Skip to main content

Configuration Profile

string
default:"~/.agentuse"
Directory containing AgentUse’s user-controlled config.json, .env, managed projects/, user-global plugins/, and user-global skills/. Set this together with AGENTUSE_DATA_DIR when isolating a test or development server.
The older AGENTUSE_CONFIG and AGENTUSE_ENV file-level overrides are deprecated compatibility controls. When present they take precedence for their respective file and are scheduled for removal no earlier than December 1, 2026.

API Configuration

These environment variables are required for authenticating with AI providers.
string
API key for Anthropic Claude models.
Claude subscription OAuth is provided by the shortlisted Claude Code Subscription plugin.
string
Long-lived Claude subscription token used by the shortlisted Claude Code Subscription plugin. It is not used by the built-in Anthropic API transport.Install the plugin before using this variable:
string
API key for OpenAI GPT models.
string
API key for OpenRouter service.
string
API key for OpenCode Go open coding models.
string
Optional base URL override for OpenCode Go. Defaults to https://opencode.ai/zen/go/v1.
string
AWS access key ID for Amazon Bedrock authentication (SigV4). Used together with AWS_SECRET_ACCESS_KEY and AWS_REGION.
string
AWS secret access key for Amazon Bedrock authentication (SigV4).
string
AWS region for Amazon Bedrock API calls (e.g. us-east-1). Falls back to AWS_DEFAULT_REGION if unset. Required when using Bedrock.
string
Optional AWS session token for temporary credentials (e.g. STS / assumed roles) when using Amazon Bedrock.
string
Bedrock API key (Bearer token). When set, used instead of AWS SigV4 authentication.
string
AWS named profile from ~/.aws/credentials / ~/.aws/config. Used when no static keys or Bearer token are set: the SDK credential provider chain resolves SSO cache, assumed roles, instance metadata, etc.

Custom API Key Suffixes

You can use multiple API keys by adding suffixes:
Then reference them in your agent:

Serve Mode

string
API key for authenticating requests to the serve mode HTTP server. Required when binding to exposed hosts (not 127.0.0.1 or localhost).The daemon reads it once at startup and removes it from its environment, so bash commands, MCP servers, and skill scripts that agents launch do not inherit it.
Clients authenticate via Bearer token:
string
default:"agentuse/agentuse"
GitHub repository (owner/name) that the “Report to AgentUse” link on a changeset review points at. The reviser sets it when a no-change diagnosis blames the AgentUse runtime rather than the agent. Point it at a fork or an internal tracker when your team triages framework bugs elsewhere.
number
default:"300"
Heap size, in MB, at which an idle per-project worker is retired and replaced.
A worker bank starts around 130MB of peak heap and settles at roughly 350-450MB once it has executed runs, so a long-lived daemon otherwise holds that memory indefinitely. When an idle worker is over the threshold it is retired through the same release path used at shutdown: runs already in flight finish in the old worker while a replacement starts serving immediately. A worker is only ever recycled while idle, and never within 2 minutes of starting. Set 0 to disable recycling.
string
Set to 0 to restore the old kill-on-shutdown behavior. By default agentuse serve releases its workers on shutdown instead of killing them, so a pm2 or systemd restart does not destroy runs that are mid-flight.
number
Hard deadline, in seconds, for a released worker to exit after the daemon goes away. Defaults to the longest in-flight run’s own timeout plus 10 minutes of grace.

Approval Gates

string
Slack bot token used to post and update channel messages when channels.slack listens for approval, completion, or failure. The app needs the chat:write bot scope, and the bot must be in the target channel unless you also grant chat:write.public for public channels.
string
Optional Slack app-level token used for Socket Mode approval actions in Slack. Web approval pages and channel-only Slack messages do not require this token. If set, the app-level token needs connections:write; plain thread-reply comments also require Slack message event subscriptions and the relevant channel history scopes.
string
Default Slack channel id for Slack channels. Agents can override this with channels.slack.channel_id.
string
Fallback public base URL used to build approval review links. Its host also joins the keyless daemon’s allowed request hosts. Prefer agentuse serve --public-url ... or serve.publicUrl for hosted deployments.

Behavior Control

string
Model used by agent files that omit model:.
Accepts anything a model: field accepts: a concrete id, a version alias, a configured @name, or any of those with an :env auth suffix.Precedence: an explicit model: in the agent file wins; otherwise this variable wins over models.default in the AgentUse config. With none of the three set, an agent file without model: fails to parse.
number
Override the maximum number of conversation steps (LLM generation cycles) an agent can take. Default: 100
Precedence: This environment variable overrides the maxSteps value in agent YAML files.This prevents infinite loops and controls cost by limiting the number of LLM calls. Each step typically involves an LLM generation with potential tool calls.
The default was reduced from 1000 to 100 for better cost protection. Most agents complete successfully within 100 steps.
number
Default timeout in seconds for individual MCP tool calls. Default: 60
Precedence: A server’s toolTimeout in agent YAML overrides this variable; this variable overrides the built-in 60-second default.

