Cori
Reference

Configuration reference

All ~/.cori/config.toml keys and environment variables that control Cori's behavior.

Config file location

~/.cori/config.toml

Read and write values with cori config:

cori config get temporal.host
cori config set temporal.host temporal.mycompany.com:7233

[temporal]

KeyTypeDefaultDescription
temporal.hoststring127.0.0.1:7233Temporal gRPC endpoint. If unset and nothing serves this address, cori run auto-spawns a dev server.

LLM provider keys

LLM provider API keys are not config — they live in the OS keychain (file fallback on headless machines) and are managed with cori login <provider> / cori logout <provider>, or from the desktop app under Manage → AI Providers. See Configure LLM providers.

Two cori config behaviors exist for convenience:

  • cori config get llm.<provider>.api_key reads through to the secret store, so scripts can still fetch the key.
  • cori config set llm.<provider>.api_key is rejected with a pointer to cori login — secrets are never written to config.toml.

The no-argument cori config get listing shows configured providers as llm.<provider>.api_key = <stored in keychain>, never the value.

[remotes]

KeyTypeDefaultDescription
remotes.hostsarray of strings["github.com", "gitlab.com", "bitbucket.org"]Allowed hosts for remote workflow refs.

Environment variables

Environment variables override the config file.

VariableOverridesDescription
CORI_TEMPORAL_TARGETtemporal.hostTemporal gRPC endpoint
OPENAI_API_KEYstored OpenAI keyPer-shell override of the keychain entry
ANTHROPIC_API_KEYstored Anthropic keyPer-shell override of the keychain entry
GEMINI_API_KEY / GOOGLE_API_KEYstored Gemini keyPer-shell override of the keychain entry
CORI_SECRETS_BACKEND—Force the secret-store backend: file or keychain (default: keychain when available)
CORI_ASSUME_YES—Set to 1 to skip first-run consent prompts
CORI_REAUTH_TIMEOUT_SECS—Timeout in seconds for re-authentication prompts
CORI_DENO—Path to the Deno binary if not on PATH

Credentials and secrets

Credentials (API keys, OAuth tokens) are stored in the OS keychain under the cori service. Machines without a usable keychain (headless Linux, CI) fall back to 0600 files under ~/.cori/credentials/. config.toml contains only non-secret configuration; a non-secret index under ~/.cori/credentials/ records which providers are configured so status displays never need to unlock the keychain. There is no general-purpose secrets vault in v1.

Store LLM keys with cori login <provider> (or the desktop app), never in config.toml — cori config set refuses secret keys.

On this page