Temporal Web UI configuration reference
To set these keys with environment variables in the temporalio/ui Docker image, see the
Temporal Web UI environment variables reference.
The Temporal Web UI Server reads its configuration from YAML files in its configuration directory.
It loads base.yaml first, then the file for the current environment, such as development.yaml.
Values in the environment file override values in base.yaml.
The configuration structs are defined in config.go in the ui-server repository. For a complete example, see development.yaml.
Each key on this page lists its environment variable and its default. The default is the value the Web UI Server uses when no configuration file sets the key. The Docker image sets its own defaults through environment variables.
Server settings
temporalGrpcAddress
Address of the Frontend Service that the Web UI Server connects to. The Web UI Server doesn't start without this value.
- Environment variable:
TEMPORAL_ADDRESS - Default:
127.0.0.1:7233, set inbase.yaml
host
Network interface that the Web UI Server listens on. When empty, the Web UI Server listens on every interface.
- Environment variable: none
- Default: empty
port
Port that the Web UI Server listens on for the browser UI and the HTTP API.
- Environment variable:
TEMPORAL_UI_PORT - Default:
8233, set inbase.yaml
publicPath
Subpath to serve the Web UI from, such as /custom-path.
Leave it empty to serve the Web UI from the root path.
- Environment variable:
TEMPORAL_UI_PUBLIC_PATH - Default: empty
enableUi
Set to true to serve the browser UI.
When false, the Web UI Server serves only its APIs.
- Environment variable:
TEMPORAL_UI_ENABLED - Default:
false
uiAssetPath
Directory to serve the Web UI's static files from, instead of the files built into the Web UI Server.
- Environment variable: none
- Default: empty
cloudUi
Set to true to use the Temporal Cloud version of the Web UI.
- Environment variable:
TEMPORAL_CLOUD_UI - Default:
false
refreshInterval
How often the Web UI Server reloads its configuration files, such as 1m.
Set it to 0s to turn off reloading.
Settings that the Web UI Server reads only at startup, such as host, port, and publicPath, still need a restart.
- Environment variable:
TEMPORAL_CONFIG_REFRESH_INTERVAL - Default:
0s
forwardHeaders
List of HTTP headers that the Web UI Server forwards from HTTP API requests to the Temporal Service's gRPC API.
forwardHeaders:
- X-Forwarded-For
- Environment variable:
TEMPORAL_FORWARD_HEADERS - Default: empty
hideLogs
Set to true to stop the Web UI Server from printing its logs to the console.
- Environment variable:
TEMPORAL_HIDE_LOGS - Default:
false
distribution
How the Web UI was installed: cli, docker, helm, or server.
When notifyOnNewVersion is true, the Web UI Server uses this value to choose which release
to check for updates.
- Environment variable:
TEMPORAL_UI_DISTRIBUTION - Default: empty, which the Web UI Server treats as
server
distributionVersion
Version of the distribution that installed the Web UI, such as the Temporal CLI version.
Only the cli distribution uses this value.
- Environment variable:
TEMPORAL_UI_DISTRIBUTION_VERSION - Default: empty
Web UI behavior settings
defaultNamespace
Namespace that the Web UI opens first.
- Environment variable:
TEMPORAL_DEFAULT_NAMESPACE - Default: empty
feedbackUrl
URL that the Feedback button in the Web UI opens. When empty, the button opens the Web UI's GitHub issues page.
- Environment variable:
TEMPORAL_FEEDBACK_URL - Default: empty
showTemporalSystemNamespace
Set to true to show the Temporal System Namespace in the Web UI.
The System Namespace holds the Workflow Executions that the Temporal Service runs internally.
- Environment variable:
TEMPORAL_SHOW_TEMPORAL_SYSTEM_NAMESPACE - Default:
false
disableNewsFetch
Set to true to stop the Web UI from requesting the news feed.
The Web UI also hides the button that opens the news feed panel.
- Environment variable:
TEMPORAL_DISABLE_NEWS_FETCH - Default:
false
notifyOnNewVersion
Set to true to show a notice in the Web UI when a newer release is available.
