Use this API to manage an instance’s appearance and application settings, and to retrieve statistics about the instance.

Changes to application settings are subject to caching and might not take effect immediately. By default, GitLab caches application settings for 60 seconds. For more information, see application cache interval.

All of these endpoints require administrator access to the instance.

Get the current appearance

GET /api/v4/application/appearance

Responses

CodeDescriptionSchema
200OKAPIEntitiesAppearance
401Unauthorized—
403Forbidden—

Modify appearance

PUT /api/v4/application/appearance

Request body (multipart/form-data)

PropertyTypeDescription
descriptionStringMarkdown text shown on the sign in / sign up page
email_header_and_footer_enabledBooleanAdd header and footer to all outgoing emails if enabled
faviconString (binary)Instance favicon in .ico/.png format
footer_messageStringMessage within the system footer bar
header_logoString (binary)Instance image used for the main navigation bar
header_messageStringMessage within the system header bar
logoString (binary)Instance image used on the sign in / sign up page
member_guidelinesStringMarkdown text shown on the members page of a group or project
message_background_colorStringBackground color for the system header / footer bar
message_font_colorStringFont color for the system header / footer bar
new_project_guidelinesStringMarkdown text shown on the new project page
profile_image_guidelinesStringMarkdown text shown on the profile page below Public Avatar
pwa_descriptionStringAn explanation of what the Progressive Web App does
pwa_iconString (binary)Icon used for Progressive Web App
pwa_nameStringName of the Progressive Web App
pwa_short_nameStringOptional, short name for Progressive Web App
site_nameStringLast part of the webpage title. Defaults to empty
titleStringInstance title on the sign in / sign up page

Responses

CodeDescriptionSchema
200OKAPIEntitiesAppearance
400Bad request—
401Unauthorized—
403Forbidden—

Retrieve application settings

GET /api/v4/application/settings

Retrieves the current application settings for this GitLab instance.

Responses

CodeDescriptionSchema
200OKAPIEntitiesApplicationSetting
401Unauthorized—
403Forbidden—

Update application settings

PUT /api/v4/application/settings

Updates the current application settings for this GitLab instance.

Request body (application/json)

