Client environment configuration reference
For how to use these variables with TOML configuration files and profiles, see Environment configuration.
Environment variables configure how a Temporal Client or the Temporal CLI connects to the Temporal Service. Most variables have a matching key in a TOML configuration file and a matching CLI flag.
When the same setting comes from more than one source, the client uses the first one it finds in this order:
- A CLI flag passed on the command line.
- An environment variable.
- A value in a TOML configuration file.
Each variable on this page lists its TOML key, its CLI flag, and the clients that read it.
Read by: every client means every SDK and the Temporal CLI.
Configuration file variables
TEMPORAL_CONFIG_FILE
Path to the TOML configuration file.
The default is temporal.toml in a platform-specific directory.
- TOML key: none
- CLI flag:
--config-file - Read by: every client
TEMPORAL_PROFILE
Name of the configuration profile to load.
The default is default.
- TOML key: none
- CLI flag:
--profile - Read by: every client
Connection variables
TEMPORAL_ADDRESS
Host and port of the Temporal Frontend Service, such as localhost:7233.
- TOML key:
profile.<name>.address - CLI flag:
--address - Read by: every client
TEMPORAL_NAMESPACE
Temporal Namespace to connect to.
- TOML key:
profile.<name>.namespace - CLI flag:
--namespace - Read by: every client
TEMPORAL_API_KEY
API key for authentication. When you set an API key, the client enables TLS by default.
- TOML key:
profile.<name>.api_key - CLI flag:
--api-key - Read by: every client
TEMPORAL_CLIENT_AUTHORITY
Overrides the :authority gRPC header.
Only the Go SDK reads this variable.
The Temporal CLI has a global --client-authority flag, but the flag doesn't read this variable or the TOML key.
- TOML key:
profile.<name>.authority - CLI flag: none
- Read by: Go
TLS variables
TEMPORAL_TLS
Set to true to enable TLS or false to disable it.
The TOML key inverts the value, so disabled = true turns TLS off.
- TOML key:
profile.<name>.tls.disabled - CLI flag:
--tls - Read by: every client
TEMPORAL_TLS_CLIENT_CERT_PATH
Path to the client's public TLS certificate.
Don't set it together with TEMPORAL_TLS_CLIENT_CERT_DATA.
- TOML key:
profile.<name>.tls.client_cert_path - CLI flag:
--tls-cert-path - Read by: every client
TEMPORAL_TLS_CLIENT_CERT_DATA
PEM data for the client's public TLS certificate.
Don't set it together with TEMPORAL_TLS_CLIENT_CERT_PATH.
- TOML key:
profile.<name>.tls.client_cert_data - CLI flag:
--tls-cert-data - Read by: every client
TEMPORAL_TLS_CLIENT_KEY_PATH
Path to the client's private TLS key.
Don't set it together with TEMPORAL_TLS_CLIENT_KEY_DATA.
- TOML key:
profile.<name>.tls.client_key_path - CLI flag:
--tls-key-path - Read by: every client
TEMPORAL_TLS_CLIENT_KEY_DATA
PEM data for the client's private TLS key.
Don't set it together with TEMPORAL_TLS_CLIENT_KEY_PATH.
- TOML key:
profile.<name>.tls.client_key_data - CLI flag:
--tls-key-data - Read by: every client
TEMPORAL_TLS_SERVER_CA_CERT_PATH
Path to the Certificate Authority (CA) certificate that verifies the server.
Don't set it together with TEMPORAL_TLS_SERVER_CA_CERT_DATA.
- TOML key:
profile.<name>.tls.server_ca_cert_path - CLI flag:
--tls-ca-path - Read by: every client
TEMPORAL_TLS_SERVER_CA_CERT_DATA
PEM data for the CA certificate that verifies the server.
Don't set it together with TEMPORAL_TLS_SERVER_CA_CERT_PATH.
- TOML key:
profile.<name>.tls.server_ca_cert_data - CLI flag:
--tls-ca-data - Read by: every client
TEMPORAL_TLS_SERVER_NAME
Overrides the server name sent for Server Name Indication (SNI) in the TLS handshake.
- TOML key:
profile.<name>.tls.server_name - CLI flag:
--tls-server-name - Read by: every client
TEMPORAL_TLS_DISABLE_HOST_VERIFICATION
Set to true to skip verifying the server's hostname against its certificate.
This exposes the connection to man-in-the-middle attacks, so use it only for testing.
Not every SDK applies this setting.
- TOML key:
profile.<name>.tls.disable_host_verification - CLI flag:
--tls-disable-host-verification - Read by: every client
gRPC metadata variables
TEMPORAL_GRPC_META_*
Sets a gRPC header on every request.
The part of the name after _META_ becomes the header key, lowercased with underscores replaced by hyphens.
For example, TEMPORAL_GRPC_META_SOME_KEY sets the some-key header.
- TOML key:
profile.<name>.grpc_meta - CLI flag:
--grpc-meta - Read by: every client except CLI
Codec Server variables
TEMPORAL_CODEC_ENDPOINT
Endpoint of a remote Codec Server. SDKs that read this variable don't apply the codec by default, so set it mainly for the Temporal CLI.
- TOML key:
profile.<name>.codec.endpoint - CLI flag:
--codec-endpoint - Read by: every client except Java
TEMPORAL_CODEC_AUTH
Authorization header value sent to the remote Codec Server.
- TOML key:
profile.<name>.codec.auth - CLI flag:
--codec-auth - Read by: every client except Java
temporal env preset variables
The Temporal CLI has a second configuration mechanism alongside TOML configuration files.
temporal env stores named key-value presets in temporal.yaml.
The variables in this section select which preset the CLI reads.
Both mechanisms work.
The temporal config command that manages TOML configuration files is experimental, and temporal env is not.
TEMPORAL_ENV
Name of the active temporal env preset.
The default is default.
- TOML key: none
- CLI flag:
--env - Read by: Temporal CLI
TEMPORAL_ENV_FILE
Path to the preset file.
The default is temporal.yaml in the CLI configuration directory.
- TOML key: none
- CLI flag:
--env-file - Read by: Temporal CLI
Legacy TLS variables
The Temporal CLI still reads an older set of TLS variable names. A legacy variable overrides the matching value from the configuration file and from the current variable. Legacy variables have no CLI flag or TOML key of their own. Use the current variable named in each entry instead.
TEMPORAL_TLS_CERT
Superseded by TEMPORAL_TLS_CLIENT_CERT_PATH.
- Read by: Temporal CLI
TEMPORAL_TLS_CERT_DATA
Superseded by TEMPORAL_TLS_CLIENT_CERT_DATA.
- Read by: Temporal CLI
TEMPORAL_TLS_KEY
Superseded by TEMPORAL_TLS_CLIENT_KEY_PATH.
- Read by: Temporal CLI
TEMPORAL_TLS_KEY_DATA
Superseded by TEMPORAL_TLS_CLIENT_KEY_DATA.
- Read by: Temporal CLI
TEMPORAL_TLS_CA
Superseded by TEMPORAL_TLS_SERVER_CA_CERT_PATH.
- Read by: Temporal CLI
TEMPORAL_TLS_CA_DATA
Superseded by TEMPORAL_TLS_SERVER_CA_CERT_DATA.
- Read by: Temporal CLI