{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://raw.githubusercontent.com/api-evangelist/portainer/main/json-schema/portainer-portainer-settings-schema.json", "title": "portainer.Settings", "x-generated": "2026-10-03", "x-method": "derived", "x-generator": "derive-json-schema.py", "x-source": "openapi/portainer-settings-api-openapi.yml#/components/schemas/portainer.Settings", "properties": { "AgentSecret": { "description": "Container environment parameter AGENT_SECRET", "type": "string" }, "AllowBindMountsForRegularUsers": { "type": "boolean" }, "AllowContainerCapabilitiesForRegularUsers": { "type": "boolean" }, "AllowDeviceMappingForRegularUsers": { "type": "boolean" }, "AllowHostNamespaceForRegularUsers": { "type": "boolean" }, "AllowPrivilegedModeForRegularUsers": { "type": "boolean" }, "AllowStackManagementForRegularUsers": { "type": "boolean" }, "AllowVolumeBrowserForRegularUsers": { "type": "boolean" }, "AuthenticationMethod": { "allOf": [ { "$ref": "#/$defs/portainer.AuthenticationMethod" } ], "description": "Active authentication method for the Portainer instance. Valid values are: 1 for internal, 2 for LDAP, or 3 for oauth" }, "BlackListedLabels": { "description": "A list of label name & value that will be used to hide containers when querying containers", "items": { "$ref": "#/$defs/portainer.Pair" }, "type": "array" }, "DisplayDonationHeader": { "description": "Deprecated fields", "type": "boolean" }, "DisplayExternalContributors": { "type": "boolean" }, "Edge": { "$ref": "#/$defs/portainer.Edge" }, "EdgeAgentCheckinInterval": { "description": "The default check in interval for edge agent (in seconds)", "type": "integer" }, "EdgePortainerUrl": { "description": "EdgePortainerURL is the URL that is exposed to edge agents", "type": "string" }, "EnableEdgeComputeFeatures": { "description": "Whether edge compute features are enabled", "type": "boolean" }, "EnableHostManagementFeatures": { "description": "Deprecated fields v26", "type": "boolean" }, "EnforceEdgeID": { "description": "EnforceEdgeID makes Portainer store the Edge ID instead of accepting anyone", "type": "boolean" }, "FeatureFlagSettings": { "additionalProperties": { "type": "boolean" }, "type": "object" }, "GlobalDeploymentOptions": { "allOf": [ { "$ref": "#/$defs/portainer.GlobalDeploymentOptions" } ], "description": "Deployment options for encouraging git ops workflows" }, "HelmRepositoryURL": { "description": "Helm repository URL, defaults to \"https://charts.bitnami.com/bitnami\"", "type": "string" }, "InternalAuthSettings": { "$ref": "#/$defs/portainer.InternalAuthSettings" }, "IsDockerDesktopExtension": { "type": "boolean" }, "KubeconfigExpiry": { "description": "The expiry of a Kubeconfig", "type": "string" }, "KubectlShellImage": { "description": "KubectlImage, defaults to portainer/kubectl-shell", "type": "string" }, "LDAPSettings": { "$ref": "#/$defs/portainer.LDAPSettings" }, "LogoURL": { "description": "URL to a logo that will be displayed on the login page as well as on top of the sidebar. Will use default Portainer logo when value is empty string", "type": "string" }, "OAuthSettings": { "$ref": "#/$defs/portainer.OAuthSettings" }, "SnapshotInterval": { "description": "The interval in which environment(endpoint) snapshots are created", "type": "string" }, "TemplatesURL": { "description": "URL to the templates that will be displayed in the UI when navigating to App Templates", "type": "string" }, "TrustOnFirstConnect": { "description": "TrustOnFirstConnect makes Portainer accepting edge agent connection by default", "type": "boolean" }, "UserSessionTimeout": { "description": "The duration of a user session", "type": "string" }, "openAMTConfiguration": { "$ref": "#/$defs/portainer.OpenAMTConfiguration" } }, "type": "object", "$defs": { "oauth2.AuthStyle": { "enum": [ 0, 1, 2 ], "type": "integer", "x-enum-varnames": [ "AuthStyleAutoDetect", "AuthStyleInParams", "AuthStyleInHeader" ] }, "portainer.AuthenticationMethod": { "enum": [ 0, 1, 2, 3 ], "type": "integer", "x-enum-varnames": [ "_", "AuthenticationInternal", "AuthenticationLDAP", "AuthenticationOAuth" ] }, "portainer.Edge": { "properties": { "AsyncMode": { "description": "Deprecated 2.18", "type": "boolean" }, "CommandInterval": { "description": "The