Relay docs

Configuration reference

Every configuration key read by the gateway, with defaults where the code sets one. See Configuration & secrets for precedence and secret handling.

#Connections & hosting

KeyDefaultPurpose
ConnectionStrings:GatewayDb—Gateway SQL database.
Cors:PanelOrigins—Allowed origins for the control-plane CORS policy.
Seed:MockBaseUrlhttp://localhost:8899Mock provider base URL used when seeding.

#Chat & agents

KeyDefaultPurpose
Gateway:DefaultModel—Model used when a request omits one / team default.
Gateway:FallbackModel—Global default fallback, used only when a model declares no fallback of its own. Set a per-model fallback in Models → Edit → Fallback model instead — it takes precedence. See Model routing & fallback.
Gateway:ModelAliases:{requested}—Dynamic remap of a requested model name.
Gateway:ToolMaxIterations5Max MCP tool-loop iterations for agents.

#Routing & resilience

KeyDefaultPurpose
Gateway:MaxRetries2Transient retry count.
Gateway:RetryBaseDelayMs250Retry backoff base.
Gateway:CatalogCacheSeconds10Model/provider catalog cache TTL.
Gateway:BudgetRefreshMinutes5Budget spend refresh interval.

#Response cache

KeyDefaultPurpose
Gateway:Cache:TtlSeconds0 (off)Response-cache TTL.
Gateway:Cache:MaxEntries5000Response-cache size cap.

#Moderation

KeyDefaultPurpose
Gateway:Moderation:EnabledfalseTurn moderation on.
Gateway:Moderation:BlocktrueBlock flagged content vs. only flag.
Gateway:Moderation:FlagJailbreaktrueDetect prompt-injection / jailbreak.

#RAG

KeyDefaultPurpose
Gateway:Rag:HybridAlpha0.5Dense vs. lexical blend weight.
Gateway:Rag:MmrLambda0.7MMR relevance/diversity tradeoff.
Qdrant:Url—Vector store endpoint.
Qdrant:ApiKey—Vector store key (if required).

#Dataset agents (SQL)

Reached by the gateway and, for the editor's picker only, by the panel host. Both hosts should carry the same BaseUrl and ApiKey — a mismatch means the picker lists a different company's datasets than a run resolves. See Dataset agents.

KeyDefaultPurpose
Gateway:Data:BaseUrl—Data app base URL. Absolute http/https, no query or fragment; an invalid value fails at startup. In development use https://localhost:7434 — the http port 307-redirects and redirects are not followed.
Gateway:Data:ApiKey—Data app API key. A secret — user-secrets / env / Key Vault. Carries the data app's company, so one key = one company for the whole instance.
Gateway:Data:TimeoutSeconds15Per-call timeout to the data app.
Gateway:Data:ModelMaxRows100Rows shown to the model.
Gateway:Data:CallerMaxRows1000Rows fetched, i.e. what the caller receives in relay_dataset.
Gateway:Data:ModelMaxChars20000Character budget for rows handed to the model.
Gateway:Data:MaxIterations6Query attempts per turn before the run fails with 422.
Gateway:Data:CacheTtlSeconds120Schema + grant cache TTL per (dataset, user). 0 disables — useful while editing grants.
Gateway:Data:NegativeCacheSeconds30How long "not accessible" is remembered, so a wrong id does not hammer the data app.
Gateway:Data:CacheMaxEntries500Schema cache size cap.
Gateway:Data:SchemaMaxChars24000Prompt budget for the schema block; past it the prompt switches to a table index.
Gateway:Data:IndexColumnPreview8Columns previewed per table in index mode.
Gateway:Data:UserIdHeaderX-Relay-User-IdHeader naming the acting end user. X-User-Id is always accepted as a fallback. Named under Data: because dataset agents introduced it, but it is Relay's single acting-user header — a non-public agent's audience check reads the same one.
Gateway:Data:CatalogUserId—Data-app identity used only to populate the panel's dataset picker.
Gateway:Data:AllowInvalidCertificatesfalseAccept the data app's self-signed dev certificate. Honoured only in Development.

