Operate
Configuration reference
Every variable, secret and binding.
Variables live in wrangler.jsonc (vars) or the Cloudflare dashboard (Worker → Settings → Variables). Secrets are set with wrangler secret put or in the dashboard.
Secrets
| Name | Required | Purpose |
|---|---|---|
BETTER_AUTH_SECRET | yes | Signs sessions. 32+ random bytes. |
GITHUB_CLIENT_ID / GITHUB_CLIENT_SECRET | no | “Continue with GitHub” |
GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET | no | “Continue with Google” |
TURNSTILE_SECRET | no | Bot protection on sign-up (with TURNSTILE_SITE_KEY) |
AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY | yes | Amazon SES, SNS and S3 — receiving and sending |
STRIPE_SECRET_KEY / STRIPE_WEBHOOK_SECRET | no | Hosted service only: plans & billing (details) |
Instance
| Variable | Default | Purpose |
|---|---|---|
APP_URL | derived | Public URL, e.g. https://mail.example.com |
INSTANCE_NAME | Squadmail | Shown in UI and mails |
MAIL_FROM | — | Sender for system mails (verified SES domain) |
AWS_REGION | eu-west-1 | SES region (must support receiving) |
SES_S3_BUCKET | auto | Bucket for incoming mail (created by setup) |
SES_CONFIGURATION_SET | — | Optional SES configuration set for sending |
DOCS_URL | https://squadmail.dev/docs | Help links |
SIGNUP_MODE | invite | open, invite, closed |
REQUIRE_EMAIL_VERIFICATION | false | Require verified email (needs MAIL_FROM) |
Features
| Variable | Default |
|---|---|
FEATURE_SENDING | true |
FEATURE_WEBHOOKS | true |
FEATURE_CATCH_ALL | true |
FEATURE_PERMANENT_INBOXES | true |
CLEF_ENABLED | true |
LABEL_MODEL | clef-flash |
AI_GATEWAY_ID | — |
Limits
See Retention, limits & quotas for MAX_*, RETENTION_DAYS, SEND_PER_DAY, LABEL_CALLS_PER_DAY, LABEL_GLOBAL_DAILY_BUDGET and API_RATE_PER_MIN.
Bindings
| Binding | Type | Required |
|---|---|---|
DB | D1 | yes |
BUCKET | R2 | yes |
JOBS | Queue producer + consumer | yes |
INBOX_HUB, COUNTERS | Durable Objects (SQLite) | yes |
OAUTH_KV | KV | yes (MCP OAuth) |
AI | Workers AI | no (Clef) |
ASSETS | Static assets | yes |
On Squadmail Cloud (billing enabled) the organization’s plan replaces most features and limits; the variables above then act as an instance-wide ceiling.
Webhook endpoints
| Path | Caller |
|---|---|
/hooks/ses/<token> | Amazon SNS (incoming mail). The token is derived from BETTER_AUTH_SECRET; the SNS signature is verified. |
/hooks/stripe | Stripe (hosted service only), signature-verified |
Cron
*/15 * * * * runs retention, expiry webhooks and housekeeping.