The Web UI Server checks the release that matches distribution.
- Environment variable:
TEMPORAL_NOTIFY_ON_NEW_VERSION - Default:
false
navCollapsedByDefault
Set to true to collapse the left navigation and the saved views navigation when the Web UI loads.
- Environment variable:
TEMPORAL_NAV_COLLAPSED_BY_DEFAULT - Default:
false
hideWorkflowQueryErrors
Set to true to hide server errors from Workflow Queries in the Web UI.
- Environment variable:
TEMPORAL_HIDE_WORKFLOW_QUERY_ERRORS - Default:
false
refreshWorkflowCountsDisabled
Set to true to stop the Web UI from refreshing the Workflow status counts on the Workflows page.
- Environment variable:
TEMPORAL_REFRESH_WORKFLOW_COUNTS_DISABLED - Default:
false
Workflow and Activity action settings
These keys disable actions in the Web UI that change Workflow Executions or Activities. Each key hides or disables the matching control in the Web UI.
disableWriteActions
Set to true to disable every action in the Web UI that changes a Workflow Execution or Activity, including batch
actions.
This key overrides the other keys in this section.
The Web UI Server also rejects write requests to its HTTP API. Workflow Queries still work.
- Environment variable:
TEMPORAL_DISABLE_WRITE_ACTIONS - Default:
false
workflowTerminateDisabled
Set to true to prevent users from terminating Workflow Executions from the Web UI.
- Environment variable:
TEMPORAL_WORKFLOW_TERMINATE_DISABLED - Default:
false
workflowCancelDisabled
Set to true to prevent users from canceling Workflow Executions from the Web UI.
- Environment variable:
TEMPORAL_WORKFLOW_CANCEL_DISABLED - Default:
false
workflowSignalDisabled
Set to true to prevent users from sending Signals to Workflow Executions from the Web UI.
- Environment variable:
TEMPORAL_WORKFLOW_SIGNAL_DISABLED - Default:
false
workflowUpdateDisabled
Set to true to prevent users from sending Updates to Workflow Executions from the Web UI.
- Environment variable:
TEMPORAL_WORKFLOW_UPDATE_DISABLED - Default:
false
workflowResetDisabled
Set to true to prevent users from resetting Workflow Executions from the Web UI.
- Environment variable:
TEMPORAL_WORKFLOW_RESET_DISABLED - Default:
false
workflowPauseDisabled
Set to true to prevent users from pausing Workflow Executions from the Web UI.
- Environment variable:
TEMPORAL_WORKFLOW_PAUSE_DISABLED - Default:
false
batchActionsDisabled
Set to true to prevent users from running batch actions on multiple Workflow Executions from the Web UI.
- Environment variable:
TEMPORAL_BATCH_ACTIONS_DISABLED - Default:
false
startWorkflowDisabled
Set to true to prevent users from starting Workflow Executions from the Web UI.
- Environment variable:
TEMPORAL_START_WORKFLOW_DISABLED - Default:
false
activityCommandsDisabled
Set to true to hide the commands for pending Activities in the Web UI.
These commands pause, unpause, and reset an Activity, and update its options.
- Environment variable:
TEMPORAL_ACTIVITY_COMMANDS_DISABLED - Default:
false
cors
The cors section controls which origins can call the Web UI Server APIs and how the Web UI Server sets its
cross-site request forgery (CSRF) cookie.
CORS stands for Cross-Origin Resource Sharing.
cors:
allowOrigins:
- http://localhost:3000
unsafeAllowAllOrigins: false
cookieInsecure: false
allowOrigins: List of origins that can make cross-origin requests to the Web UI Server APIs. A value of*allows every origin.- Environment variable:
TEMPORAL_CORS_ORIGINS - Default: empty, which allows no cross-origin requests
- Environment variable:
unsafeAllowAllOrigins: Set totrueto accept cross-origin requests from any origin and ignoreallowOrigins. Use it only for local development.- Environment variable:
TEMPORAL_CORS_UNSAFE_ALLOW_ALL_ORIGINS - Default:
false
- Environment variable:
cookieInsecure: Set totrueto send the CSRF cookie over connections the browser considers insecure, such as plain HTTP. Use it only when something other than HTTPS secures the connection, such as a VPN.- Environment variable:
TEMPORAL_CSRF_COOKIE_INSECURE - Default:
false
- Environment variable:
auth
The auth section configures sign-in to the Web UI through an identity provider (IdP).