PropertyTypeDescription
abuse_notification_emailStringAbuse reports will be sent to this address if it is set. Abuse reports are always available in the admin area
admin_modeBooleanRequire admin users to re-authenticate for administrative (i.e. potentially dangerous) operations
admin_notification_emailStringDeprecated: Use :abuse_notification_email instead. Abuse reports will be sent to this address if it is set. Abuse reports are always available in the admin area
after_sign_out_pathStringWe will redirect users to this page after they sign out
after_sign_up_textStringText shown after sign up
ai_action_api_rate_limitIntegerMaximum requests a user can make per 8 hours to aiAction endpoint
akismet_api_keyStringGenerate API key at http://www.akismet.com
akismet_enabledBooleanHelps prevent bots from creating issues
allow_account_deletionStringSet to true to allow users to delete their accounts. Premium and Ultimate only
allow_application_default_credentials_for_offline_transferStringAllow Google Cloud Application Default Credentials for offline transfer. Even when enabled, only administrators can use these credentials, and the bucket name must start with gitlab-offline-transfer-. Has no effect on GitLab.com. Introduced in GitLab 19.3
allow_bypass_placeholder_confirmationStringSkip confirmation when administrators reassign placeholder users. Introduced in GitLab 18.0
allow_contribution_mapping_to_adminsString—
allow_deploy_tokens_and_keys_with_external_authnString—
allow_local_requests_from_hooks_and_servicesBooleanDeprecated: Use :allow_local_requests_from_web_hooks_and_services instead. Allow requests to the local network from hooks and services
allow_local_requests_from_system_hooksStringAllow requests to the local network from system hooks
allow_local_requests_from_web_hooks_and_servicesStringAllow requests to the local network from webhooks and integrations
allow_possible_spamString—
allow_project_creation_for_guest_and_belowStringIndicates whether users assigned up to the Guest role can create groups and personal projects. Defaults to true
allow_runner_registration_tokenBooleanAllow registering runners using a registration token
allow_s3_compatible_storage_for_offline_transferStringAllow S3-compatible object storage for offline transfer. Introduced in GitLab 18.9
anonymous_searches_allowedString—
archive_builds_in_human_readableStringSet the duration for which the jobs are considered as old and expired. After that time passes, the jobs are archived and no longer able to be retried. Make it empty to never expire jobs. It has to be no less than 1 day, for example: 15 days, 1 month, 2 years
asciidoc_max_includesStringMaximum limit of AsciiDoc include directives being processed in any one document. Default: 32. Maximum: 64
asset_proxy_allowlistArray of stringsAssets that match these domain(s) will NOT be proxied. Wildcards allowed. Your GitLab installation URL is automatically allowed
asset_proxy_enabledBooleanEnable proxying of assets
asset_proxy_secret_keyStringShared secret with the asset proxy server
asset_proxy_urlStringURL of the asset proxy server
asset_proxy_whitelistArray of stringsDeprecated: Use :asset_proxy_allowlist instead. Assets that match these domain(s) will NOT be proxied. Wildcards allowed. Your GitLab installation URL is automatically whitelisted
authn_data_retention_cleanup_enabledBooleanEnable authentication data retention cleanup workers to enforce retention policies
authorized_keys_enabledStringBy default, the authorized_keys file supports Git over SSH without additional configuration. GitLab can be optimized to authenticate SSH keys via the database file. Only disable this if you have configured your OpenSSH server to use the AuthorizedKeysCommand
auto_accept_awarded_achievementsStringIf true, newly awarded achievements are accepted automatically and appear on user profiles immediately. Does not affect achievements awarded before this setting is enabled. Recipients can still hide any achievement. Default value: false. Introduced in GitLab 19.4
auto_devops_domainStringSpecify a domain to use by default for every project’s Auto Review Apps and Auto Deploy stages
auto_devops_enabledStringEnable Auto DevOps for projects by default. It automatically builds, tests, and deploys applications based on a predefined CI/CD configuration
autocomplete_users_limitIntegerRate limit for authenticated requests to users autocomplete endpoint
autocomplete_users_unauthenticated_limitIntegerRate limit for authenticated requests to users autocomplete endpoint
background_operations_max_jobsString—
block_jwt_for_reclaimed_pathsString—
bulk_import_concurrent_pipeline_batch_limitIntegerMaximum simultaneous direct transfer batch exports to process
bulk_import_enabledBooleanEnable migrating GitLab groups and projects by direct transfer
bulk_import_max_download_fileIntegerMaximum download file size in MB when importing from source GitLab instances by direct transfer
bulk_import_max_download_file_sizeStringMaximum download file size when importing from source GitLab instances by direct transfer
can_create_groupStringIndicates whether users can create top-level groups. Defaults to true
can_create_organizationString—
ci_delete_pipelines_in_seconds_limit_human_readableStringMaximum value that is allowed for configuring pipeline retention. Defaults to 1 year
ci_job_live_trace_enabledBooleanTurn on incremental logging for job logs
ci_lint_limit_per_userIntegerMaximum number of CI Lint requests allowed per minute per user. Set to 0 for unlimited requests per minute
ci_max_caches_per_jobIntegerMaximum number of caches that can be defined in a single CI/CD job
ci_max_includesIntegerMaximum number of includes per pipeline
ci_max_total_yaml_size_bytesStringThe maximum amount of memory, in bytes, that can be allocated for the pipeline configuration, with all included YAML configuration files
ci_partitions_in_seconds_limitStringThe time window, in seconds, before new CI partitions are created and the system switches to the next set of partitions. Must be between 1 month and 6 months. Default is 1 month (2592000). Write-only. Not returned in GET responses. Deprecated in favor of ci_partitions_in_seconds_limit_human_readable and is scheduled for removal in API v5
ci_partitions_in_seconds_limit_human_readableStringThe time window before new CI partitions are created and the system switches to the next set of partitions. Must be between 1 month and 6 months. Defaults to 1 month
code_dropdown_custom_clientsArray of objectsCustom “Open with” clients shown in the project Code dropdown list
code_dropdown_custom_clients[].http_url_templateStringURL template opened for the HTTPS clone URL. Must contain {url} exactly once
code_dropdown_custom_clients[].name
Required
StringName shown to users in the Code dropdown list
code_dropdown_custom_clients[].ssh_url_templateStringURL template opened for the SSH clone URL. Must contain {url} exactly once
code_suggestions_api_rate_limitIntegerMaximum requests a user can make per minute to code suggestions endpoint
commit_email_hostnameStringCustom hostname (for private commit emails)
concurrent_bitbucket_import_jobs_limitIntegerBitbucket Cloud Importer maximum number of simultaneous import jobs
concurrent_bitbucket_server_import_jobs_limitIntegerBitbucket Server Importer maximum number of simultaneous import jobs
concurrent_github_import_jobs_limitIntegerGithub Importer maximum number of simultaneous import jobs
concurrent_pull_request_import_jobs_limitIntegerMaximum number of simultaneous pull request import jobs for the GitHub, Bitbucket Cloud, and Bitbucket Server importers
concurrent_relation_batch_export_limitIntegerMaximum number of simultaneous batch export jobs to process
concurrent_relation_export_limitString—
container_expiration_policies_enable_historic_entriesStringEnable cleanup policies for all projects
container_registry_cleanup_tags_service_max_list_sizeStringThe maximum number of tags that can be deleted in a single execution of cleanup policies
container_registry_delete_tags_service_timeoutStringThe maximum time, in seconds, that the cleanup process can take to delete a batch of tags for cleanup policies
container_registry_expiration_policies_cachingStringCaching during the execution of cleanup policies
container_registry_expiration_policies_worker_capacityStringNumber of workers for cleanup policies
container_registry_token_expire_delayIntegerAuthorization token duration (minutes)
create_organization_api_limitString—
custom_http_clone_url_rootStringSet a custom Git clone URL for HTTP(S)
deactivate_dormant_usersString—
deactivate_dormant_users_periodString—
deactivation_email_additional_textString—
decompress_archive_file_timeoutIntegerDefault timeout for decompressing archived files, in seconds. Set to 0 to disable timeouts
default_artifacts_expire_inStringSet the default expiration time for each job’s artifacts
default_branch_nameStringSet the initial branch name for all projects in an instance
default_branch_protectionIntegerDetermine if developers can push to default branch
Allowed values: 0, 3, 1, 2, 4
default_branch_protection_defaultsObjectDetermine if developers can push to default branch
default_branch_protection_defaults.allow_force_pushBooleanAllow force push for all users with push access
default_branch_protection_defaults.allowed_to_mergeArray of objectsAn array of access levels allowed to merge
default_branch_protection_defaults.allowed_to_merge[].access_level
Required
IntegerA valid access level
Allowed values: 30, 40, 60, 0
default_branch_protection_defaults.allowed_to_pushArray of objectsAn array of access levels allowed to push
default_branch_protection_defaults.allowed_to_push[].access_level
Required
IntegerA valid access level
Allowed values: 30, 40, 60, 0
default_branch_protection_defaults.code_owner_approval_requiredBooleanRequire approval from code owners
default_branch_protection_defaults.developer_can_initial_pushBooleanAllow developers to initial push
default_ci_config_pathStringThe instance default CI/CD configuration file and path for new projects
default_dark_syntax_highlighting_themeStringDefault dark mode syntax highlighting theme for users who are new or not signed in. See IDs of available themes
