Skip to main content

Configuration reference

sesame reads its settings from an environment file when it starts. This page lists every setting the app reads, with its meaning, its default, the values it accepts and whether it is required. It also lists the settings of the deploy tools. It is for the person who runs the server. The deploy guide tells you when to set each one: Deploy and run sesame.

How the settings are read

Secret marks a value that must stay on the server. Do not paste it into a chat, a ticket, an email or an AI agent session, and do not commit it. The app never writes a secret to its log, its errors or its API.

The settings you must fill in

To connect your Polymarket account

Add these settings after the server passes its security checks, as in Go live. To create the Session Key, follow Session Key setup.

Settings you may want to change

Risk ceilings

Each risk limit in the app’s Settings has a ceiling, set here. The limit that applies is the lower of the two. Settings refuses to save a limit above its ceiling and shows Ceiling <value> under each field.
  • None of these settings is required.
  • Write an amount without separators: 50000, not 50,000. It can have up to 6 decimal places.
  • A ceiling of 0 blocks every order of that kind.
  • You can set a ceiling below a limit that is saved in Settings. The app uses the ceiling from the next start.
  • To raise a limit in Settings, the app asks for your login password.
  • The live verification gives values for a first live run.
The other limits in Settings have fixed maximums and no setting here:

Rules checked at start

If a setting breaks one of these rules, the app does not start. Its log names the setting and the rule. What to do next is in troubleshooting.
  • Single quotes around a value with $. UI_PASSWORD_HASH needs them. Without them, the parts after each $ are replaced and the value breaks.
  • Telegram: both or neither. Set TELEGRAM_BOT_TOKEN and TELEGRAM_CHAT_ID together, or leave both empty.
  • The wallet goes with the key. A Session Key or CLOB credentials need POLYMARKET_WALLET_ADDRESS.
  • Never the owner. The Session Key’s address, POLYMARKET_SIGNER_ADDRESS and the wallet address must all differ from POLYMARKET_OWNER_ADDRESS. The wallet address must also differ from the Session Key’s address.
  • CLOB credentials: all three or none. With CLOB credentials and no Session Key, POLYMARKET_SIGNER_ADDRESS is required. With a Session Key, POLYMARKET_SIGNER_ADDRESS must be that key’s address.
  • The cookie setting matches the origin. COOKIE_SECURE is true when SESAME_PUBLIC_ORIGIN starts with https, and false when it starts with http.
  • The fake venue is for development only. SESAME_FAKE_VENUE=1 needs a development build. It is refused with LIVE_TRADING=true, with a Session Key and with CLOB credentials.
  • Refused settings. The app does not start while one of these lines is in the file, even with an empty value. Delete the line.

Do not set these on the server

On the server, the file deploy/compose.yaml sets the settings in the table below that have a value in the On the server column. Those values override sesame.env, so a value you write there has no effect. The deploy also refuses to start while sesame.env sets a proxy variable.

Advanced and developer-only

Leave these settings out on the server unless a row says otherwise.

Polymarket credentials and endpoints

Note: an endpoint must use the scheme of its default (https or wss). It must have no user name or password, and its host must be polymarket.com or a subdomain of it. Change an endpoint only if Polymarket moves it before a new release of the app does.

Server and development

Settings of the deploy tools

These settings are not in sesame.env. The deploy scripts read them, not the app. None of them is a secret.

Your computer: deploy/.deploy.env

Copy deploy/deploy.env.example to deploy/.deploy.env, or set the same names in the shell. A value in the shell wins. First deploy, step 1 tells you when to fill them in.

The server: /etc/sesame/deploy.conf

The file is owned by root and is readable by all users. The deploy refuses a line with any other name. The deploy writes /opt/sesame/.env for Docker Compose. It holds DOMAIN, ACME_EMAIL, SESAME_IMAGE_TAG and SESAME_PREVIOUS_IMAGE_TAG. Do not edit it.