Skip to main content
ServFlow is an agent builder: you define AI agents and the workflows they run, and a Go engine serves them. The instance itself — ports, storage, authentication, tracing — is configured with a single TOML file passed to servflowai start --config. This page is the complete reference for that file. For installing the binary see Installation; for what an agent is, see Agents.
Every option can also be set with an environment variable. Environment variables take precedence over the TOML file, which makes them convenient for containers and CI.

Minimal configuration

Only server.config_folder is required. Everything else has a working default:
Start the instance with:

[server]

Controls how the process is hosted. One port serves everything. The workflow engine owns the root path, so a workflow listening on /hello answers at http://localhost:8080/hello. The builder UI is mounted under /dashboard on this same port, so its pages and assets live there rather than at the origin root.

[sqlite]

The store. Agents, integrations, providers, secrets, workspaces, and user accounts are rows in one SQLite file.
When master_key is set, these are encrypted in the store:
  • the value of every secret
  • the config of every integration
  • the config of every provider, which holds its API key
  • the tokens of integrations connected through a sign-in, such as Notion
Rows written before master_key was set stay in plain text.
Never commit master_key to version control. Set it with SERVFLOW_SQLITE_MASTER_KEY in production. Changing it makes previously encrypted values unreadable.

[secrets]

Controls where {{ secret "name" }} resolves from at runtime.
By default, ServFlow checks an environment variable whose name exactly matches the secret name before it checks the stored secret of that name. Set disable_env = true on a shared or hosted instance so workflows and agent tools cannot read the instance’s own environment variables through {{ secret }}.

[authentication]

Controls how the dashboard and management API are gated.
mode defaults to local. A config file that omits this section is still gated — the first time you open the dashboard you are asked to create an account. See First run.
mode = "none" leaves the dashboard and management API open to anyone who can reach the port. Use it only on a trusted local machine.
Sessions are opaque tokens stored in the database, so they survive restarts and can be revoked by logging out.

[tracing]

OpenTelemetry tracing for debugging workflow and agent runs.
Tracing can also be configured during first-run setup, which offers a hosted collector, a custom endpoint, or disabling it.

Complete example

Environment variable overrides

Environment variables always win over the TOML file. This keeps secrets out of configuration files and lets one image serve several environments:

Secrets from environment variables

A secret is looked up by name each time it is used. By default, an environment variable whose name is exactly the secret’s name, with no prefix and no change of case, is used before the stored secret of that name. A name that matches neither gives an empty value, not an error. Set [secrets].disable_env = true to skip environment lookup completely.

Viewing the active configuration

To see the settings an instance actually resolved, including defaults and environment overrides:

Next steps

Installation

Install ServFlow and create your first account.

Secrets

Store a credential once and use it by name.

Agents

Learn the object model your configuration serves.