default_group_visibilityStringThe default group visibility
Allowed values: private, internal, public
default_preferred_languageStringDefault preferred language for users who are not logged in
default_project_creationIntegerDetermine if developers can create projects in the group
Allowed values: 0, 3, 4, 1, 2
default_project_visibilityStringThe default project visibility
Allowed values: private, internal, public
default_projects_limitIntegerThe maximum number of personal projects
default_search_scopeString—
default_snippet_visibilityStringThe default snippet visibility
Allowed values: private, internal, public
default_syntax_highlighting_themeStringDefault syntax highlighting theme for users who are new or not signed in. See IDs of available themes
delay_user_account_self_deletionString—
delete_inactive_projectsStringEnable dormant project deletion. Default is false
deletion_adjourned_periodStringNumber of days to wait before deleting a project or group that is marked for deletion. Value must be between 1 and 90. Defaults to 30
deny_all_requests_except_allowedString—
dependency_management_settingsObjectDependency management settings
dependency_management_settings.security_update_scheduler_max_concurrencyIntegerMaximum number of dependency management security update scheduler jobs that run concurrently across the Sidekiq fleet
description_and_note_max_sizeIntegerMaximum work item, merge request, and vulnerability description and comment content size in bytes
diagramsnet_enabledBooleanEnable Diagrams.net
diagramsnet_urlStringThe Diagrams.net server URL
diff_max_commitsStringMaximum number of diff commits per merge request
diff_max_filesStringMaximum files in a diff
diff_max_linesStringMaximum lines in a diff
diff_max_patch_bytesStringMaximum diff patch size, in bytes
diff_max_versionsStringMaximum number of diff versions per merge request
disable_admin_oauth_scopesBooleanStop administrators from connecting to non-trusted OAuth applications
disable_feed_tokenBooleanDisable display of RSS/Atom and Calendar feed_tokens
disable_password_authentication_for_users_with_sso_identitiesStringDisable password authentication in the web interface for users with an SSO identity. This does not affect Git operations over HTTP(S). Default is false
disabled_oauth_sign_in_sourcesArray of stringsDisable certain OAuth sign-in sources
dns_rebinding_protection_enabledStringEnforce DNS-rebinding attack protection
domain_allowlistArray of stringsONLY users with e-mail addresses that match these domain(s) will be able to sign-up. Wildcards allowed. Enter multiple entries on separate lines. Ex: domain.com, *.domain.com
domain_allowlist_rawString—
domain_denylistArray of stringsUsers with e-mail addresses that match these domain(s) will NOT be able to sign-up. Wildcards allowed. Enter multiple entries on separate lines. Ex: domain.com, *.domain.com
domain_denylist_enabledBooleanEnable domain denylist for sign ups
domain_denylist_rawString—
downstream_pipeline_trigger_limit_per_project_user_shaIntegerMaximum number of downstream pipelines that can be triggered per minute (for a given project, user, and commit)
dsa_key_restrictionIntegerRestrictions on the complexity of uploaded DSA keys. A value of -1 disables all DSA keys
Allowed values: 0, 1024, 2048, 3072, -1
dynamic_client_registration_enabledString—
ecdsa_key_restrictionIntegerRestrictions on the complexity of uploaded ECDSA keys. A value of -1 disables all ECDSA keys
Allowed values: 0, 256, 384, 521, -1
ecdsa_sk_key_restrictionIntegerRestrictions on the complexity of uploaded ECDSA_SK keys. A value of -1 disables all ECDSA_SK keys
Allowed values: 0, 256, -1
ed25519_key_restrictionIntegerRestrictions on the complexity of uploaded ED25519 keys. A value of -1 disables all ED25519 keys
Allowed values: 0, 256, -1
ed25519_sk_key_restrictionIntegerRestrictions on the complexity of uploaded ED25519_SK keys. A value of -1 disables all ED25519_SK keys
Allowed values: 0, 256, -1
eks_access_key_idStringAccess key ID for the EKS integration IAM user
eks_account_idStringAmazon account ID for EKS integration
eks_integration_enabledBooleanEnable integration with Amazon EKS
eks_secret_access_keyStringSecret access key for the EKS integration IAM user
email_author_in_bodyBooleanSome email servers do not support overriding the email sender name. Enable this option to include the name of the author of the issue, merge request or comment in the email body instead
email_confirmation_settingStringEmail confirmation setting, possible values: off, soft, and hard
Allowed values: off, soft, hard
email_otp_enabledBooleanEnable Email-based one-time passwords (OTP) as a multi-factor authentication method
email_restrictionsStringRegular expression that is checked against the email used during registration
email_restrictions_enabledStringPrevent new users from creating an account by email
enable_artifact_external_redirect_warning_pageBooleanShow the external redirect page that warns you about user-generated content in GitLab Pages
enable_language_server_restrictionsBooleanEnables enforcing language server restrictions
enabled_git_access_protocolStringAllow only the selected protocols to be used for Git access
Allowed values: ssh, http, all
enforce_ci_inbound_job_token_scope_enabledString—
enforce_email_subaddress_restrictionsString—
enforce_granular_tokensString—
enforce_termsString(If enabled, requires: terms) Enforce application ToS to all users
error_tracking_api_urlString—
error_tracking_enabledString—
external_auth_client_certString(If enabled, requires: external_auth_client_key) The certificate to use to authenticate with the external authorization service
external_auth_client_keyStringPrivate key for the certificate when authentication is required for the external authorization service, this is encrypted when stored
external_auth_client_key_passStringPassphrase to use for the private key when authenticating with the external service this is encrypted when stored
external_authorization_service_default_labelStringThe default classification label to use when requesting authorization and no classification label has been specified on the project
external_authorization_service_enabledString(If enabled, requires: external_authorization_service_default_label, external_authorization_service_timeout, and external_authorization_service_url) Enable using an external authorization service for accessing projects
external_authorization_service_timeoutStringThe timeout after which an authorization request is aborted, in seconds. When a request times out, access is denied to the user. (min: 0.001, max: 10, step: 0.001)
external_authorization_service_urlStringURL to which authorization requests are directed
external_pipeline_validation_service_timeoutStringHow long to wait for a response from the pipeline validation service. Assumes OK if it times out
external_pipeline_validation_service_tokenStringOptional. Token to include as the X-Gitlab-Token header in requests to the URL in external_pipeline_validation_service_url
external_pipeline_validation_service_urlStringURL to use for pipeline validation requests
failed_login_attempts_unlock_period_in_minutesStringTime period in minutes after which the user is unlocked when maximum number of failed sign-in attempts reached
fe_application_settings_attributesObjectProvides FEApplicationSetting parameters
fe_application_settings_attributes.gitaly_pull_mirroring_timeoutInteger—
fe_application_settings_attributes.maintenance_modeBoolean—
fe_application_settings_attributes.pause_opensearch_indexingBoolean—
fe_application_settings_attributes.repository_branch_indexing_modeStringRepository branch indexing mode for OpenSearch code indexing
Allowed values: default_branch_only, allow_project_regex
fe_application_settings_attributes.use_advanced_searchBoolean—
first_day_of_weekStringStart day of the week for calendar views and date pickers. Valid values are 0 (default) for Sunday, 1 for Monday, and 6 for Saturday
floc_enabledBooleanEnable FloC (Federated Learning of Cohorts)
force_pages_access_controlString—
git_push_pipeline_limitIntegerSet the limit for pipelines and branches that can be triggered when creating a Git push. Set to 0 to disable the limit
gitaly_timeout_defaultIntegerDefault Gitaly timeout, in seconds. Set to 0 to disable timeouts
gitaly_timeout_fastIntegerGitaly fast operation timeout, in seconds. Set to 0 to disable timeouts
gitaly_timeout_mediumIntegerMedium Gitaly timeout, in seconds. Set to 0 to disable timeouts
gitlab_dedicated_instanceStringIndicates whether the instance was provisioned for GitLab Dedicated
gitlab_environment_toolkit_instanceStringIndicates whether the instance was provisioned with the GitLab Environment Toolkit for Service Ping reporting
gitlab_product_usage_data_enabledStringIndicates if product usage data collection is enabled. When the GITLAB_PRODUCT_USAGE_DATA_ENABLED environment variable is set, the API returns the effective value from the environment variable
gitlab_shell_operation_limitStringMaximum number of Git operations per minute a user can perform. Default: 600
gitpod_enabledBooleanEnable Gitpod
gitpod_urlStringThe configured Gitpod instance URL
global_search_block_anonymous_searches_enabledString—
global_search_groups_enabledString—
global_search_merge_requests_enabledString—
global_search_snippet_titles_enabledString—
global_search_users_enabledString—
global_search_work_items_enabledString—
grafana_enabledBooleanEnable Grafana
grafana_urlStringGrafana URL
granular_tokens_enforced_afterString—
gravatar_enabledBooleanFlag indicating if the Gravatar service is enabled
group_api_limitString—
group_archive_unarchive_api_limitString—
group_create_limitString—
group_download_export_limitString—
group_export_limitString—
group_import_limitString—
group_invited_groups_api_limitString—
group_projects_api_limitString—
group_runner_token_expiration_intervalIntegerToken expiration interval for group runners, in seconds
group_shared_groups_api_limitString—
groups_api_limitString—
