Configuration reference
sesame reads its settings from an environment file when it starts. This page lists every setting the app reads, with its meaning, its default, the values it accepts and whether it is required. It also lists the settings of the deploy tools. It is for the person who runs the server. The deploy guide tells you when to set each one: Deploy and run sesame.How the settings are read
Secret marks a value that must stay on the server. Do not paste it into a chat, a ticket,
an email or an AI agent session, and do not commit it. The app never writes a secret to its
log, its errors or its API.
The settings you must fill in
To connect your Polymarket account
Add these settings after the server passes its security checks, as in Go live. To create the Session Key, follow Session Key setup.Settings you may want to change
Risk ceilings
Each risk limit in the app’s Settings has a ceiling, set here. The limit that applies is the lower of the two. Settings refuses to save a limit above its ceiling and showsCeiling <value> under each field.
- None of these settings is required.
- Write an amount without separators:
50000, not50,000. It can have up to 6 decimal places. - A ceiling of
0blocks every order of that kind. - You can set a ceiling below a limit that is saved in Settings. The app uses the ceiling from the next start.
- To raise a limit in Settings, the app asks for your login password.
- The live verification gives values for a first live run.
Rules checked at start
If a setting breaks one of these rules, the app does not start. Its log names the setting and the rule. What to do next is in troubleshooting.-
Single quotes around a value with
$.UI_PASSWORD_HASHneeds them. Without them, the parts after each$are replaced and the value breaks. -
Telegram: both or neither. Set
TELEGRAM_BOT_TOKENandTELEGRAM_CHAT_IDtogether, or leave both empty. -
The wallet goes with the key. A Session Key or CLOB credentials need
POLYMARKET_WALLET_ADDRESS. -
Never the owner. The Session Key’s address,
POLYMARKET_SIGNER_ADDRESSand the wallet address must all differ fromPOLYMARKET_OWNER_ADDRESS. The wallet address must also differ from the Session Key’s address. -
CLOB credentials: all three or none. With CLOB credentials and no Session Key,
POLYMARKET_SIGNER_ADDRESSis required. With a Session Key,POLYMARKET_SIGNER_ADDRESSmust be that key’s address. -
The cookie setting matches the origin.
COOKIE_SECUREistruewhenSESAME_PUBLIC_ORIGINstarts withhttps, andfalsewhen it starts withhttp. -
The fake venue is for development only.
SESAME_FAKE_VENUE=1needs a development build. It is refused withLIVE_TRADING=true, with a Session Key and with CLOB credentials. -
Refused settings. The app does not start while one of these lines is in the file, even
with an empty value. Delete the line.
Do not set these on the server
On the server, the filedeploy/compose.yaml sets the settings in the table below that have a
value in the On the server column. Those values override sesame.env, so a value you write
there has no effect. The deploy also refuses to start while sesame.env sets a proxy
variable.
Advanced and developer-only
Leave these settings out on the server unless a row says otherwise.Polymarket credentials and endpoints
Note: an endpoint must use the scheme of its default (
https or wss). It must have no user
name or password, and its host must be polymarket.com or a subdomain of it. Change an
endpoint only if Polymarket moves it before a new release of the app does.
Server and development
Settings of the deploy tools
These settings are not insesame.env. The deploy scripts read them, not the app. None of
them is a secret.
Your computer: deploy/.deploy.env
Copy deploy/deploy.env.example to deploy/.deploy.env, or set the same names in the shell.
A value in the shell wins. First deploy, step 1
tells you when to fill them in.
The server: /etc/sesame/deploy.conf
The file is owned by root and is readable by all users. The deploy refuses a line with any
other name.
The deploy writes
/opt/sesame/.env for Docker Compose. It holds DOMAIN, ACME_EMAIL,
SESAME_IMAGE_TAG and SESAME_PREVIOUS_IMAGE_TAG. Do not edit it.