Prerequisites
Fleet requires an Enterprise plan and LangSmith Self-Hosted v0.13 or later. This standalone deployment configuration requires v0.15 or later. Install the base LangSmith platform first. Fleet provisions an API server, task queue, PostgreSQL, Redis, tool server, and trigger server. It does not require LangSmith Deployment.Enable Fleet
Generate a Fernet encryption key for Fleet:agent_builder_encryption_key in your existing LangSmith app Secret. Add the following to your langsmith_config.yaml:
fleet.encryptionKey inline. Do not commit encryption keys to version control. Both fleetToolServer and fleetTriggerServer are required.
Fleet uses dedicated PostgreSQL and Redis instances by default. To use external databases, configure fleet.postgres.external and fleet.redis.external:
(Optional) Enable OAuth tools and triggers for Fleet
To enable OAuth-based tools such as Gmail, Slack, or Linear in Fleet, configure theproviderOrgId and add provider IDs for each integration you want to use. You can enable any combination of providers.
Available providers
General configuration
Add the following to yourlangsmith_config.yaml. Include only the providers you need.
Provider setup guides
Google OAuth provider
Google OAuth provider
Create OAuth client in GCP
Add URLs to GCP
<hostname> with your LangSmith hostname and <provider-id> with the provider ID you’ll use (for example, google):Authorized JavaScript origins:https://<hostname>
https://<hostname>/api-host/v2/auth/callback/<provider-id>https://<hostname>/host-oauth-callback/<provider-id>
Copy credentials
Configure OAuth provider in LangSmith
- Client ID: from GCP
- Client Secret: from GCP
- Authorization URL:
https://accounts.google.com/o/oauth2/auth - Token URL:
https://oauth2.googleapis.com/token - Provider ID: Unique string, for example:
google
Apply the changes
Microsoft OAuth provider
Microsoft OAuth provider
Create an Azure app registration
Choose supported account types
Add the redirect URI
<hostname> with your LangSmith hostname and <provider-id> with your provider ID:Create a client secret
Add Microsoft Graph delegated permissions
Mail.ReadWriteMail.SendCalendars.ReadWriteTeam.ReadBasic.AllChannel.ReadBasic.AllChannel.CreateChannelMessage.SendChannelMessage.Read.AllChat.CreateChat.ReadWriteUser.ReadBasic.AllFiles.ReadWrite.AllSites.ReadWrite.All
offline_access for Microsoft providers so users can receive refresh tokens.Grant tenant consent
Configure OAuth provider in LangSmith
- Name: For example,
Microsoft - Provider ID: Unique string, for example:
microsoft-oauth-provider - Client ID: Application (client) ID from Azure
- Client Secret: Client secret value from Azure
- Authorization URL:
https://login.microsoftonline.com/common/oauth2/v2.0/authorize - Token URL:
https://login.microsoftonline.com/common/oauth2/v2.0/token - Provider Type:
microsoft - Token endpoint auth method:
client_secret_post
common in the authorization and token URLs with your tenant ID.Apply the changes
Linear OAuth provider
Linear OAuth provider
Create a Linear OAuth app
Add callback URL
<hostname> with your LangSmith hostname and <provider-id> with your provider ID:Copy credentials
Configure OAuth provider in LangSmith
- Client ID: from Linear app
- Client Secret: from Linear app
- Authorization URL:
https://linear.app/oauth/authorize - Token URL:
https://api.linear.app/oauth/token - Provider ID: Unique string, for example:
linear
Apply the changes
LinkedIn OAuth provider
LinkedIn OAuth provider
Create a LinkedIn OAuth app
Add redirect URI
<hostname> with your LangSmith hostname and <provider-id> with your provider ID:Copy credentials
Configure OAuth provider in LangSmith
- Client ID: from LinkedIn app
- Client Secret: from LinkedIn app
- Authorization URL:
https://www.linkedin.com/oauth/v2/authorization - Token URL:
https://www.linkedin.com/oauth/v2/accessToken - Provider ID: Unique string, for example:
linkedin
Apply the changes
Salesforce OAuth provider
Salesforce OAuth provider
Create an External Client App
- External Client App Name: for example,
LangSmith Fleet - Contact Email: an admin email address
- Distribution State: Local
Enable OAuth and configure the OAuth settings
- Callback URL, replacing
<hostname>with your LangSmith hostname and<provider-id>with your provider ID:
- Selected OAuth Scopes: add Manage user data via APIs (api) and Perform requests at any time (refresh_token, offline_access).