hashed_storage_enabledStringCreate new projects using hashed storage paths: Enable immutable, hash-based paths and repository names to store repositories on disk. This prevents repositories from having to be moved or renamed when the Project URL changes and may improve disk I/O performance. (Always enabled in GitLab versions 13.0 and later, configuration is scheduled for removal in 14.0)
helm_max_packages_countString—
help_page_documentation_base_urlStringAlternate documentation pages URL
help_page_hide_commercial_contentBooleanHide marketing-related entries from help
help_page_support_urlStringAlternate support URL for help page and help dropdown
help_page_textStringCustom text displayed on the help page
hide_third_party_offersStringDo not display offers from third parties in GitLab
home_page_urlStringWe will redirect non-logged in users to this page
housekeeping_enabledBooleanEnable automatic repository housekeeping (git repack, git gc)
housekeeping_full_repack_periodIntegerNumber of Git pushes after which a full ‘git repack’ is run
housekeeping_gc_periodIntegerNumber of Git pushes after which ‘git gc’ is run
housekeeping_incremental_repack_periodIntegerNumber of Git pushes after which an incremental ‘git repack’ is run
housekeeping_optimize_repository_periodIntegerNumber of Git pushes after which Gitaly is asked to optimize a repository
html_emails_enabledBooleanBy default GitLab sends emails in HTML and plain text formats so mail clients can choose what format to use. Disable this option if you only want to send emails in plain text format
iframe_rendering_allowlistArray of stringsAllowed iframe src host[:port] entries. Enter multiple entries separated by commas or on separate lines
iframe_rendering_allowlist_rawStringRaw newline- or comma-separated list of allowed iframe src host[:port] entries
iframe_rendering_enabledBooleanAllow rendering of iframes in Markdown
import_jobs_concurrency_limitString—
import_sourcesArray of stringsEnabled sources for code import during project creation. OmniAuth must be configured for GitHub, Bitbucket, and GitLab.com
inactive_projects_delete_after_monthsStringIf delete_inactive_projects is true, the time (in months) to wait before deleting dormant projects. Default is 2
inactive_projects_min_size_mbStringIf delete_inactive_projects is true, the minimum repository size for projects to be checked for inactivity. Default is 0
inactive_projects_send_warning_email_after_monthsStringIf delete_inactive_projects is true, sets the time (in months) to wait before emailing Maintainers that the project is scheduled to be deleted because it is dormant. Default is 1
inactive_resource_access_tokens_delete_after_daysStringSpecifies retention period for inactive project and group access tokens. Default is 30
include_optional_metrics_in_service_pingStringWhether or not optional metrics are enabled in Service Ping
instance_token_prefixString—
invisible_captcha_enabledBooleanEnable Invisible Captcha spam detection during signup
invitation_flow_enforcementString—
issues_create_limitIntegerMaximum number of issue creation requests allowed per minute per user. Set to 0 for unlimited requests per minute
jira_connect_additional_audience_urlString—
jira_connect_application_keyStringID of the OAuth application used to authenticate with the GitLab for Jira Cloud app
jira_connect_proxy_urlStringURL of the GitLab instance used as a proxy for the GitLab for Jira Cloud app
jira_connect_public_key_storage_enabledBooleanEnable public key storage for the GitLab for Jira Cloud app
jira_forge_app_idStringAtlassian Forge app ID (ARI) of the GitLab for Jira Cloud app, used to verify inbound Forge Invocation Tokens
keep_latest_artifactStringPrevent the deletion of the artifacts from the most recent successful jobs, regardless of the expiry time. Enabled by default
kroki_diagram_proxy_enabledStringEnable Kroki diagram proxy. Default is false
kroki_enabledBooleanEnable Kroki
kroki_formatsStringAdditional formats supported by the Kroki instance. Possible values are true or false for formats bpmn, blockdiag, excalidraw, and mermaid in the format <format>: true or <format>: false
kroki_urlStringThe Kroki server URL
local_markdown_versionIntegerLocal markdown version, increase this value when any cached markdown should be invalidated
lock_require_sha_for_mergeStringEnforce the require_sha_for_merge setting for all groups on the instance. Introduced in GitLab 19.2
lock_resource_access_token_notify_inheritedString—
logging_field_dual_emit_targetIntegerVersion to dual-emit alongside schema_version. Must be strictly greater than schema_version, or omit/null to disable
Allowed values: 1
logging_field_schema_versionIntegerLogging field schema version (v0, v1, …). Cannot be downgraded
Allowed values: 0, 1
login_recaptcha_protection_enabledBooleanHelps prevent brute-force attacks
mailgun_events_enabledBooleanEnable Mailgun event receiver
mailgun_signing_keyStringThe Mailgun HTTP webhook signing key for receiving events from webhook
math_rendering_limits_enabledString—
max_artifacts_content_include_sizeString—
max_artifacts_sizeIntegerSet the maximum file size for each job’s artifacts
max_attachment_sizeIntegerMaximum attachment size in MB
max_decompressed_archive_sizeIntegerMaximum decompressed size in MB
max_export_sizeIntegerMaximum export size in MB
max_github_response_json_value_countIntegerMaximum allowed object count for GitHub API responses. 0 for unlimited. Count is an estimate based on the number of : , { and [ occurrences in the response
max_github_response_size_limitIntegerMaximum allowed size in MB for GitHub API responses. 0 for unlimited
max_http_decompressed_sizeStringMaximum allowed size in MiB for Gzip-compressed HTTP responses from outbound requests after decompression. 0 for unlimited
max_http_response_csv_structural_charsStringMaximum allowed object count in CSV HTTP responses from outbound requests. Count is an estimate based on the number of ,, ;, \t, and \n occurrences in the response. Introduced in GitLab 18.4
max_http_response_json_depthStringMaximum allowed nesting depth in JSON HTTP responses from outbound requests
max_http_response_json_structural_charsStringMaximum allowed object count in JSON HTTP responses from outbound requests. Count is an estimate based on the number of :, ,, {, and [ occurrences in the response. Introduced in GitLab 18.4
max_http_response_size_limitStringMaximum allowed size in MiB for HTTP responses from outbound requests. 0 for unlimited. Applicable for integrations, importers, and webhooks. Introduced in GitLab 18.4
max_http_response_xml_structural_charsStringMaximum allowed object count in XML HTTP responses from outbound requests. Count is an estimate based on the number of <, and = occurrences in the response. Introduced in GitLab 18.4
max_import_remote_file_sizeIntegerMaximum remote file size in MB for imports from external object storages
max_import_sizeIntegerMaximum import size in MB
max_login_attemptsStringMaximum number of sign-in attempts before locking out the user
max_pages_custom_domains_per_projectIntegerMaximum number of GitLab Pages custom domains per project
max_pages_sizeIntegerMaximum size of pages in MB
max_terraform_state_size_bytesIntegerMaximum size in bytes of the Terraform state file. Set this to 0 for unlimited file size
max_yaml_depthStringThe maximum depth of nested CI/CD configuration added with the include keyword. Default: 100
max_yaml_size_bytesStringThe maximum size in bytes of a single CI/CD configuration file. Default: 2097152
mcp_server_enabledString—
members_delete_limitString—
metrics_method_call_thresholdIntegerA method call is only tracked when it takes longer to complete than the given amount of milliseconds
minimum_language_server_versionStringThe minimum language server version to accept requests from
minimum_password_lengthStringIndicates whether passwords require a minimum length. Premium and Ultimate only
mirror_availableStringAllow repository mirroring to configured by project Maintainers. If disabled, only Administrators can configure repository mirroring
namespace_aggregation_schedule_lease_duration_in_secondsIntegerMaximum duration (in seconds) between refreshes of namespace statistics (Default: 300)
notes_create_limitString—
notes_create_limit_allowlist_rawString—
notify_on_unknown_sign_inStringEnable sending notification if sign in from unknown IP address happens
nuget_skip_metadata_url_validationString—
oauth_access_token_expires_inIntegerLifetime of OAuth access tokens in seconds
observability_backend_ssl_verification_enabledString—
offline_transfer_exports_enabledStringEnable exporting GitLab groups and projects by offline transfer. Introduced in GitLab 19.3
offline_transfer_imports_enabledStringEnable importing GitLab groups and projects by offline transfer. Introduced in GitLab 19.3
organization_cluster_agent_authorization_enabledString—
outbound_local_requests_allowlist_rawString—
outbound_local_requests_whitelistArray of stringsList of trusted domains or IP addresses to which local requests are allowed when local requests for webhooks and integrations are disabled
package_registry_allow_anyone_to_pull_optionStringEnable to allow anyone to pull from package registry visible and changeable
package_registry_cleanup_policies_worker_capacityStringNumber of workers assigned to the packages cleanup policies
pages_domain_verification_enabledStringRequire users to prove ownership of custom domains. Domain verification is an essential security measure for public GitLab sites. Users are required to demonstrate they control a domain before it is enabled
pages_extra_deployments_default_expiry_secondsString—
pages_unique_domain_default_enabledStringEnable unique domains by default for Pages sites to avoid cookie sharing between sites under a given namespace. Default is true
password_authentication_enabledBooleanFlag indicating if password authentication is enabled for the web interface. Mutually exclusive with password_authentication_enabled_for_web, signin_enabled
password_authentication_enabled_for_gitBooleanFlag indicating if password authentication is enabled for Git over HTTP(S)
password_authentication_enabled_for_webBooleanFlag indicating if password authentication is enabled for the web interface. Mutually exclusive with password_authentication_enabled, signin_enabled