#Batch & eval processors

KeyDefaultPurpose
Gateway:BatchPollSeconds10Batch queue poll interval.
Gateway:BatchConcurrency4 (1–32)Batch row concurrency.
Gateway:EvalPollSeconds10Eval queue poll interval.
Gateway:EvalConcurrency4 (1–32)Eval case concurrency.

#Health probing & alerting

KeyDefaultPurpose
Gateway:HealthProbe:EnabledfalseActively probe providers.
Gateway:HealthProbe:IntervalSeconds60Probe interval.
Gateway:HealthProbe:TimeoutSeconds5Probe timeout.
Gateway:HealthProbe:AlertThreshold2Consecutive failures before alert.
Gateway:HealthProbe:WebhookUrl—Slack-compatible alert webhook.
Gateway:HealthProbe:AlertEmail—Alert recipient.
Gateway:HealthProbe:Smtp:Host / Port / UseSsl / From / User / Password587 / trueSMTP for email alerts.
Gateway:Alerts:EnabledfalseTelemetry-threshold alerting.
Gateway:Alerts:IntervalSeconds300Alert evaluation interval.
Gateway:Alerts:WindowMinutes15Look-back window.
Gateway:Alerts:ErrorRatePercent10Error-rate threshold.
Gateway:Alerts:P95LatencyMs0 (off)p95 latency threshold.

#Telemetry & OTLP

KeyDefaultPurpose
ClickHouse:ConnectionString—Observability store (read/write). Set on the gateway and the panel. Empty = no telemetry.
ClickHouse:ObservationTable / ScoreTablerelay_observation / relay_scoreTable names (created and evolved at startup).
ClickHouse:FlushIntervalMs / BatchSize / Capacity1000 / 500 / 10000Writer batching; events are dropped (never blocking) when the buffer is full.
ClickHouse:QueryTimeoutSeconds30Panel/API query timeout.
Telemetry:DashboardSource—otel reads the usage dashboard from the collector's otel_traces table instead of relay_observation.
Telemetry:Backend—Legacy; observations are always written when ClickHouse is configured. OTLP export is Gateway:Otlp:Enabled.
Telemetry:Capture:DefaultmetadataBody capture when a workspace has no setting: none, metadata, full.
Telemetry:Capture:RedactPiitrueDefault PII redaction of captured text.
Telemetry:Capture:MaxBodyChars20000Default per-field cap on captured text.
Telemetry:RetentionDays / BodyRetentionDays0 / 30Default row and captured-text retention (0 = keep).
Telemetry:SettingsCacheSeconds60How long the gateway caches a workspace's observability settings.
Telemetry:Panel:ShowBodiestrueHide captured text in the panel (metrics still show).
Gateway:Stream:IncludeUsagetrueAsk OpenAI-compatible providers for streamed token usage.
Gateway:EvaluatorPollSeconds / EvaluatorLagSeconds60 / 30LLM-judge evaluator cycle, and how far behind "now" it reads.
Gateway:AlertRules:IntervalSeconds60Workspace alert-rule evaluation interval.
Gateway:EndUserBudgetCacheSeconds30End-user budget cache on the request path.
Gateway:Otlp:EnabledfalseEnable OTLP export.
Gateway:Otlp:Endpointhttp://localhost:4318/v1/tracesTraces endpoint (logs/metrics derived).
Gateway:Otlp:LogsEndpoint / MetricsEndpointderivedOverride the derived endpoints.
Gateway:Otlp:ServiceNamerelay-gatewayService name on emitted signals.
Gateway:Otlp:ApiKey—HyperDX ingestion key (Authorization header).
Gateway:Otlp:MetricsIntervalSeconds30Metrics export interval.

#Secrets

KeyPurpose
Encryption:MasterKeyAES-256-GCM key for at-rest secrets in the DB.
config[<SecretRef>]Each provider's API key, resolved by the SecretRef name stored on the Provider row.