- Keep Require Secret for the Web Server Flow selected.
- Leave Enable Authorization Code and Credentials Flow and Enable Client Credentials Flow unselected. Fleet uses the standard web server (authorization code) flow.
Set the OAuth policies
- Refresh Token Policy: select Refresh token is valid until revoked.
- Permitted Users: leave All users may self-authorize. If you choose Admin approved users are pre-authorized instead, you must first assign the app to a permission set or profile, or authorization fails.
Copy the credentials
Configure OAuth provider in LangSmith
- Provider ID: Unique string, for example:
salesforce-oauth-provider. Use this same value forsalesforceOAuthProviderin the next step. - Display Name: For example,
Salesforce - Client ID: Consumer Key from Salesforce
- Client Secret: Consumer Secret from Salesforce
- Authorization URL:
https://<MyDomain>.my.salesforce.com/services/oauth2/authorize - Token URL:
https://<MyDomain>.my.salesforce.com/services/oauth2/token
<MyDomain> with your org’s My Domain, found under Setup > My Domain. For a sandbox, use https://<MyDomain>--<SandboxName>.sandbox.my.salesforce.com/services/oauth2/authorize and the matching token URL.Apply the changes
Slack OAuth provider
Slack OAuth provider
(Optional) Enable GitHub App for Fleet
Fleet integrates with GitHub through a dedicated GitHub App (not an OAuth app). The GitHub App provides repository access for Fleet’s GitHub tools and supports the user authorization flow required for private repository access. Setup involves creating a GitHub App, gathering its credentials, storing them as Kubernetes secrets, and referencing them from yourlangsmith_config.yaml.
Create a GitHub App
Fill in basic details
- GitHub App name: Any unique name, for example
acme-langsmith-fleet. Make a note of the slug GitHub generates (the lowercased, hyphenated form of the name), as this is the value you’ll use forFLEET_GITHUB_APP_SLUG. - Homepage URL: Your LangSmith hostname, for example
https://langsmith.acme.com. - Deselect Active under Webhook for now. You’ll enable it in a later step after generating a webhook secret.
Set callback URLs
<hostname> with your LangSmith hostname:Set webhook URL and generate a webhook secret
- Select Active.
-
Set the Webhook URL to:
- Paste the generated value into Webhook secret. Save it, as you’ll need the same value when creating the Kubernetes secret in a later step.
Set repository permissions
- Contents: Read and write
- Issues: Read and write
- Pull requests: Read and write
- Metadata: Read-only (automatically selected)
Choose install visibility
Create the app
Generate a client secret
FLEET_GITHUB_APP_CLIENT_SECRET. GitHub only shows it once.Generate a private key
.pem file. Keep this file secure, as it grants full access to the GitHub App. The PEM contents are FLEET_GITHUB_APP_PRIVATE_KEY.Generate a state JWT secret
FLEET_GITHUB_APP_STATE_JWT_SECRET.Create a Kubernetes secret
Add the configuration to your langsmith_config.yaml
FLEET_GITHUB_APP_ENABLED must be set on the tool server so the GitHub tools are registered. The remaining FLEET_GITHUB_APP_* variables are consumed by the platform backend and live under commonEnv.Deploy and install the app on repositories
- In LangSmith, open a Fleet agent and go to the GitHub integration in the agent editor.
- Click Connect GitHub to install the app on the repositories Fleet should access.
- For private repositories, you must explicitly select each repository during installation.