performance_bar_allowed_group_idStringDeprecated: Use :performance_bar_allowed_group_path instead. Path of the group that is allowed to toggle the performance bar
performance_bar_allowed_group_pathStringPath of the group that is allowed to toggle the performance bar
performance_bar_enabledStringDeprecated: Pass performance_bar_allowed_group_path: nil instead. Allow enabling the performance
personal_access_token_prefixStringPrefix to prepend to all personal access tokens
pipeline_limit_per_project_user_shaIntegerMaximum number of pipeline creation requests allowed per minute per user and commit. Set to 0 for unlimited requests per minute
pipeline_limit_per_userIntegerMaximum number of pipeline creation requests allowed per minute per user. Set to 0 for unlimited requests per minute
plantuml_diagram_proxy_enabledStringEnable PlantUML diagram proxy. Default is false
plantuml_enabledBooleanEnable PlantUML
plantuml_urlStringThe PlantUML server URL
polling_interval_multiplierNumberInterval multiplier used by endpoints that perform polling. Set to 0 to disable polling
project_api_limitString—
project_create_limitString—
project_download_export_limitString—
project_export_enabledBooleanEnable project export
project_export_limitString—
project_import_limitString—
project_invited_groups_api_limitString—
project_jobs_api_rate_limitIntegerMaximum authenticated requests to /project/:id/jobs per minute
project_members_api_limitString—
project_repositories_blobs_batch_limitString—
project_runner_token_expiration_intervalIntegerToken expiration interval for project runners, in seconds
projects_api_limitString—
projects_api_rate_limit_unauthenticatedStringMaximum number of requests per 10 minutes per IP address for unauthenticated requests to the list all projects API. Default: 400. To disable throttling, set to 0
prometheus_metrics_enabledBooleanEnable Prometheus metrics
protected_ci_variablesStringCI/CD variables are protected by default
protected_paths_for_get_request_rawString—
protected_paths_rawString—
push_event_activities_limitIntegerMaximum number of changes (branches or tags) in a single push above which a bulk push event is created. Setting to 0 does not disable throttling
push_event_hooks_limitIntegerMaximum number of changes (branches or tags) in a single push above which webhooks and integrations are not triggered. Setting to 0 does not disable throttling
rate_limiting_response_textStringWhen rate limiting is enabled via the throttle_* settings, send this plain text response when a rate limit is exceeded. ‘Retry later’ is sent if this is blank
raw_blob_request_limitIntegerMaximum number of requests per minute for each raw path. Set to 0 for unlimited requests per minute
raw_blob_request_limit_unauthenticatedIntegerMaximum number of requests per minute for a raw blob for unauthenticated requests. Set to 0 for unlimited requests per minute
recaptcha_enabledBooleanHelps prevent bots from creating accounts
recaptcha_private_keyStringGenerate private key at http://www.google.com/recaptcha
recaptcha_site_keyStringGenerate site key at http://www.google.com/recaptcha
receive_max_input_sizeStringMaximum push size (MB)
reindexing_minimum_index_sizeString—
reindexing_minimum_relative_bloat_sizeString—
relation_export_batch_sizeStringThe size of each batch when exporting batched relations. Introduced in GitLab 18.2
remember_me_enabledStringEnable Remember me setting
repository_checks_enabledBooleanGitLab will periodically run ‘git fsck’ in all project and wiki repositories to look for silent disk corruption issues
repository_storages_weightedObjectStorage paths for new projects with a weighted value ranging from 0 to 100
require_admin_approval_after_user_signupBooleanRequire explicit admin approval for new signups
require_admin_two_factor_authenticationStringAllow administrators to require 2FA for all administrators on the instance
require_email_verification_on_account_lockedStringIf true, all users on the instance must verify their identity after suspicious sign-in activity is detected
require_personal_access_token_expiryBooleanFlag indicating if Personal / Group / Project access token expiry is required
require_sha_for_mergeStringInstance default that requires a valid commit sha for calls to the merge a merge request endpoint. Introduced in GitLab 19.2
require_two_factor_authenticationBooleanRequire all users to set up Two-factor authentication
resource_access_token_notify_inheritedString—
resource_usage_limitsObjectDefinition for resource usage limits enforced in Sidekiq workers
restricted_visibility_levelsArray of stringsSelected levels cannot be used by non-admin users for groups, projects or snippets. If the public level is restricted, user profiles are only visible to logged in users
root_moved_permanently_redirectionString—
rsa_key_restrictionIntegerRestrictions on the complexity of uploaded RSA keys. A value of -1 disables all RSA keys
Allowed values: 0, 1024, 2048, 3072, 4096, -1
runner_jobs_endpoints_api_limitStringMaximum number of requests per minute per job token for requests to /jobs/* requests to the runner jobs API endpoints. Default: 200. To disable throttling, set to 0. Introduced in GitLab 18.5
runner_jobs_patch_trace_api_limitStringMaximum number of requests per minute per runner token for requests to the PATCH /jobs/:id/trace runner jobs API endpoint. Default: 2000. To disable throttling, set to 0. Introduced in GitLab 18.5
runner_jobs_request_api_limitStringMaximum number of requests per minute per runner token for requests to the /jobs/request runner jobs API endpoint. Default: 2000. To disable throttling, set to 0. Introduced in GitLab 18.5
runner_token_expiration_intervalIntegerToken expiration interval for shared runners, in seconds
search_rate_limitStringMaximum number of requests per minute for performing a search while authenticated. Default: 30. To disable throttling, set to 0
search_rate_limit_allowlist_rawString—
search_rate_limit_unauthenticatedStringMaximum number of requests per minute for performing a search while unauthenticated. Default: 10. To disable throttling, set to 0
security_policy_global_group_approvers_enabledBooleanQuery scan result policy approval groups globally
security_txt_contentStringPublic security contact information made available at https://gitlab.example.com/.well-known/security.txt
sentry_clientside_dsnString—
sentry_clientside_traces_sample_rateString—
sentry_dsnString—
sentry_enabledString—
sentry_environmentString—
session_expire_delayIntegerSession duration in minutes. GitLab restart is required to apply changes
session_expire_from_initBooleanExpires sessions based off the creation date rather than last activity
shared_runners_enabledBooleanEnable shared runners for new projects
shared_runners_textStringShared runners text
show_migrate_from_jenkins_bannerBooleanEnable Jenkins migration banner
sidekiq_job_limiter_compression_threshold_bytesStringThe threshold in bytes at which Sidekiq jobs are compressed before being stored in Redis. Default: 100,000 bytes (100 KB)
sidekiq_job_limiter_limit_bytesStringThe threshold in bytes at which Sidekiq jobs are rejected. Default: 0 bytes (doesn’t reject any job)
sidekiq_job_limiter_modeStringtrack or compress. Sets the behavior for Sidekiq job size limits. Default: ‘compress’
sidekiq_timezone_overrideStringIANA timezone identifier (for example, America/Chicago) applied to all Sidekiq cron jobs. When blank, no override is applied and cron jobs use the Rails application timezone
sign_in_restrictionsStringApplication sign in restrictions
signin_enabledBooleanFlag indicating if password authentication is enabled for the web interface. Mutually exclusive with password_authentication_enabled_for_web, password_authentication_enabled
signup_enabledBooleanFlag indicating if sign up is enabled
silent_admin_exports_enabledStringEnable Silent admin exports. Default is false
silent_mode_enabledStringEnable Silent mode. Default is false
slack_app_enabledBooleanEnable the GitLab for Slack app
slack_app_idStringThe client ID of the GitLab for Slack app
slack_app_secretStringThe client secret of the GitLab for Slack app. Used for authenticating OAuth requests from the app
slack_app_signing_secretStringThe signing secret of the GitLab for Slack app. Used for authenticating API requests from the app
slack_app_verification_tokenStringThe verification token of the GitLab for Slack app. This method of authentication is deprecated by Slack and used only for authenticating slash commands from the app
snippet_size_limitStringMaximum snippet content size in bytes. Default: 52428800 Bytes (50 MB)
snowplow_app_idStringThe Snowplow site name / application id
snowplow_collector_hostnameStringThe Snowplow collector hostname
snowplow_cookie_domainStringThe Snowplow cookie domain
snowplow_database_collector_hostnameStringThe Snowplow collector for database events hostname. (for example, your-db-snowplow-collector.example.com)
snowplow_enabledBooleanEnable Snowplow tracking
sourcegraph_enabledBooleanEnable Sourcegraph
sourcegraph_public_onlyBooleanOnly allow public projects to communicate with Sourcegraph
sourcegraph_urlStringThe configured Sourcegraph instance URL
spam_check_api_keyStringAPI key used by GitLab for accessing the Spam Check service endpoint
spam_check_endpoint_enabledBooleanEnable Spam Check via external API endpoint
spam_check_endpoint_urlStringThe URL of the external Spam Check service endpoint
static_objects_external_storage_auth_tokenStringAuthentication token for the external storage linked in static_objects_external_storage_url
static_objects_external_storage_urlStringURL to an external storage for repository static objects
tags_create_limitString—
terminal_max_session_timeIntegerMaximum time for web terminal websocket connection (in seconds). Set to 0 for unlimited time
termsString(Required by: enforce_terms) Markdown content for the ToS
terraform_state_encryption_enabledBooleanEnable encryption for Terraform state files
throttle_authenticated_api_enabledString(If enabled, requires: throttle_authenticated_api_period_in_seconds and throttle_authenticated_api_requests_per_period) Enable authenticated API request rate limit. Helps reduce request volume (for example, from crawlers or abusive bots)
