Skip to main content

Environment Variables Reference

Fabric reads environment variables from the process environment and, for user-managed secrets, from ~/.fabric/.env. API keys and bot tokens normally live in .env; when a subsystem defines a credential field in config.yaml (dashboard auth does), that config field is canonical and may use ${VAR} interpolation into .env. Some variables below are process-only overrides or internal bridge variables and should not be committed to .env just because they are documented here.

Fabric-prefixed names

FABRIC_ is the canonical namespace for Fabric-owned process variables. Keep user-facing behaviour in config.yaml; the Fabric-prefixed entries documented below are limited to bootstrap settings, deployment controls, diagnostics, and other process-level contracts. Names that exist only as Python constants are not environment variables and do not belong in this reference.

LLM Providers

VariableDescription
OPENROUTER_API_KEYOpenRouter API key (recommended for flexibility)
OPENROUTER_BASE_URLOverride the OpenRouter-compatible base URL
NOUS_BASE_URLOverride Nous Portal base URL (rarely needed; development/testing only)
NOUS_INFERENCE_BASE_URLOverride Nous inference endpoint directly
OPENAI_API_KEYAPI key for custom OpenAI-compatible endpoints (used with OPENAI_BASE_URL)
OPENAI_BASE_URLBase URL for custom endpoint (VLLM, SGLang, etc.)
LM_API_KEYAPI key for LM Studio (lmstudio provider). Often a placeholder for local servers
LM_BASE_URLLM Studio base URL (default: http://localhost:1234/v1)
COPILOT_GITHUB_TOKENGitHub token for Copilot API — first priority (OAuth gho_* or fine-grained PAT github_pat_*; classic PATs ghp_* are not supported)
GH_TOKENGitHub token — second priority for Copilot (also used by gh CLI)
GITHUB_TOKENGitHub token — third priority for Copilot; also used by Skills Hub for higher API rate limits and skill publishing
COPILOT_CLI_PATHOverride the GitHub Copilot ACP CLI binary path (default: copilot)
COPILOT_ACP_BASE_URLOverride Copilot ACP base URL
COPILOT_API_BASE_URLOverride the Copilot API base URL (copilot provider)
GLM_API_KEYz.ai / ZhipuAI GLM API key (z.ai)
ZAI_API_KEYAlias for GLM_API_KEY
Z_AI_API_KEYAlias for GLM_API_KEY
GLM_BASE_URLOverride z.ai base URL (default: https://api.z.ai/api/paas/v4)
KIMI_API_KEYKimi / Moonshot AI API key (moonshot.ai)
KIMI_CODING_API_KEYAlias key for the kimi-coding provider (accepted alongside KIMI_API_KEY)
KIMI_BASE_URLOverride Kimi base URL (default: https://api.moonshot.ai/v1)
KIMI_CN_API_KEYKimi / Moonshot China API key (moonshot.cn)
ARCEEAI_API_KEYArcee AI API key (chat.arcee.ai)
ARCEE_BASE_URLOverride Arcee base URL (default: https://api.arcee.ai/api/v1)
GMI_API_KEYGMI Cloud API key (gmicloud.ai)
GMI_BASE_URLOverride GMI Cloud base URL (default: https://api.gmi-serving.com/v1)
MINIMAX_API_KEYMiniMax API key — global endpoint (minimax.io). Not used by minimax-oauth (OAuth path uses browser login instead).
MINIMAX_BASE_URLOverride MiniMax base URL (default: https://api.minimax.io/anthropic — Fabric uses MiniMax's Anthropic Messages-compatible endpoint). Not used by minimax-oauth.
MINIMAX_CN_API_KEYMiniMax API key — China endpoint (minimaxi.com). Not used by minimax-oauth (OAuth path uses browser login instead).
MINIMAX_CN_BASE_URLOverride MiniMax China base URL (default: https://api.minimaxi.com/anthropic). Not used by minimax-oauth.
KILOCODE_API_KEYKilo Code API key (kilo.ai)
KILOCODE_BASE_URLOverride Kilo Code base URL (default: https://api.kilo.ai/api/gateway)
XIAOMI_API_KEYXiaomi MiMo API key (platform.xiaomimimo.com)
XIAOMI_BASE_URLOverride Xiaomi MiMo base URL (default: https://api.xiaomimimo.com/v1)
TOKENHUB_API_KEYTencent TokenHub API key (tokenhub.tencentmaas.com)
TOKENHUB_BASE_URLOverride Tencent TokenHub base URL (default: https://tokenhub.tencentmaas.com/v1)
AZURE_FOUNDRY_API_KEYMicrosoft Foundry / Azure OpenAI API key (ai.azure.com). Not needed when model.auth_mode: entra_id
AZURE_FOUNDRY_BASE_URLMicrosoft Foundry endpoint URL (e.g. https://<resource>.openai.azure.com/openai/v1 for OpenAI-style, or https://<resource>.services.ai.azure.com/anthropic for Anthropic-style)