command list interval for edge agent - used in edge async mode (in seconds)", "type": "integer" }, "PingInterval": { "description": "The ping interval for edge agent - used in edge async mode (in seconds)", "type": "integer" }, "SnapshotInterval": { "description": "The snapshot interval for edge agent - used in edge async mode (in seconds)", "type": "integer" } }, "type": "object" }, "portainer.GlobalDeploymentOptions": { "properties": { "hideStacksFunctionality": { "type": "boolean" } }, "type": "object" }, "portainer.InternalAuthSettings": { "properties": { "RequiredPasswordLength": { "type": "integer" } }, "type": "object" }, "portainer.LDAPGroupSearchSettings": { "properties": { "GroupAttribute": { "description": "LDAP attribute which denotes the group membership", "type": "string" }, "GroupBaseDN": { "description": "The distinguished name of the element from which the LDAP server will search for groups", "type": "string" }, "GroupFilter": { "description": "The LDAP search filter used to select group elements, optional", "type": "string" } }, "type": "object" }, "portainer.LDAPSearchSettings": { "properties": { "BaseDN": { "description": "The distinguished name of the element from which the LDAP server will search for users", "type": "string" }, "Filter": { "description": "Optional LDAP search filter used to select user elements", "type": "string" }, "UserNameAttribute": { "description": "LDAP attribute which denotes the username", "type": "string" } }, "type": "object" }, "portainer.LDAPSettings": { "properties": { "AnonymousMode": { "description": "Enable this option if the server is configured for Anonymous access. When enabled, ReaderDN and Password will not be used", "type": "boolean" }, "AutoCreateUsers": { "description": "Automatically provision users and assign them to matching LDAP group names", "type": "boolean" }, "GroupSearchSettings": { "items": { "$ref": "#/$defs/portainer.LDAPGroupSearchSettings" }, "type": "array" }, "Password": { "description": "Password of the account that will be used to search users", "type": "string" }, "ReaderDN": { "description": "Account that will be used to search for users", "type": "string" }, "SearchSettings": { "items": { "$ref": "#/$defs/portainer.LDAPSearchSettings" }, "type": "array" }, "StartTLS": { "description": "Whether LDAP connection should use StartTLS", "type": "boolean" }, "TLSConfig": { "$ref": "#/$defs/portainer.TLSConfiguration" }, "URL": { "description": "URL or IP address of the LDAP server", "type": "string" } }, "type": "object" }, "portainer.OAuthSettings": { "properties": { "AccessTokenURI": { "type": "string" }, "AuthStyle": { "$ref": "#/$defs/oauth2.AuthStyle" }, "AuthorizationURI": { "type": "string" }, "ClientID": { "type": "string" }, "ClientSecret": { "type": "string" }, "DefaultTeamID": { "type": "integer" }, "KubeSecretKey": { "items": { "type": "integer" }, "type": "array" }, "LogoutURI": { "type": "string" }, "OAuthAutoCreateUsers": { "type": "boolean" }, "RedirectURI": { "type": "string" }, "ResourceURI": { "type": "string" }, "SSO": { "type": "boolean" }, "Scopes": { "type": "string" }, "UserIdentifier": { "type": "string" } }, "type": "object" }, "portainer.OpenAMTConfiguration": { "properties": { "certFileContent": { "type": "string" }, "certFileName": { "type": "string" }, "certFilePassword": { "type": "string" }, "domainName": { "type": "string" }, "enabled": { "type": "boolean" }, "mpsPassword": { "type": "string" }, "mpsServer": { "type": "string" }, "mpsToken": { "description": "retrieved from API", "type": "string" }, "mpsUser": { "type": "string" } }, "type": "object" }, "portainer.Pair": { "properties": { "name": { "type": "string" }, "value": { "type": "string" } }, "type": "object" }, "portainer.TLSConfiguration": { "properties": { "TLS": { "description": "Use TLS", "type": "boolean" }, "TLSCACert": { "description": "Path to the TLS CA certificate file", "type": "string" }, "TLSCert": { "description": "Path to the TLS client certificate file", "type": "string" }, "TLSKey": { "description": "Path to the TLS client key file", "type": "string" }, "TLSSkipVerify": { "description": "Skip the verification of the server TLS certificate", "type": "boolean" } }, "type": "object" } } }