throttle_authenticated_api_period_in_secondsStringRate limit period (in seconds)
throttle_authenticated_api_requests_per_periodStringMaximum requests per period per user
throttle_authenticated_dependency_proxy_enabledStringIf true, enforces the authenticated dependency proxy request rate limit. Default value: false
throttle_authenticated_dependency_proxy_period_in_secondsStringRate limit period in seconds. throttle_authenticated_dependency_proxy_enabled must be true. Default value: 15
throttle_authenticated_dependency_proxy_requests_per_periodStringMaximum requests per period per user. throttle_authenticated_dependency_proxy_enabled must be true. Default value: 1000
throttle_authenticated_deprecated_api_enabledString—
throttle_authenticated_deprecated_api_period_in_secondsString—
throttle_authenticated_deprecated_api_requests_per_periodString—
throttle_authenticated_files_api_enabledString—
throttle_authenticated_files_api_period_in_secondsString—
throttle_authenticated_files_api_requests_per_periodString—
throttle_authenticated_git_http_enabledStringIf true, enforces the authenticated Git HTTP request rate limit. Default value: false
throttle_authenticated_git_http_period_in_secondsStringRate limit period in seconds. throttle_authenticated_git_http_enabled must be true. Default value: 3600
throttle_authenticated_git_http_requests_per_periodStringMaximum requests per period per user. throttle_authenticated_git_http_enabled must be true. Default value: 3600
throttle_authenticated_git_lfs_enabledString—
throttle_authenticated_git_lfs_period_in_secondsString—
throttle_authenticated_git_lfs_requests_per_periodString—
throttle_authenticated_packages_api_enabledString(If enabled, requires: throttle_authenticated_packages_api_period_in_seconds and throttle_authenticated_packages_api_requests_per_period) Enable authenticated API request rate limit. Helps reduce request volume (for example, from crawlers or abusive bots)
throttle_authenticated_packages_api_period_in_secondsStringRate limit period (in seconds)
throttle_authenticated_packages_api_requests_per_periodStringMaximum requests per period per user
throttle_authenticated_web_enabledString(If enabled, requires: throttle_authenticated_web_period_in_seconds and throttle_authenticated_web_requests_per_period) Enable authenticated web request rate limit. Helps reduce request volume (for example, from crawlers or abusive bots)
throttle_authenticated_web_period_in_secondsStringRate limit period (in seconds)
throttle_authenticated_web_requests_per_periodStringMaximum requests per period per user
throttle_protected_paths_enabledString—
throttle_protected_paths_period_in_secondsString—
throttle_protected_paths_requests_per_periodString—
throttle_unauthenticated_api_enabledString(If enabled, requires: throttle_unauthenticated_api_period_in_seconds and throttle_unauthenticated_api_requests_per_period) Enable unauthenticated API request rate limit. Helps reduce request volume (for example, from crawlers or abusive bots)
throttle_unauthenticated_api_period_in_secondsStringRate limit period in seconds
throttle_unauthenticated_api_requests_per_periodStringMaximum requests per period per IP
throttle_unauthenticated_deprecated_api_enabledString—
throttle_unauthenticated_deprecated_api_period_in_secondsString—
throttle_unauthenticated_deprecated_api_requests_per_periodString—
throttle_unauthenticated_enabledString(Deprecated in GitLab 14.3. Use throttle_unauthenticated_web_enabled or throttle_unauthenticated_api_enabled instead.) (If enabled, requires: throttle_unauthenticated_period_in_seconds and throttle_unauthenticated_requests_per_period) Enable unauthenticated web request rate limit. Helps reduce request volume (for example, from crawlers or abusive bots)
throttle_unauthenticated_files_api_enabledString—
throttle_unauthenticated_files_api_period_in_secondsString—
throttle_unauthenticated_files_api_requests_per_periodString—
throttle_unauthenticated_git_http_enabledStringIf true, enforces the unauthenticated Git HTTP request rate limit. Default value: false
throttle_unauthenticated_git_http_period_in_secondsStringRate limit period in seconds. throttle_unauthenticated_git_http_enabled must be true. Default value: 3600
throttle_unauthenticated_git_http_requests_per_periodStringMaximum requests per period per IP. throttle_unauthenticated_git_http_enabled must be true. Default value: 3600
throttle_unauthenticated_packages_api_enabledString(If enabled, requires: throttle_unauthenticated_packages_api_period_in_seconds and throttle_unauthenticated_packages_api_requests_per_period) Enable unauthenticated API request rate limit. Helps reduce request volume (for example, from crawlers or abusive bots)
throttle_unauthenticated_packages_api_period_in_secondsStringRate limit period (in seconds)
throttle_unauthenticated_packages_api_requests_per_periodStringMaximum requests per period per user
throttle_unauthenticated_period_in_secondsString(Deprecated in GitLab 14.3. Use throttle_unauthenticated_web_period_in_seconds or throttle_unauthenticated_api_period_in_seconds instead.) Rate limit period in seconds
throttle_unauthenticated_requests_per_periodString(Deprecated in GitLab 14.3. Use throttle_unauthenticated_web_requests_per_period or throttle_unauthenticated_api_requests_per_period instead.) Maximum requests per period per IP
throttle_unauthenticated_web_enabledString(If enabled, requires: throttle_unauthenticated_web_period_in_seconds and throttle_unauthenticated_web_requests_per_period) Enable unauthenticated web request rate limit. Helps reduce request volume (for example, from crawlers or abusive bots)
throttle_unauthenticated_web_period_in_secondsStringRate limit period in seconds
throttle_unauthenticated_web_requests_per_periodStringMaximum requests per period per IP
time_tracking_limit_to_hoursStringLimit display of time tracking units to hours. Default is false
top_level_group_creation_enabledStringAllows a user to create top-level-groups. Default is true
two_factor_grace_periodIntegerAmount of time (in hours) that users are allowed to skip forced configuration of two-factor authentication
unique_ips_limit_enabledString(If enabled, requires: unique_ips_limit_per_user and unique_ips_limit_time_window) Limit sign in from multiple IPs
unique_ips_limit_per_userStringMaximum number of IPs per user
unique_ips_limit_time_windowStringHow many seconds an IP is counted towards the limit
update_runner_versions_enabledStringFetch GitLab Runner release version data from GitLab.com
usage_ping_enabledBooleanEvery week GitLab will report license usage back to GitLab, Inc
usage_ping_features_enabledString—
usage_ping_generation_enabledString—
use_clickhouse_for_analyticsStringEnables ClickHouse as a data source for analytics reports. ClickHouse must be configured for this setting to take effect. Available on Premium and Ultimate only
user_contributed_projects_api_limitString—
user_deactivation_emails_enabledBooleanSend emails to users upon account deactivation
user_default_externalStringNewly registered users are external by default
user_default_internal_regexStringSpecify an email address regex pattern to identify default internal users
user_defaults_to_private_profileStringNewly created users have private profile by default. Defaults to false
user_oauth_applicationsStringAllow users to register any application to use GitLab as an OAuth provider. This setting does not affect group-level OAuth applications
user_projects_api_limitString—
user_show_add_ssh_key_messageStringWhen set to false disable the You won't be able to pull or push repositories via SSH until you add an SSH key to your profile warning shown to users with no uploaded SSH key
user_starred_projects_api_limitString—
users_api_limit_followersStringMaximum number of requests per minute, per user or IP address. Default: 100. Set to 0 to disable limits. Introduced in GitLab 17.10
users_api_limit_followingStringMaximum number of requests per minute, per user or IP address. Default: 100. Set to 0 to disable limits. Introduced in GitLab 17.10
users_api_limit_gpg_keyStringMaximum number of requests per minute, per user or IP address. Default: 120. Set to 0 to disable limits. Introduced in GitLab 17.10
users_api_limit_gpg_keysStringMaximum number of requests per minute, per user or IP address. Default: 120. Set to 0 to disable limits. Introduced in GitLab 17.10
users_api_limit_ssh_keyString—
users_api_limit_ssh_keysString—
users_api_limit_statusStringMaximum number of requests per minute, per user or IP address. Default: 240. Set to 0 to disable limits. Introduced in GitLab 17.10
users_get_by_id_limitIntegerMaximum number of calls to the /users/:id API per 10 minutes per user. Set to 0 for unlimited requests
users_get_by_id_limit_allowlist_rawString—
valid_runner_registrarsArray of stringsList of types which are allowed to register a GitLab runner
version_check_enabledStringLet GitLab inform you when an update is available
vscode_extension_marketplaceObjectSettings for VS Code Extension Marketplace
vscode_extension_marketplace.custom_valuesObjectVS Code Extension Marketplace URL’s when preset is ‘custom’
vscode_extension_marketplace.enabledBooleanEnables VS Code Extension Marketplace for Web IDE and Workspaces
vscode_extension_marketplace.presetStringThe preset configuration of URL’s for the VS Code Extension Marketplace
vscode_extension_marketplace_enabledString—
vscode_extension_marketplace_extension_host_domainString—
vscode_extension_marketplace_single_origin_fallback_enabledString—
web_hook_event_resend_limitStringMaximum number of webhook event resend requests per minute, per user, for a given project or group. Default: 5. Set to 0 to disable limits. Introduced in GitLab 19.3
web_hook_test_limitStringMaximum number of webhook test requests per minute, per user, for a given project or group. Default: 5. Set to 0 to disable limits. Introduced in GitLab 19.3
whats_new_variantStringWhat’s new variant, possible values: all_tiers, current_tier, and disabled
Allowed values: all_tiers, current_tier, disabled
wiki_asciidoc_allow_uri_includesBooleanAllow URI includes for AsciiDoc wiki pages
wiki_page_max_content_bytesIntegerMaximum wiki page content size in bytes