AZURE_ANTHROPIC_KEYAzure Anthropic API key for provider: anthropic + base_url pointing at a Microsoft Foundry Claude deployment
AZURE_TENANT_IDEntra ID tenant ID (service-principal flows; honored by azure-identity when model.auth_mode: entra_id)
AZURE_CLIENT_IDEntra ID client ID (service principal, workload identity, or user-assigned managed identity)
AZURE_CLIENT_SECRETService principal secret used by EnvironmentCredential
AZURE_CLIENT_CERTIFICATE_PATHService principal certificate (alternative to AZURE_CLIENT_SECRET)
AZURE_FEDERATED_TOKEN_FILEFederated token file path for AKS Workload Identity / OIDC flows
AZURE_AUTHORITY_HOSTSovereign-cloud authority override (e.g. https://login.microsoftonline.us for Azure Government). See Azure Foundry guide
IDENTITY_ENDPOINT / MSI_ENDPOINTManaged Identity endpoint for App Service, Functions, and Container Apps; VMs usually use IMDS instead and do not set these
HF_TOKENHugging Face token for Inference Providers (huggingface.co/settings/tokens)
HF_BASE_URLOverride Hugging Face base URL (default: https://router.huggingface.co/v1)
GOOGLE_API_KEYGoogle AI Studio API key (aistudio.google.com/app/apikey)
GEMINI_API_KEYAlias for GOOGLE_API_KEY
GEMINI_BASE_URLOverride Google AI Studio base URL
ANTHROPIC_API_KEYAnthropic Console API key (console.anthropic.com); paired with native Anthropic unless ANTHROPIC_BASE_URL explicitly binds it to another Anthropic Messages endpoint
ANTHROPIC_BASE_URLOverride the Anthropic Messages endpoint and explicitly bind ANTHROPIC_API_KEY to it
DASHSCOPE_API_KEYQwen Cloud (Alibaba DashScope) API key for Qwen models (modelstudio.console.alibabacloud.com)
DASHSCOPE_BASE_URLCustom DashScope base URL (default: https://dashscope-intl.aliyuncs.com/compatible-mode/v1; use https://dashscope.aliyuncs.com/compatible-mode/v1 for mainland-China region)
ALIBABA_CODING_PLAN_API_KEYQwen Coding Plan API key (alibaba-coding-plan provider)
ALIBABA_CODING_PLAN_BASE_URLOverride the Qwen Coding Plan base URL
DEEPSEEK_API_KEYDeepSeek API key for direct DeepSeek access (platform.deepseek.com)
DEEPSEEK_BASE_URLCustom DeepSeek API base URL
NOVITA_API_KEYNovitaAI API key — AI-native cloud for Model API, Agent Sandbox, and GPU Cloud (novita.ai/settings/key-management)
NOVITA_BASE_URLOverride NovitaAI base URL (default: https://api.novita.ai/openai/v1)
NVIDIA_API_KEYNVIDIA NIM API key — Nemotron and open models (build.nvidia.com)
NVIDIA_BASE_URLOverride NVIDIA base URL (default: https://integrate.api.nvidia.com/v1; set to http://localhost:8000/v1 for a local NIM endpoint)
STEPFUN_API_KEYStepFun API key — Step-series models (platform.stepfun.com)
STEPFUN_BASE_URLOverride StepFun base URL (default: https://api.stepfun.com/v1)
OLLAMA_API_KEYOllama Cloud API key — managed Ollama catalog without local GPU (ollama.com/settings/keys)
OLLAMA_BASE_URLOverride Ollama Cloud base URL (default: https://ollama.com/v1)
XAI_API_KEYxAI (Grok) API key for chat + TTS + web search (console.x.ai)
XAI_BASE_URLOverride xAI base URL (default: https://api.x.ai/v1)
MISTRAL_API_KEYMistral API key for Voxtral TTS and Voxtral STT (console.mistral.ai)
AWS_REGIONAWS region for Bedrock inference (e.g. us-east-1, eu-central-1). Read by boto3.
AWS_PROFILEAWS named profile for Bedrock authentication (reads ~/.aws/credentials). Leave unset to use default boto3 credential chain.
BEDROCK_BASE_URLOverride Bedrock runtime base URL (default: https://bedrock-runtime.us-east-1.amazonaws.com; usually leave unset and use AWS_REGION instead)
OPENCODE_ZEN_API_KEYOpenCode Zen API key — pay-as-you-go access to curated models (opencode.ai)
OPENCODE_ZEN_BASE_URLOverride OpenCode Zen base URL
OPENCODE_GO_API_KEYOpenCode Go API key — $10/month subscription for open models (opencode.ai)
OPENCODE_GO_BASE_URLOverride OpenCode Go base URL
VOICE_TOOLS_OPENAI_KEYPreferred OpenAI key for OpenAI speech-to-text and text-to-speech providers
FABRIC_HOMEOverride Fabric config directory (default: ~/.fabric). Also scopes the gateway PID file and systemd service name, so multiple installations can run concurrently

