Configuration reference
All ~/.cori/config.toml keys and environment variables that control Cori's behavior.
Config file location
~/.cori/config.toml
Read and write values with cori config:
cori config get temporal.host
cori config set temporal.host temporal.mycompany.com:7233[temporal]
| Key | Type | Default | Description |
|---|---|---|---|
temporal.host | string | 127.0.0.1:7233 | Temporal gRPC endpoint. If unset and nothing serves this address, cori run auto-spawns a dev server. |
LLM provider keys
LLM provider API keys are not config — they live in the OS keychain (file fallback on headless machines) and are managed with cori login <provider> / cori logout <provider>, or from the desktop app under Manage → AI Providers. See Configure LLM providers.
Two cori config behaviors exist for convenience:
cori config get llm.<provider>.api_keyreads through to the secret store, so scripts can still fetch the key.cori config set llm.<provider>.api_keyis rejected with a pointer tocori login— secrets are never written toconfig.toml.
The no-argument cori config get listing shows configured providers as llm.<provider>.api_key = <stored in keychain>, never the value.
[remotes]
| Key | Type | Default | Description |
|---|---|---|---|
remotes.hosts | array of strings | ["github.com", "gitlab.com", "bitbucket.org"] | Allowed hosts for remote workflow refs. |
Environment variables
Environment variables override the config file.
| Variable | Overrides | Description |
|---|---|---|
CORI_TEMPORAL_TARGET | temporal.host | Temporal gRPC endpoint |
OPENAI_API_KEY | stored OpenAI key | Per-shell override of the keychain entry |
ANTHROPIC_API_KEY | stored Anthropic key | Per-shell override of the keychain entry |
GEMINI_API_KEY / GOOGLE_API_KEY | stored Gemini key | Per-shell override of the keychain entry |
CORI_SECRETS_BACKEND | — | Force the secret-store backend: file or keychain (default: keychain when available) |
CORI_ASSUME_YES | — | Set to 1 to skip first-run consent prompts |
CORI_REAUTH_TIMEOUT_SECS | — | Timeout in seconds for re-authentication prompts |
CORI_DENO | — | Path to the Deno binary if not on PATH |
Credentials and secrets
Credentials (API keys, OAuth tokens) are stored in the OS keychain under the cori service. Machines without a usable keychain (headless Linux, CI) fall back to 0600 files under ~/.cori/credentials/. config.toml contains only non-secret configuration; a non-secret index under ~/.cori/credentials/ records which providers are configured so status displays never need to unlock the keychain. There is no general-purpose secrets vault in v1.
Store LLM keys with cori login <provider> (or the desktop app), never in config.toml — cori config set refuses secret keys.