Responses

CodeDescriptionSchema
200OKAPIEntitiesApplicationSetting
400Bad Request—
401Unauthorized—
403Forbidden—

Retrieve application statistics

GET /api/v4/application/statistics

Retrieves the current application statistics for this GitLab instance.

Responses

CodeDescriptionSchema
200OKAPIEntitiesApplicationStatistics
401Unauthorized—
403Forbidden—

Schemas

Objects returned by the operations above and objects nested in their request bodies.

APIEntitiesAppearance

PropertyTypeDescription
descriptionStringExample: Open source software to collaborate on code
email_header_and_footer_enabledBooleanExample: false
faviconStringExample: /uploads/-/system/appearance/favicon/1/favicon.png
footer_messageStringExample: This is a footer message
header_logoStringExample: /uploads/-/system/appearance/header_logo/1/header.png
header_messageStringExample: This is a header message
logoStringExample: /uploads/-/system/appearance/logo/1/logo.png
member_guidelinesStringExample: Please read the member guidelines.
message_background_colorStringExample: #e75e40
message_font_colorStringExample: #ffffff
new_project_guidelinesStringExample: Please read the FAQs for help.
profile_image_guidelinesStringExample: Custom profile image guidelines
pwa_descriptionStringExample: GitLab as PWA
pwa_iconStringExample: /uploads/-/system/appearance/pwa_icon/1/icon.png
pwa_nameStringExample: GitLab
pwa_short_nameStringExample: GitLab
site_nameStringExample: GitLab
titleStringExample: GitLab Community Edition

