SousLeSens configuration#
SouslesensVocables configuration is stored on the config directory.
(under ${DATA_ROOT_DIR}/souslesens/vocables if deployed with docker).
mainConfig.json#
The mainConfig.json contain all the souslesensVocables configuration.
souslesensUrl: the public URL of SousLeSens, with protocol and port.souslesensUrlForVirtuoso: the URL of SousLeSens, from Virtuoso. It’s used to pull RDF data from the SousLeSens server.listenPort: The listen port of SousLeSens.serverUrl: The base URL used to build the graph traversal queries.theme: the UI theme of SousLeSensselector: Display a selector to choose the UI themedefaultTheme: Set the fallback theme
auth: The authentication mechanisme. Can belocal,keycloak,auth0,databaseordisabledcookieSameSite: The value of theSameSiteattribute of the session cookiescookieSecure: Mark the session cookies asSecure(sent over HTTPS only)cookieSecureTrustProxy: Trust theX-Forwarded-Protoheader to set theSecureflag behind a reverse proxycookieMaxAge: The lifetime of the session cookies, in millisecondsdefaultGroups: The groups assigned by default to the userslogs: The logger configuration for the serverdirectory: The path to the directory where the log files are storeduseFileLogger: Set tofalseto disable the file logger and the writing on the filesystemuseSymlink: Set tofalseto disable the creation of symlinks in the logs directory. Useful for the operating system which have a hard time to manage them.
default_lang: The default language of the application, used for the SPARQL queries and labelssentryDsnNode: The sentry DSN for the serversentryDsnJsFront: The sentry DSN for the clientformalOntologySourceLabel: The label of the formal ontology source, added as read-only to the userstools_available: The list of available tools. Values:lineage,KGcreator,KGquery,admin,ConfigEditor,GraphManagement,UserSettings,OntoCreatorauth0: Ifauthis set toauth0, the auth0 configuration.domain: theauth0domainclientID: Auth0 clientIDclientSecret: Auth0 clientSecretscope: Auth0 scope. Set it toopenid email profileapi: Auth0 API configurationclientID: Auth0 API clientIDclientSecret: Auth0 API clientSecret
usernameMapping: The Auth0 field used as the login. Can beemail,nicknameornameuseAuth0Roles: Set totrueto use the Auth0 roles as SLS groups
keycloak: Ifauthis set tokeycloak, the KeyCloak configurationrealm: The KeyCloak realmpublicClient:trueif the client is publicclientID: The KeyCloak clientIDclientSecret: The KeyCloak clientSecretauthServerURL: The public URL of the KeyCloak server
health_enabled_services: The services checked by the/api/v1/healthendpoint. Default:virtuoso,elasticsearch,spacyserversparql_server: The SPARQL server configuration (Virtuoso)url: The url of the SPARQL server, with protocol and port and pathuser: Virtuoso userpassword: Virtuoso password
ElasticSearch: The Elasticsearch server configurationCompatibility: Only Elasticsearch 8.x is supported. Elasticsearch 7 and earlier versions are not compatible.
url: The ElasticSearch URL, with protocol and portuser: The ElasticSearch userpassword: The ElasticSearch passwordskipSslVerify: Set totrueto skip SSL verify (with self-signed certs)other_servers: List of other ElasticSearch nodessearchChunkSize: Size of chunk for the indices search
Note: Elasticsearch 8 enables security (SSL/TLS + authentication) by default. For development environments, you can disable it by setting
xpack.security.enabled: falsein your docker-compose configuration.jowlServer:enabled:trueif the JOWL server is enabledurl: The JOWL URL, with protocol and port
slsPyApi: sls-py-api configurationenabled:trueif sls-py-api is enabledurl: The url of sls-py-api (with protocol and port)
llm: The LLM provider configuration used by AI features.provider: Active provider. Supported values:anthropic,openrouter,ollama.<provider>: Provider-specific settings. The section name must matchprovider.
database: The database configuration used to store the usersuser: The database userpassword: The database passwordhost: The database hostdatabase: The database nameport: The database port
annotator: The annotator configuration (optional)tikaServerUrl: The URL of the Apache Tika serverspacyServerUrl: The URL of the spaCy serverparsedDocumentsHomeDir: The home directory of the parsed documents.nullto disable.uploadDirPath: The path of the upload directory.nullto disable.
wiki: The wiki configurationurl: The wiki URL, with protocol and port
userData: The configuration of the userData file management systemlocation: the system used to store the file content (fileordatabase)maximumFileSize: the maximum file content size allowed in the database (in bytes)
sparqlDownloadLimit: The maximum number of rows per page when downloading SPARQL results from the/api/v1/rdf/graphendpoints. Maximum1000000.generalQuota: The general quotas per API route and HTTP method. A mapping of{ route: { method: number } }, for example{ "source": { "GET": 10 } }.metrics: The server metrics configurationenabled: Set totrueto expose the metricsauth: The basic authentication protecting the/metricsendpointenabled:trueto enable the basic authenticationusername: The usernamepassword: The password
virtuoso: The Virtuoso load protection settings. These back therestrictVirtuosoLoadsecurity handler, which answers429to the heavy SPARQL/RDF endpoints once the estimated load crosses a threshold.maxPending: Number of in-flight SPARQL requests above which the estimated load is considered to be 100%. The load ratio ispending / maxPending × 100, capped at 100. Default50.maxLoad: Global load threshold (0-100), in percent, above which protected endpoints answer429. It applies to users whose profiles define nomaxVirtuosoLoad(see rights-and-quotas). Default80.
Note:
maxPendinghere is the scale the estimated load is measured against, not the threshold that triggers the refusal; the refusal threshold ismaxLoad.
LLM provider configuration#
The AI integration is configured in config/mainConfig.json under the llm section. SLS reads and
validates this section at startup from model/config.js, then bin/AI/llmClient.js selects the
adapter matching llm.provider.
Only one provider is active at a time:
{
"llm": {
"provider": "anthropic",
"anthropic": {
"apiKey": "sk-ant-api03-...",
"defaultModel": "claude-sonnet-4-6",
"maxTokens": 1024,
"rateLimitTPM": 28000
}
}
}
Supported providers:
Provider |
Required settings |
Optional settings |
|---|---|---|
|
|
|
|
|
|
|
|
|
Defaults are defined in model/config.js. ollama.baseUrl defaults to http://localhost:11434.
maxTokens is the ceiling on what the model may produce in a single turn, and it is the only
authority on that: POST /api/v1/ai/complete clamps any value a caller asks for down to it, so the
chat panel and any other client answer within the limit set here. It defaults to 1024, which cuts
long answers off mid-sentence, and its maximum is 32768. When a turn does hit the ceiling the answer
comes back with stopReason: "max_tokens" and the applied maxTokens, and the chat panel says so
under the truncated text.
API key encryption#
LLM API keys can be stored encrypted in mainConfig.json. The server decrypts values prefixed with
enc:v1: when SLS_SECRET_KEY is set.
To print an encrypted key:
$env:SLS_SECRET_KEY = "my-passphrase"
node bin/AI/encryptKey.js sk-ant-api03-...
To encrypt the current llm.<provider>.apiKey in place:
$env:SLS_SECRET_KEY = "my-passphrase"
node bin/AI/encryptKey.js --in-place
The same SLS_SECRET_KEY must be available when the SLS server starts.