Code Mode

boolean
Code Mode is enabled by default. Set this to 0 to omit code_exec from normal runs. The policy is inherited by recursive subagents and serve worker processes, which makes it suitable for controlled before-and-after tests or emergency rollback. This is a runtime switch only; do not add it to an agent’s frontmatter.
The CLI equivalents are agentuse run --no-code-mode and agentuse serve --no-code-mode.

Mock Mode (Testing)

Mock all tool outputs with the LLM instead of executing them. Mirror the --mock flags on agentuse run; see Testing with Mocked Tools.
boolean
1 to mock all tool outputs (no real bash/filesystem/MCP/store side effects). Same as --mock. Requires AGENTUSE_MOCK_MODEL.
string
required
Model that generates mock outputs. Required whenever mock mode is on (same as --mock-model). Not defaulted to the agent’s model on purpose: mock fires an LLM call per tool result, and running that on the agent’s premium, rate-limited token caused opaque 429s.Use the lowest-end model you can reach here: mocking only fabricates a plausible tool result, not real reasoning, so a small fast model is plenty and keeps cost and rate-limit pressure low. Good picks: anthropic:claude-haiku-4-5, openai:gpt-5.4-nano, or openrouter:deepseek/deepseek-v4-flash.Set it for one run with --mock-model, or as a global default in the shell, ~/.agentuse/.env, or the env block of ~/.agentuse/config.json. --mock-model overrides whichever source supplies it.
string
What mock mode covers. Unset (or all) mocks every tool result, same as --mock. gated mocks only bash commands matching the agent’s tools.bash.gated patterns and leaves every other tool real, same as agentuse test --scope gated. Only read when mock mode is on.
string
Resolve the await_human approval gate deterministically instead of suspending (mock mode only). Same as --mock-approval. Values: approve (also 1/true), reject, or comment:<text>. An approve grants the gated-command lease from the gate’s changes[] exactly like a real reviewer approval; a reject seals the gate (terminal), and a comment forces the revise-and-re-gate branch on the first gate then approves the re-gate.

Context Management

boolean
Enable or disable automatic context compaction when approaching model limits. Default: true (enabled)
When enabled, AgentUse automatically compacts older messages when context approaches the model’s token limit.
number
Percentage of context limit to trigger compaction. Default: 0.7 (70%)
Must be a decimal between 0 and 1.
number
Number of recent messages to preserve during compaction. Default: 3
These messages are never compacted to maintain conversation flow.
number
Minimum active-context size that triggers opportunistic compaction at an approval gate. Default: 64000
This is separate from COMPACTION_THRESHOLD: a 64k-token context may be far below a large model’s window, but still expensive to resend after a human approval pause. Set to 0 to disable approval-boundary compaction while keeping normal model-limit compaction enabled.
number
Minimum active-context size that triggers opportunistic compaction between LLM steps after the first tool call. Default: 64000
This enables split-turn compaction for long autonomous runs: older context can be summarized before the next model call even when the full model window is not close to exhausted. Set to 0 to disable step-boundary compaction while keeping approval-boundary and model-limit compaction enabled.

Tool Output

Large tool results are re-sent to the model on every subsequent step. AgentUse stores oversized direct JSON and text results outside model context and returns a queryable handle instead. Bash keeps a larger bounded canonical capture for that result store, with the complete stream saved as a session artifact if the capture ceiling is crossed.
number
Maximum serialized size of a direct JSON or text response returned inline. Larger results become a reusable resultId handle with a partial preview and jq-style omitted map, and can be narrowed with the results tool. Default: 10240 (10KB)
number
Maximum serialized size returned inline by one results tool query. Queries above this limit ask for a narrower selection and never create another result handle. Default: 20480 (20KB)
number
Maximum canonical output retained by the built-in bash accumulator for reusable results. Output over this limit is reduced to a head + tail slice and the complete stream is saved as a session artifact; AgentUse does not issue a reusable resultId for that incomplete capture. Default: 4194304 (4MB)
number
Legacy general tool-output limit. It remains the fallback for Bash canonical capture and the inline result limit when their dedicated variables are unset, preserving existing configurations. Prefer AGENTUSE_BASH_CAPTURE_BYTES and AGENTUSE_TOOL_INLINE_RESULT_BYTES for independent control. Default: 30720 (30KB)
number
Fraction of a truncated output budget kept as the head; the remainder is kept as the tail. Errors and context often appear early, while the most recent output appears at the end, so both ends are preserved. Default: 0.4 (40% head / 60% tail)
Must be a decimal between 0 and 1.
number
Default number of lines read_file returns when no explicit limit is given (and the truncation cap for file reads). Default: 2000
number
Per-line character cap for read_file output. Longer lines are truncated with a ... (truncated) suffix. Default: 2000
Prefer not generating bloat in the first place over raising these caps. For example, use git diff --stat instead of a full git diff of high-churn files. Truncation is a safety net, not a substitute for asking the tool for less.