It controls who can access the Web UI, not authorization against the Temporal Service.
auth:
enabled: true
providers:
- label: sso
type: oidc
providerUrl: https://accounts.google.com
issuerUrl:
clientId: xxxxx-xxxx.apps.googleusercontent.com
clientSecret: xxxxxxxxxxxxxxxxxxxx
callbackUrl: https://xxxx.com:8080/auth/sso/callback
scopes:
- openid
- profile
- email
enabled: Set totrueto require users to sign in to the Web UI. The otherauthkeys take effect only when this key istrue.- Environment variable:
TEMPORAL_AUTH_ENABLED - Default:
false
- Environment variable:
redirectToProvider: Set totrueto skip the Web UI sign-in page and send users who aren't signed in directly to the IdP.- Environment variable:
TEMPORAL_AUTH_REDIRECT_TO_PROVIDER - Default:
false
- Environment variable:
maxSessionDuration: Longest a user session can last, such as8hor168h. After this duration, users must sign in again even if their tokens are still valid. When empty, sessions have no maximum duration.- Environment variable:
TEMPORAL_MAX_SESSION_DURATION - Default: empty
- Environment variable:
providers: List of IdPs. The Web UI Server uses only the first provider in the list.- Default: empty
providers
Each provider takes the following keys.
When enabled is true, the Web UI Server doesn't start unless providerUrl, clientId, and callbackUrl are set.
label: Label for the IdP.- Environment variable:
TEMPORAL_AUTH_LABEL - Default: empty
- Environment variable:
type: Authentication type. Onlyoidcis supported.- Environment variable:
TEMPORAL_AUTH_TYPE - Default: empty
- Environment variable:
providerUrl: IdP URL that the Web UI Server uses for OpenID Connect (OIDC) discovery, such ashttps://accounts.google.com.- Environment variable:
TEMPORAL_AUTH_PROVIDER_URL - Default: empty
- Environment variable:
issuerUrl: URL of the token issuer. Set it only when the issuer differs fromproviderUrl.- Environment variable:
TEMPORAL_AUTH_ISSUER_URL - Default: empty
- Environment variable:
clientId: OAuth client ID that the IdP issued for the Web UI.- Environment variable:
TEMPORAL_AUTH_CLIENT_ID - Default: empty
- Environment variable:
clientSecret: OAuth client secret that the IdP issued for the Web UI.- Environment variable:
TEMPORAL_AUTH_CLIENT_SECRET - Default: empty
- Environment variable:
callbackUrl: URL that the IdP redirects users to after they sign in, such ashttps://xxxx.com:8080/auth/sso/callback.- Environment variable:
TEMPORAL_AUTH_CALLBACK_URL - Default: empty
- Environment variable:
scopes: List of OIDC scopes to request, such asopenid,profile, andemail.- Environment variable:
TEMPORAL_AUTH_SCOPES - Default: empty
- Environment variable:
options: Map of query parameters that the Web UI Server adds to the redirect URL for the IdP. Use it for IdP-specific sign-in flows, such as the Auth0audienceandorganizationparameters.- Environment variable: none
- Default: empty
useIdTokenAsBearer: Set totrueto send the ID token instead of the access token as the bearer token in theAuthorizationheader.- Environment variable:
TEMPORAL_AUTH_USE_ID_TOKEN_AS_BEARER - Default:
false
- Environment variable:
refreshTokenDuration: Lifetime of the refresh tokens that the IdP issues, such as24h. Set it only when the IdP issues opaque refresh tokens, because the Web UI Server can't read their expiration. For JSON Web Token (JWT) refresh tokens, the Web UI Server uses the token'sexpclaim and ignores this value. When neither is available, the Web UI Server assumes a lifetime of 7 days.- Environment variable:
TEMPORAL_AUTH_REFRESH_TOKEN_DURATION - Default: empty
- Environment variable:
tls
The tls section configures Transport Layer Security (TLS) for the Web UI Server's connection to the Frontend Service.
