Operate

Configuration reference

Every variable, secret and binding.

Variables live in wrangler.jsonc (vars) or the Cloudflare dashboard (Worker → Settings → Variables). Secrets are set with wrangler secret put or in the dashboard.

Secrets

NameRequiredPurpose
BETTER_AUTH_SECRETyesSigns sessions. 32+ random bytes.
GITHUB_CLIENT_ID / GITHUB_CLIENT_SECRETno“Continue with GitHub”
GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRETno“Continue with Google”
TURNSTILE_SECRETnoBot protection on sign-up (with TURNSTILE_SITE_KEY)
AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEYyesAmazon SES, SNS and S3 — receiving and sending
STRIPE_SECRET_KEY / STRIPE_WEBHOOK_SECRETnoHosted service only: plans & billing (details)

Instance

VariableDefaultPurpose
APP_URLderivedPublic URL, e.g. https://mail.example.com
INSTANCE_NAMESquadmailShown in UI and mails
MAIL_FROM—Sender for system mails (verified SES domain)
AWS_REGIONeu-west-1SES region (must support receiving)
SES_S3_BUCKETautoBucket for incoming mail (created by setup)
SES_CONFIGURATION_SET—Optional SES configuration set for sending
DOCS_URLhttps://squadmail.dev/docsHelp links
SIGNUP_MODEinviteopen, invite, closed
REQUIRE_EMAIL_VERIFICATIONfalseRequire verified email (needs MAIL_FROM)

Features

VariableDefault
FEATURE_SENDINGtrue
FEATURE_WEBHOOKStrue
FEATURE_CATCH_ALLtrue
FEATURE_PERMANENT_INBOXEStrue
CLEF_ENABLEDtrue
LABEL_MODELclef-flash
AI_GATEWAY_ID—

Limits

See Retention, limits & quotas for MAX_*, RETENTION_DAYS, SEND_PER_DAY, LABEL_CALLS_PER_DAY, LABEL_GLOBAL_DAILY_BUDGET and API_RATE_PER_MIN.

Bindings

BindingTypeRequired
DBD1yes
BUCKETR2yes
JOBSQueue producer + consumeryes
INBOX_HUB, COUNTERSDurable Objects (SQLite)yes
OAUTH_KVKVyes (MCP OAuth)
AIWorkers AIno (Clef)
ASSETSStatic assetsyes

On Squadmail Cloud (billing enabled) the organization’s plan replaces most features and limits; the variables above then act as an instance-wide ceiling.

Webhook endpoints

PathCaller
/hooks/ses/<token>Amazon SNS (incoming mail). The token is derived from BETTER_AUTH_SECRET; the SNS signature is verified.
/hooks/stripeStripe (hosted service only), signature-verified

Cron

*/15 * * * * runs retention, expiry webhooks and housekeeping.

Edit this page on GitHub