it only when the IdP issues opaque refresh tokens, because the Web UI Server can't read their expiration.
For JSON Web Token (JWT) refresh tokens, the Web UI Server uses the token's exp claim and ignores this value.
When neither is available, the Web UI Server assumes a lifetime of 7 days.
- Configuration key:
auth.providers.refreshTokenDuration - Default: empty
TLS variables
These variables configure Transport Layer Security (TLS) for the Web UI Server's connection to the Frontend Service.
They don't configure TLS for the Web UI itself.
For the matching configuration keys, see tls.
TEMPORAL_TLS_CA
Path to the Certificate Authority (CA) certificate that verifies the Frontend Service's certificate.
- Configuration key:
tls.caFile - Default: empty
TEMPORAL_TLS_CERT
Path to the client certificate that the Web UI Server presents to the Frontend Service for mutual TLS (mTLS).
- Configuration key:
tls.certFile - Default: empty
TEMPORAL_TLS_KEY
Path to the private key for the certificate in TEMPORAL_TLS_CERT.
- Configuration key:
tls.keyFile - Default: empty
TEMPORAL_TLS_CA_DATA
PEM data for the CA certificate.
Use it instead of TEMPORAL_TLS_CA.
- Configuration key:
tls.caData - Default: empty
TEMPORAL_TLS_CERT_DATA
PEM data for the client certificate.
Use it instead of TEMPORAL_TLS_CERT.
- Configuration key:
tls.certData - Default: empty
TEMPORAL_TLS_KEY_DATA
PEM data for the private key.
Use it instead of TEMPORAL_TLS_KEY.
- Configuration key:
tls.keyData - Default: empty
TEMPORAL_TLS_ENABLE_HOST_VERIFICATION
Set to true to verify that the Frontend Service's certificate matches its hostname.
- Configuration key:
tls.enableHostVerification - Default:
false
TEMPORAL_TLS_SERVER_NAME
Overrides the server name sent for Server Name Indication (SNI) and checked against the Frontend Service's certificate.
- Configuration key:
tls.serverName - Default: empty
Codec Server variables
These variables configure how the Web UI sends payloads to a Codec Server for decoding.
For the matching configuration keys, see codec.
TEMPORAL_CODEC_ENDPOINT
URL of the Codec Server.
- Configuration key:
codec.endpoint - Default: empty
TEMPORAL_CODEC_PASS_ACCESS_TOKEN
Set to true to send the user's access token in the Authorization header of requests to the Codec Server.
- Configuration key:
codec.passAccessToken - Default:
false
TEMPORAL_CODEC_INCLUDE_CREDENTIALS
Set to true to include browser credentials, such as cookies, in requests to the Codec Server.
- Configuration key:
codec.includeCredentials - Default:
false
TEMPORAL_CODEC_DEFAULT_ERROR_MESSAGE
Message that the Web UI shows in its error banner when it can't reach the Codec Server. When empty, the Web UI shows its built-in message.
- Configuration key:
codec.defaultErrorMessage - Default: empty
TEMPORAL_CODEC_DEFAULT_ERROR_LINK
Link that the Web UI shows in its error banner when it can't reach the Codec Server. When empty, the Web UI links to Set your Codec Server endpoints with Web UI and CLI.
- Configuration key:
codec.defaultErrorLink - Default: empty