It doesn't configure TLS for the Web UI itself.
To serve the Web UI over HTTPS, see uiServerTLS.
tls:
caFile: ../ca.cert
certFile: ../cluster.pem
keyFile: ../cluster.key
caData:
certData:
keyData:
enableHostVerification: true
serverName: tls-server
caFile: Path to the Certificate Authority (CA) certificate that verifies the Frontend Service's certificate.- Environment variable:
TEMPORAL_TLS_CA - Default: empty
- Environment variable:
certFile: Path to the client certificate that the Web UI Server presents to the Frontend Service for mutual TLS (mTLS).- Environment variable:
TEMPORAL_TLS_CERT - Default: empty
- Environment variable:
keyFile: Path to the private key for the certificate incertFile.- Environment variable:
TEMPORAL_TLS_KEY - Default: empty
- Environment variable:
caData: PEM data for the CA certificate. Use it instead ofcaFile.- Environment variable:
TEMPORAL_TLS_CA_DATA - Default: empty
- Environment variable:
certData: PEM data for the client certificate. Use it instead ofcertFile.- Environment variable:
TEMPORAL_TLS_CERT_DATA - Default: empty
- Environment variable:
keyData: PEM data for the private key. Use it instead ofkeyFile.- Environment variable:
TEMPORAL_TLS_KEY_DATA - Default: empty
- Environment variable:
enableHostVerification: Set totrueto verify that the Frontend Service's certificate matches its hostname.- Environment variable:
TEMPORAL_TLS_ENABLE_HOST_VERIFICATION - Default:
false
- Environment variable:
serverName: Overrides the server name sent for Server Name Indication (SNI) and checked against the Frontend Service's certificate.- Environment variable:
TEMPORAL_TLS_SERVER_NAME - Default: empty
- Environment variable:
uiServerTLS
The uiServerTLS section configures the Web UI Server to serve the Web UI over HTTPS.
The Web UI Server starts in TLS mode only when you set both keys.
uiServerTLS:
certFile: ../ui-server.pem
keyFile: ../ui-server.key
certFile: Path to the certificate that the Web UI Server presents to browsers.- Environment variable:
TEMPORAL_UI_SERVER_TLS_CERT - Default: empty
- Environment variable:
keyFile: Path to the private key for the certificate incertFile.- Environment variable:
TEMPORAL_UI_SERVER_TLS_KEY - Default: empty
- Environment variable:
codec
The codec section configures how the Web UI sends payloads to a Codec Server for decoding.
codec:
endpoint: https://your-codec-server-endpoint
passAccessToken: false
includeCredentials: false
defaultErrorMessage:
defaultErrorLink:
endpoint: URL of the Codec Server.- Environment variable:
TEMPORAL_CODEC_ENDPOINT - Default: empty
- Environment variable:
passAccessToken: Set totrueto send the user's access token in theAuthorizationheader of requests to the Codec Server.- Environment variable:
TEMPORAL_CODEC_PASS_ACCESS_TOKEN - Default:
false
- Environment variable:
includeCredentials: Set totrueto include browser credentials, such as cookies, in requests to the Codec Server.- Environment variable:
TEMPORAL_CODEC_INCLUDE_CREDENTIALS - Default:
false
- Environment variable:
defaultErrorMessage: Message that the Web UI shows in its error banner when it can't reach the Codec Server. When empty, the Web UI shows its built-in message.- Environment variable:
TEMPORAL_CODEC_DEFAULT_ERROR_MESSAGE - Default: empty
- Environment variable:
defaultErrorLink: Link that the Web UI shows in its error banner when it can't reach the Codec Server. When empty, the Web UI links to Set your Codec Server endpoints with Web UI and CLI.- Environment variable:
TEMPORAL_CODEC_DEFAULT_ERROR_LINK - Default: empty
- Environment variable: