Settings API
Settings API
Backs the Settings page: a small, explicitly allowlisted subset of the server's configuration can be read and overridden at runtime. Overrides are stored in Ciaren's database, applied to the running server immediately, and re-applied on every startup — so they take precedence over environment variables until reset. See Advanced Setup for which settings are editable and why the rest are environment-only.
| Method | Path | Description |
|---|---|---|
GET | /api/settings | List every editable setting with metadata and its effective value |
PUT | /api/settings/{key} | Set an override: {"value": …} |
DELETE | /api/settings/{key} | Remove the override, falling back to env/default (idempotent) |
Each item carries the UI metadata and current state:
{
"key": "MAX_UPLOAD_SIZE_MB",
"env_var": "CIAREN_MAX_UPLOAD_SIZE_MB",
"label": "Max upload size (MB)",
"description": "Largest dataset file the upload endpoint accepts.",
"category": "Datasets",
"value_type": "integer",
"choices": null,
"min_value": 1,
"max_value": 10240,
"restart_required": false,
"value": 250,
"source": "override",
"default_value": 100,
"env_value": 100
}
valueis the effective value;sourcesays where it comes from (override>env>default).env_valueis what aDELETEwould restore (the environment variable if set, else the built-in default).env_varnames the environment variable the setting maps to. While an override exists, editing that variable has no effect — the override wins until it is deleted.value_typeisinteger(withmin_value/max_value),select(withchoices), orurl(http/https, empty string to disable; no current setting uses it).restart_required: truemarks values consumed once at startup (e.g.SCHEDULER_MAX_CONCURRENT_RUNSsizes the worker pool); the override is saved immediately but only fully applies after a restart.
Writes are validated server-side: an unknown or non-editable key (secrets,
security guards, bootstrap values) is a 404; a value of the wrong type, out
of range, or not among choices is a 400 and changes nothing. Values never
include secrets — the editable set contains none by design.
Like the rest of /api, these endpoints honour the optional
CIAREN_API_TOKEN gate and the
browser-origin (CSRF) guard.