APIEntitiesApplicationSetting

PropertyTypeDescription
abuse_notification_emailString—
admin_modeString—
after_sign_out_pathString—
after_sign_up_textString—
ai_action_api_rate_limitString—
akismet_api_keyString—
akismet_enabledString—
allow_account_deletionString—
allow_application_default_credentials_for_offline_transferString—
allow_bypass_placeholder_confirmationString—
allow_contribution_mapping_to_adminsString—
allow_deploy_tokens_and_keys_with_external_authnString—
allow_local_requests_from_hooks_and_servicesString—
allow_local_requests_from_system_hooksString—
allow_local_requests_from_web_hooks_and_servicesString—
allow_possible_spamString—
allow_project_creation_for_guest_and_belowString—
allow_runner_registration_tokenString—
allow_s3_compatible_storage_for_offline_transferString—
anonymous_searches_allowedString—
archive_builds_in_human_readableString—
asciidoc_max_includesString—
asset_proxy_allowlistString—
asset_proxy_enabledString—
asset_proxy_urlString—
asset_proxy_whitelistString—
authn_data_retention_cleanup_enabledString—
authorized_keys_enabledString—
auto_accept_awarded_achievementsString—
auto_devops_domainString—
auto_devops_enabledString—
autocomplete_users_limitString—
autocomplete_users_unauthenticated_limitString—
background_operations_max_jobsString—
block_jwt_for_reclaimed_pathsString—
bulk_import_concurrent_pipeline_batch_limitString—
bulk_import_enabledString—
bulk_import_max_download_file_sizeString—
can_create_groupString—
can_create_organizationString—
ci_delete_pipelines_in_seconds_limit_human_readableString—
ci_job_live_trace_enabledString—
ci_lint_limit_per_userString—
ci_max_caches_per_jobString—
ci_max_includesString—
ci_max_total_yaml_size_bytesString—
ci_partitions_in_seconds_limit_human_readableString—
code_dropdown_custom_clientsString—
code_suggestions_api_rate_limitString—
commit_email_hostnameString—
concurrent_bitbucket_import_jobs_limitString—
concurrent_bitbucket_server_import_jobs_limitString—
concurrent_github_import_jobs_limitString—
concurrent_pull_request_import_jobs_limitString—
concurrent_relation_batch_export_limitString—
concurrent_relation_export_limitString—
container_expiration_policies_enable_historic_entriesString—
container_registry_cleanup_tags_service_max_list_sizeString—
container_registry_delete_tags_service_timeoutString—
container_registry_expiration_policies_cachingString—
container_registry_expiration_policies_worker_capacityString—
container_registry_import_created_beforeString—
container_registry_import_max_retriesString—
container_registry_import_max_step_durationString—
container_registry_import_max_tags_countString—
container_registry_import_start_max_retriesString—
container_registry_import_target_planString—
container_registry_import_timeoutString—
container_registry_pre_import_tags_rateString—
container_registry_pre_import_timeoutString—
container_registry_token_expire_delayString—
create_organization_api_limitString—
custom_http_clone_url_rootString—
deactivate_dormant_usersString—
deactivate_dormant_users_periodString—
deactivation_email_additional_textString—
decompress_archive_file_timeoutString—
default_artifacts_expire_inString—
default_branch_nameString—
default_branch_protectionString—
default_branch_protection_defaultsString—
default_ci_config_pathString—
default_dark_syntax_highlighting_themeString—
default_group_visibilityString—
default_preferred_languageString—
default_project_creationString—
default_project_visibilityString—
default_projects_limitString—
default_search_scopeString—
default_snippet_visibilityString—
default_syntax_highlighting_themeString—
delay_user_account_self_deletionString—
delete_inactive_projectsString—
deletion_adjourned_periodString—
deny_all_requests_except_allowedString—
dependency_management_settingsString—
description_and_note_max_sizeString—
diagramsnet_enabledString—
diagramsnet_urlString—
diff_max_commitsString—
diff_max_filesString—
diff_max_linesString—
diff_max_patch_bytesString—
diff_max_versionsString—
disable_admin_oauth_scopesString—
disable_feed_tokenString—
disable_password_authentication_for_users_with_sso_identitiesString—
disabled_oauth_sign_in_sourcesString—
dns_rebinding_protection_enabledString—
domain_allowlistString—
domain_allowlist_rawString—
domain_denylistString—
domain_denylist_enabledString—
domain_denylist_rawString—
downstream_pipeline_trigger_limit_per_project_user_shaString—
dsa_key_restrictionString—
dynamic_client_registration_enabledString—
ecdsa_key_restrictionString—
ecdsa_sk_key_restrictionString—
ed25519_key_restrictionString—
ed25519_sk_key_restrictionString—
eks_access_key_idString—
eks_account_idString—
eks_integration_enabledString—
email_author_in_bodyString—
email_confirmation_settingString—
email_otp_enabledString—
email_restrictionsString—
email_restrictions_enabledString—
enable_artifact_external_redirect_warning_pageString—
enable_language_server_restrictionsString—
enabled_git_access_protocolString—
enforce_ci_inbound_job_token_scope_enabledString—
enforce_email_subaddress_restrictionsString—
enforce_granular_tokensString—
enforce_termsString—
error_tracking_api_urlString—
error_tracking_enabledString—
external_auth_client_certString—
external_auth_client_keyString—
external_auth_client_key_passString—
external_authorization_service_default_labelString—
external_authorization_service_enabledString—
external_authorization_service_timeoutString—
external_authorization_service_urlString—
external_pipeline_validation_service_timeoutString—
external_pipeline_validation_service_tokenString—
external_pipeline_validation_service_urlString—
failed_login_attempts_unlock_period_in_minutesString—
fe_application_settings_attributesObject—
first_day_of_weekString—
floc_enabledString—
force_pages_access_controlString—
git_push_pipeline_limitString—
gitaly_timeout_defaultString—
gitaly_timeout_fastString—
gitaly_timeout_mediumString—
gitlab_dedicated_instanceString—
gitlab_environment_toolkit_instanceString—
gitlab_product_usage_data_enabledString—
gitlab_product_usage_data_sourceString—
gitlab_shell_operation_limitString—
gitpod_enabledString—
gitpod_urlString—
global_search_block_anonymous_searches_enabledString—
global_search_groups_enabledString—
global_search_merge_requests_enabledString—
global_search_snippet_titles_enabledString—
global_search_users_enabledString—
global_search_work_items_enabledString—
grafana_enabledString—
grafana_urlString—
granular_tokens_enforced_afterString—
gravatar_enabledString—
group_api_limitString—
group_archive_unarchive_api_limitString—
group_create_limitString—
group_download_export_limitString—
group_export_limitString—
group_import_limitString—
group_invited_groups_api_limitString—
group_projects_api_limitString—
group_runner_token_expiration_intervalString—
group_shared_groups_api_limitString—
groups_api_limitString—
hashed_storage_enabledString—
helm_max_packages_countString—
help_page_documentation_base_urlString—
help_page_hide_commercial_contentString—
help_page_support_urlString—
help_page_textString—
hide_third_party_offersString—
home_page_urlString—
housekeeping_bitmaps_enabledString—
housekeeping_enabledString—
housekeeping_full_repack_periodString—
housekeeping_gc_periodString—
housekeeping_incremental_repack_periodString—
housekeeping_optimize_repository_periodString—
html_emails_enabledString—
idString—
iframe_rendering_allowlistString—
iframe_rendering_allowlist_rawString—
iframe_rendering_enabledString—
import_jobs_concurrency_limitString—
import_sourcesString—
inactive_projects_delete_after_monthsString—
inactive_projects_min_size_mbString—
inactive_projects_send_warning_email_after_monthsString—
inactive_resource_access_tokens_delete_after_daysString—
include_optional_metrics_in_service_pingString—
instance_token_prefixString—
invisible_captcha_enabledString—
invitation_flow_enforcementString—
issues_create_limitString—
jira_connect_additional_audience_urlString—
jira_connect_application_keyString—
jira_connect_proxy_urlString—
jira_connect_public_key_storage_enabledString—
jira_forge_app_idString—
keep_latest_artifactString—
kroki_diagram_proxy_enabledString—
kroki_enabledString—
kroki_formatsString—
kroki_urlString—
local_markdown_versionString—
lock_require_sha_for_mergeString—
lock_resource_access_token_notify_inheritedString—
logging_field_dual_emit_targetInteger—
logging_field_schema_versionInteger—
login_recaptcha_protection_enabledString—
mailgun_events_enabledString—
mailgun_signing_keyString—
math_rendering_limits_enabledString—
max_artifacts_content_include_sizeString—
max_artifacts_sizeString—
max_attachment_sizeString—
max_decompressed_archive_sizeString—
max_export_sizeString—
max_github_response_json_value_countString—
max_github_response_size_limitString—
max_http_decompressed_sizeString—
max_http_response_csv_structural_charsString—
max_http_response_json_depthString—
max_http_response_json_structural_charsString—
max_http_response_size_limitString—
max_http_response_xml_structural_charsString—
max_import_remote_file_sizeString—
max_import_sizeString—
max_login_attemptsString—
max_pages_custom_domains_per_projectString—
max_pages_sizeString—
max_terraform_state_size_bytesString—
max_yaml_depthString—
max_yaml_size_bytesString—
mcp_server_enabledString—
members_delete_limitString—
metrics_method_call_thresholdString—
minimum_language_server_versionString—
minimum_password_lengthString—
mirror_availableString—
namespace_aggregation_schedule_lease_duration_in_secondsString—
notes_create_limitString—
notes_create_limit_allowlist_rawString—
notify_on_unknown_sign_inString—
nuget_skip_metadata_url_validationString—
oauth_access_token_expires_inString—
observability_backend_ssl_verification_enabledString—
offline_transfer_exports_enabledString—
offline_transfer_imports_enabledString—
organization_cluster_agent_authorization_enabledString—
outbound_local_requests_allowlist_rawString—
outbound_local_requests_whitelistString—
package_registry_allow_anyone_to_pull_optionString—
package_registry_cleanup_policies_worker_capacityString—
pages_domain_verification_enabledString—
pages_extra_deployments_default_expiry_secondsString—
pages_unique_domain_default_enabledString—
password_authentication_enabledString—
password_authentication_enabled_for_gitString—
password_authentication_enabled_for_webString—
performance_bar_allowed_group_idString—
personal_access_token_prefixString—
pipeline_limit_per_project_user_shaString—
pipeline_limit_per_userString—
plantuml_diagram_proxy_enabledString—
plantuml_enabledString—
plantuml_urlString—
polling_interval_multiplierString—
project_api_limitString—
project_create_limitString—
project_download_export_limitString—
project_export_enabledString—
project_export_limitString—
project_import_limitString—
project_invited_groups_api_limitString—
project_jobs_api_rate_limitString—
project_members_api_limitString—
project_repositories_blobs_batch_limitString—
project_runner_token_expiration_intervalString—
projects_api_limitString—
projects_api_rate_limit_unauthenticatedString—
prometheus_metrics_enabledString—
protected_ci_variablesString—
protected_paths_for_get_request_rawString—
protected_paths_rawString—
push_event_activities_limitString—
push_event_hooks_limitString—
rate_limiting_response_textString—
raw_blob_request_limitString—
raw_blob_request_limit_unauthenticatedString—
recaptcha_enabledString—
recaptcha_private_keyString—
recaptcha_site_keyString—
receive_max_input_sizeString—
reindexing_minimum_index_sizeString—
reindexing_minimum_relative_bloat_sizeString—
relation_export_batch_sizeString—
remember_me_enabledString—
repository_checks_enabledString—
repository_storages_weightedString—
require_admin_approval_after_user_signupString—
require_admin_two_factor_authenticationString—
require_email_verification_on_account_lockedString—
require_personal_access_token_expiryString—
require_sha_for_mergeString—
require_two_factor_authenticationString—
resource_access_token_notify_inheritedString—
resource_usage_limitsString—
restricted_visibility_levelsString—
root_moved_permanently_redirectionString—
rsa_key_restrictionString—
runner_jobs_endpoints_api_limitString—
runner_jobs_patch_trace_api_limitString—
runner_jobs_request_api_limitString—
runner_token_expiration_intervalString—
search_rate_limitString—
search_rate_limit_allowlist_rawString—
search_rate_limit_unauthenticatedString—
security_txt_contentString—
sentry_clientside_dsnString—
sentry_clientside_traces_sample_rateString—
sentry_dsnString—
sentry_enabledString—
sentry_environmentString—
session_expire_delayString—
session_expire_from_initString—
shared_runners_enabledString—
shared_runners_textString—
show_migrate_from_jenkins_bannerString—
sidekiq_job_limiter_compression_threshold_bytesString—
sidekiq_job_limiter_limit_bytesString—
sidekiq_job_limiter_modeString—
sidekiq_timezone_overrideString—
sign_in_restrictionsString—
signin_enabledString—
signup_enabledString—
silent_admin_exports_enabledString—
silent_mode_enabledString—
slack_app_enabledString—
slack_app_idString—
slack_app_secretString—
slack_app_signing_secretString—
slack_app_verification_tokenString—
snippet_size_limitString—
snowplow_app_idString—
snowplow_collector_hostnameString—
snowplow_cookie_domainString—
snowplow_database_collector_hostnameString—
snowplow_enabledString—
sourcegraph_enabledString—
sourcegraph_public_onlyString—
sourcegraph_urlString—
spam_check_api_keyString—
spam_check_endpoint_enabledString—
spam_check_endpoint_urlString—
static_objects_external_storage_auth_tokenString—
static_objects_external_storage_urlString—
tags_create_limitString—
terminal_max_session_timeString—
termsString—
terraform_state_encryption_enabledString—
throttle_authenticated_api_enabledString—
throttle_authenticated_api_period_in_secondsString—
throttle_authenticated_api_requests_per_periodString—
throttle_authenticated_dependency_proxy_enabledString—
throttle_authenticated_dependency_proxy_period_in_secondsString—
throttle_authenticated_dependency_proxy_requests_per_periodString—
throttle_authenticated_deprecated_api_enabledString—
throttle_authenticated_deprecated_api_period_in_secondsString—
throttle_authenticated_deprecated_api_requests_per_periodString—
throttle_authenticated_files_api_enabledString—
throttle_authenticated_files_api_period_in_secondsString—
throttle_authenticated_files_api_requests_per_periodString—
throttle_authenticated_git_http_enabledString—
throttle_authenticated_git_http_period_in_secondsString—
throttle_authenticated_git_http_requests_per_periodString—
throttle_authenticated_git_lfs_enabledString—
throttle_authenticated_git_lfs_period_in_secondsString—
throttle_authenticated_git_lfs_requests_per_periodString—
throttle_authenticated_packages_api_enabledString—
throttle_authenticated_packages_api_period_in_secondsString—
throttle_authenticated_packages_api_requests_per_periodString—
throttle_authenticated_web_enabledString—
throttle_authenticated_web_period_in_secondsString—
throttle_authenticated_web_requests_per_periodString—
throttle_protected_paths_enabledString—
throttle_protected_paths_period_in_secondsString—
throttle_protected_paths_requests_per_periodString—
throttle_unauthenticated_api_enabledString—
throttle_unauthenticated_api_period_in_secondsString—
throttle_unauthenticated_api_requests_per_periodString—
throttle_unauthenticated_deprecated_api_enabledString—
throttle_unauthenticated_deprecated_api_period_in_secondsString—
throttle_unauthenticated_deprecated_api_requests_per_periodString—
throttle_unauthenticated_enabledString—
throttle_unauthenticated_files_api_enabledString—
throttle_unauthenticated_files_api_period_in_secondsString—
throttle_unauthenticated_files_api_requests_per_periodString—
throttle_unauthenticated_git_http_enabledString—
throttle_unauthenticated_git_http_period_in_secondsString—
throttle_unauthenticated_git_http_requests_per_periodString—
throttle_unauthenticated_packages_api_enabledString—
throttle_unauthenticated_packages_api_period_in_secondsString—
throttle_unauthenticated_packages_api_requests_per_periodString—
throttle_unauthenticated_period_in_secondsString—
throttle_unauthenticated_requests_per_periodString—
throttle_unauthenticated_web_enabledString—
throttle_unauthenticated_web_period_in_secondsString—
throttle_unauthenticated_web_requests_per_periodString—
time_tracking_limit_to_hoursString—
top_level_group_creation_enabledString—
two_factor_grace_periodString—
unique_ips_limit_enabledString—
unique_ips_limit_per_userString—
unique_ips_limit_time_windowString—
update_runner_versions_enabledString—
usage_ping_enabledString—
usage_ping_features_enabledString—
usage_ping_generation_enabledString—
use_clickhouse_for_analyticsString—
user_contributed_projects_api_limitString—
user_deactivation_emails_enabledString—
user_default_externalString—
user_default_internal_regexString—
user_defaults_to_private_profileString—
user_oauth_applicationsString—
user_projects_api_limitString—
user_show_add_ssh_key_messageString—
user_starred_projects_api_limitString—
users_api_limit_followersString—
users_api_limit_followingString—
users_api_limit_gpg_keyString—
users_api_limit_gpg_keysString—
users_api_limit_ssh_keyString—
users_api_limit_ssh_keysString—
users_api_limit_statusString—
users_get_by_id_limitString—
users_get_by_id_limit_allowlist_rawString—
valid_runner_registrarsString—
version_check_enabledString—
vscode_extension_marketplaceString—
vscode_extension_marketplace_enabledString—
vscode_extension_marketplace_extension_host_domainString—
vscode_extension_marketplace_single_origin_fallback_enabledString—
web_hook_event_resend_limitString—
web_hook_test_limitString—
whats_new_variantString—
wiki_asciidoc_allow_uri_includesString—
wiki_page_max_content_bytesString—

APIEntitiesApplicationStatistics

PropertyTypeDescription
active_usersIntegerNumber of active users
Example: 21
forksIntegerApproximate number of repo forks
Example: 6
groupsIntegerApproximate number of projects
Example: 1
issuesIntegerApproximate number of issues
Example: 121
merge_requestsIntegerApproximate number of merge requests
Example: 49
milestonesIntegerApproximate number of milestones
Example: 3
notesIntegerApproximate number of notes
Example: 6
projectsIntegerApproximate number of projects
Example: 4
snippetsIntegerApproximate number of snippets
Example: 4
ssh_keysIntegerApproximate number of SSH keys
Example: 11
usersIntegerApproximate number of users
Example: 22