Skip to guide
Deployment/Configure
Self-hosting reference

Workspace connections

Enable the connections now offered in the product: Google Drive, Slack, GitHub, and opt-in Gmail.

Enable secure credential storage first

Every workspace connection needs EMBEDDING_SECRETS_KEY plus its OAuth client pair. Without both, the product reports the provider as not configured. Generate the encryption key from 32 random bytes encoded as base64 and preserve it for the lifetime of stored grants.

Generate a new encryption key
openssl rand -base64 32

Compose already forwards EMBEDDING_SECRETS_KEY. Forward the connection-specific environment variables into app and worker in your operator override as well.

Provider configuration

Register each callback on your public APP_PUBLIC_URL. Connection credentials are separate from AUTH_GOOGLE_* and AUTH_GITHUB_* social sign-in credentials.

Google Drive
GOOGLE_OAUTH_CLIENT_ID + GOOGLE_OAUTH_CLIENT_SECRET. Callback: /api/connectors/google/oauth/callback.
Slack
SLACK_CLIENT_ID + SLACK_CLIENT_SECRET. Callback: /api/connectors/slack/oauth/callback.
GitHub
GITHUB_OAUTH_CLIENT_ID + GITHUB_OAUTH_CLIENT_SECRET. Callback: /api/connectors/github/oauth/callback.
Gmail · opt-in
The Google OAuth pair plus GMAIL_CONNECTOR_ENABLED=true. Uses a separate mailbox grant and the shared Google callback; reads mail without sending or deleting it.

Gmail uses the restricted gmail.readonly scope. Prepare the Google consent screen and the verification or internal-app setup before enabling it for users.

Google Picker and linked editing

The Google file picker needs NEXT_PUBLIC_GOOGLE_API_KEY (a restricted browser API key) and NEXT_PUBLIC_GOOGLE_APP_ID (the numeric project ID) at web-app build time.

GOOGLE_DOCS_EDITING_ENABLED=true enables the separate Drive-linked editing capability. It is not required merely to configure a Drive knowledge connection.

Host-local agent sources

AGENT_KNOWLEDGE_CONNECTOR_ENABLED with AGENT_KNOWLEDGE_PROJECT_ROOTS enables access to configured project roots on the server host. AGENT_SESSIONS_CONNECTOR_ENABLED enables local agent transcript sources. These are optional personal-instance capabilities: a hosted server does not gain access to a visitor's local computer.

Deployment Guide — Self-Host Launchstack | Launchstack