This reference uses the Replicated 0.70 configuration as its baseline. Available options and defaults depend on your installed release. Some fields appear only after you enable their parent feature or select a provider. Check your installed release and its release notes before using a setting described here. A field documented here may not yet be available in an older release.
Open the Configuration Screen
- Open
https://admin.<your-base-domain>:30000. - Log in with the Admin Console password created during installation.
- Select
Config.
Apply a Configuration Change
- Update the required fields.
- Select
Save config. - Review the pending configuration change.
- Deploy the new sequence.
- On
Dashboard, wait for the application status to return toReady.
Domain Configuration
Recommended: Simple
Use the defaultSimple mode unless your organization requires a custom hostname for each service.
- Leave
Hostname Configuration Modeset toSimple (default). - Enter your
Base Domain, such asopenhands.example.com.
*.openhands.example.com cover all of them:
Installations created before the Simple layout run in
Legacy mode, which nests some hostnames deeper (auth.app.<base>, *.runtime.<base>). Keep existing installs on Legacy; their certificates and OAuth callbacks were issued for those hostnames.Customize every hostname
Customize every hostname
Select
Manual only when your DNS or network requirements do not allow the Simple layout.You must create DNS records, issue certificates, and configure external OAuth and webhook callbacks for the complete custom hostname set.
Additional CORS Origins
Additional Permitted CORS Origins is optional in either hostname mode. Enter a comma-separated list of browser origins, including the scheme and host with no path or trailing slash. The OpenHands application origin is always allowed automatically.
Certificate Configuration
LLM Configuration
Select the administrator-managed LLM provider. The Admin Console shows only the fields required by the selected provider.Provider Notes
- For Azure, deployment names must exist at the configured endpoint and API version.
- For AWS Bedrock, use an EC2 instance profile where possible. Pods must be able to reach the instance metadata service, and the role needs model invocation permissions.
- For custom OpenAI-compatible endpoints, prefix model names with
openai/. - Model lists accept one model per line.
Bring Your Own Key
EnableAllow users to configure their own LLM providers (BYOK) to let users add provider credentials and custom models in their OpenHands settings. Leave it disabled to restrict users to administrator-managed models.
LiteLLM Admin Console
LiteLLM Admin Password sets the password for the LiteLLM UI at https://<llm-proxy-hostname>/ui. The username is admin.
Changing this password restarts LiteLLM. Models added in LiteLLM appear in the OpenHands model selector after a short delay. Leave the LiteLLM Team field blank to make a model available to all users, and do not reuse a model name already configured in the Replicated LLM section.
Default OpenHands Organization
These settings are additive. Disabling them does not delete organizations, remove members, or demote users.
Keycloak Administration
UseKeycloak Admin Password to manage the existing Keycloak admin account password. Set it in the Admin Console, save, and deploy, then sign in at https://<authentication-hostname>/admin/ to manage users and identity-provider account links. Leave the field blank to keep the current password. Manage the password through Replicated so later deployments retain the intended value.
Authentication Security
Prevent Duplicate Base Emails (on by default) rejects sign-ins when another user has the same email after removing a plus-address suffix. For example, name+test@example.com matches name@example.com. Check for an existing account when investigating a rejected sign-in involving an email alias.
Authentication and Integrations
The following groups appear independently and reveal additional required fields when enabled.Bitbucket Data Center Authentication
Configure the server domain, OAuth application credentials, and bot identity used for repository operations. See Bitbucket Data Center.Azure DevOps Authentication
Configure the Microsoft Entra tenant, Azure DevOps organization, client ID, and client secret. See Azure DevOps.Jira Data Center Integration
Configure the Jira base URL, account-linking method, and either OAuth or service-account credentials. See Jira Data Center.Jira Cloud Integration
EnableEnable Jira Cloud Integration, then save and deploy. An organization administrator finishes setup under Settings → Integrations → Jira in OpenHands and registers the webhook in Jira Cloud. See Jira Cloud for service-account credentials, email matching, and webhook setup.
GitHub Authentication
Enable the GitHub App used for sign-in and repository access, then provide:GitHub App Client IDGitHub App Client SecretGitHub App IDGitHub App SlugGitHub App Webhook SecretGitHub App Private Key
GitLab Authentication
Provide the GitLab host and OAuth client credentials. Leave the host atgitlab.com for GitLab SaaS, or enter the hostname of your self-managed GitLab instance.