Logging and Debug

string
Set the logging level for AgentUse output. Default: INFO
Controls which messages are displayed during execution.
boolean
Enable debug logging and verbose output. Default: false
Shows detailed execution information, tool calls, and internal state.

Telemetry

boolean
Disable all anonymous telemetry, including CLI, daemon, execution, and bundled dashboard telemetry. AgentUse records installation and first-execution lifecycle events, execution metadata, and a fixed top-level dashboard page category. The browser sends that category only to its local AgentUse daemon, which batches delivery; it does not contact PostHog directly. Server telemetry reports only the kind of bind address (host_class: loopback, any, or other), never the host itself. No prompts, code, or file paths are ever collected. Default: false (telemetry enabled)

Update Checks

boolean
Disable the daily npm registry check and all CLI/Web UI update reminders. Update checks are cached locally, run off the command’s critical path, and are also disabled automatically in CI, local development builds, and npx cache executions. Interactive CLI reminders appear at most once per version every seven days and are suppressed for non-TTY, --quiet, and --json output. The dashboard keeps its dismissal per browser and version.

Storage

string
default:"~/.local/share/agentuse"
Exact directory containing AgentUse-owned durable data: provider credentials, installed global plugins, sessions, learnings, schedules, server registry and logs, push state, telemetry identity, and update state.
AgentUse does not append another agentuse/ component to this path. This variable takes precedence over XDG_DATA_HOME.
string
Standards-compatible fallback base directory. AgentUse uses $XDG_DATA_HOME/agentuse only when AGENTUSE_DATA_DIR is unset. Default XDG base: ~/.local/share.
Everything a run generates is stored per project, under the resolved AgentUse data directory:
For a fully isolated development daemon, set AGENTUSE_DATA_DIR and AGENTUSE_CONFIG_DIR. Existing XDG-based integrations remain compatible.See Session Logs and Learning for more details.

Development Variables

string
For local development with self-signed certificates (HTTPS testing).
Never use this in production. It disables SSL certificate verification.

MCP Server Environment Variables

Security by Design: AgentUse intentionally prevents hardcoding secrets in .agentuse files. All sensitive values must come from environment variables, keeping your secrets secure and out of version control.

The Security Model

MCP servers can access environment variables through two fields:
  • requiredEnvVars: Variables that MUST exist or the agent fails immediately
  • allowedEnvVars: Variables that are passed through if they exist (optional)

Why This Design?

  1. No Secrets in Code: .agentuse files are often committed to version control
  2. Clear Requirements: Developers know exactly what env vars are needed
  3. Early Failure: Missing required vars fail fast with clear error messages
  4. Security Allowlist: Only explicitly allowed vars are passed to MCP servers

Setting Environment Variables

Error Messages

AgentUse provides clear, actionable error messages:

Complete Example

With .env file:

Using .env Files

For a full overview of user-facing configuration files and directories, see Configuration Files. AgentUse automatically loads .env files if present in your project directory:
Never commit .env files to version control. Add them to .gitignore.

Priority Order

Environment variables are loaded in this order (later overrides earlier):
  1. System environment variables
  2. .env file in current directory
  3. Command-line environment variables
Example:

Security Best Practices

Store Secrets Securely

Never hardcode API keys in agent files:

Use .gitignore

Always exclude sensitive files:

Validate Required Variables

For MCP servers that require specific environment variables, they will fail with clear error messages if the variables are not set.

Troubleshooting

Verify the environment variable is set:
If empty, set it:
Or use the auth command:
Check which key is being used:
When the Claude Code Subscription plugin is installed, subscription OAuth takes priority over the built-in Anthropic API-key transport.
Ensure you’re setting it before running the agent:

Next Steps

Model Configuration

Set up model providers and API keys

MCP Configuration

Configure MCP servers