Enterprise SSO (SAML) Authentication
EnableEnable Enterprise SSO Authentication, provide the SAML Metadata URL, and optionally set the Identity Provider Display Name. See SAML SSO for identity-provider requirements and sign-in verification.
Slack
Provide the Slack client ID, client secret, and signing secret. After deployment, complete the OpenHands-side installation and account-linking flow. See Slack.SMTP Email Delivery
Enable SMTP to send budget alerts, administrator notifications, and Keycloak account emails for email verification, account linking, and password resets.
Match the SSL and STARTTLS options to the behavior required by your mail server.
Database Configuration
Choose the bundled PostgreSQL database or an external PostgreSQL service. For an external database, configure:- Host and port
- SSL mode
- Username and password
- Whether OpenHands should create databases automatically
- Database names for OpenHands, Keycloak, LiteLLM, Runtime API, and Automations
Sandbox Configuration
Idle Time and Deletion Time control when idle and paused conversations are
reclaimed. A single running session is additionally capped at 12 hours
regardless of these values; this maximum is not currently configurable. See
Conversations and Sandboxes for the
full conversation lifecycle.Custom Sandbox Image
EnableUse a Custom Sandbox Image to configure an image repository, tag, and optional private-registry credentials. See Custom Sandbox Images.
Proxy Configuration
Enable the HTTP proxy when outbound traffic must pass through a corporate proxy.
Prefer adding the proxy CA under
Additional Trusted CA Certificates instead of disabling TLS verification.
Troubleshooting
Log Level defaults to INFO. Use DEBUG only while investigating a problem because it produces significantly more log output. Return to INFO after collecting the necessary diagnostics.
See Troubleshooting to generate a
support bundle, inspect component logs, and open a support ticket.
Upgrade Checks
Budget policy checks run before and after upgrades. These options control whether findings block the upgrade or are recorded while it proceeds.Acknowledge does not establish that budget policy is healthy. If a strict check fails, collect the reported findings and use Troubleshooting before changing the gate mode.
Experimental
Enable Plugin Directory deploys the experimental plugin marketplace at /plugins. When enabled, configure a marketplace source beginning with github://, https://, or http://.
See Plugin Marketplace for setup and limitations.
Analytics Configuration
Enable analytics to deploy the bundled Laminar observability services. Optionally provide a Laminar project API key; an ingest-only key is recommended. See Analytics for the complete setup and verification flow. When analytics is enabled,ClickHouse Diagnostic Log Retention controls retention of ClickHouse system diagnostic tables such as trace_log, query_log, and text_log. These tables can grow quickly on busy installations. This setting controls diagnostic logs, not Laminar conversation-trace retention.
Automations
Enable Automations deploys the Automations UI and backend.
If you use external PostgreSQL, create and grant access to the Automations database before enabling this option.
Conversation Archive Delay
Conversation Archive Delay (seconds) appears when automations are enabled. It sets the delay after a run finishes before its conversation is archived and its sandbox deleted. The default is 0, which archives as soon as the run finishes. During the delay the sandbox is paused, and opening the conversation resumes it.
An archive delay longer than sandbox Deletion Time does not preserve the sandbox longer: paused sandboxes are deleted at that age regardless. See Automations for setup and run ownership.
Agent Canvas
Enable Agent Canvas deploys the conversation UI at /canvas on the application hostname and locks it to this installation’s OpenHands backend.
Advanced Options
Change advanced options only when the corresponding integration or deployment requirement is understood.
Installer-Managed Secrets
Replicated generates internal PostgreSQL, Redis, JWT, Keycloak, LiteLLM, sandbox, plugin-directory, and Automations secrets during installation. These values are intentionally hidden from the configuration screen.Related Guides
Quick Start
Install an OpenHands Enterprise VM deployment.
External PostgreSQL
Prepare and configure an external database.
Custom Sandbox Images
Build and deploy a custom agent-server image.
Analytics
Configure Laminar observability.
Troubleshooting
Collect diagnostics and inspect the deployment.