Provider Auth (OAuth)

Fabric authenticates to native Anthropic with ANTHROPIC_API_KEY only — there is no OAuth/subscription login for Anthropic, and Fabric does not read or reuse Claude Code's own credential files (see NOTICE). Other providers (Nous, OpenAI Codex, xAI, Qwen, MiniMax) support OAuth device-code or browser logins via fabric auth add <provider> / fabric model.

VariableDescription

Tool APIs

VariableDescription
PARALLEL_API_KEYAI-native web search (parallel.ai)
FIRECRAWL_API_KEYWeb scraping and cloud browser (firecrawl.dev)
FIRECRAWL_API_URLCustom Firecrawl API endpoint for self-hosted instances (optional)
TAVILY_API_KEYTavily API key for AI-native web search, extract, and crawl (app.tavily.com)
SEARXNG_URLSearXNG instance URL for free self-hosted web search — no API key required (searxng.github.io)
TAVILY_BASE_URLOverride the Tavily API endpoint. Useful for corporate proxies and self-hosted Tavily-compatible search backends. Same pattern as GROQ_BASE_URL.
EXA_API_KEYExa API key for AI-native web search and contents (exa.ai)
BRAVE_SEARCH_API_KEYBrave Search API subscription token for web search (free tier available) (brave.com/search/api)
BROWSERBASE_API_KEYBrowser automation (browserbase.com)
BROWSERBASE_PROJECT_IDBrowserbase project ID
BROWSER_USE_API_KEYBrowser Use cloud browser API key (browser-use.com)
FIRECRAWL_BROWSER_TTLFirecrawl browser session TTL in seconds (default: 300)
BROWSER_CDP_URLChrome DevTools Protocol URL for local browser (set via /browser connect, e.g. ws://localhost:9222)
CAMOFOX_URLCamofox local anti-detection browser URL (default: http://localhost:9377)
CAMOFOX_USER_IDOptional externally managed Camofox user ID for shared visible sessions
CAMOFOX_SESSION_KEYOptional Camofox session key used when creating tabs for CAMOFOX_USER_ID
CAMOFOX_ADOPT_EXISTING_TABSet to true to reuse an existing Camofox tab before creating a new one
BROWSER_INACTIVITY_TIMEOUTBrowser session inactivity timeout in seconds
AGENT_BROWSER_ARGSExtra Chromium launch flags (comma- or newline-separated). Fabric auto-injects --no-sandbox,--disable-dev-shm-usage when running as root or on AppArmor-restricted unprivileged user namespaces (Ubuntu 23.10+, DGX Spark, many container images); set this manually only to override or add other flags.
AGENT_BROWSER_ENGINEBrowser engine for local mode: auto (default — Chromium-family via CDP), or a specific engine override.
FAL_KEYImage generation (fal.ai)
KREA_API_KEYKrea API key for Krea 2 image generation (krea.ai)
GROQ_API_KEYGroq Whisper STT API key (groq.com)
ELEVENLABS_API_KEYElevenLabs premium TTS voices (elevenlabs.io)
STT_GROQ_MODELOverride the Groq STT model (default: whisper-large-v3-turbo)
GROQ_BASE_URLOverride the Groq OpenAI-compatible STT endpoint
STT_OPENAI_MODELOverride the OpenAI STT model (default: whisper-1)
STT_OPENAI_BASE_URLOverride the OpenAI-compatible STT endpoint
HONCHO_API_KEYCross-session user modeling (honcho.dev)
HONCHO_BASE_URLBase URL for self-hosted Honcho instances (default: Honcho cloud). No API key required for local instances
HINDSIGHT_TIMEOUTTimeout in seconds for Hindsight memory-provider API calls (default: 60). Bump this if your Hindsight instance is slow to respond during /sync or on_session_switch and you're seeing timeouts in errors.log.
SUPERMEMORY_API_KEYSemantic long-term memory with profile recall and session ingest (supermemory.ai)
DAYTONA_API_KEYDaytona cloud sandboxes (daytona.io)

Skill API Keys

Secrets consumed by specific bundled / optional skills. Each is only needed if you use the corresponding skill.

VariableUsed by skillDescription
NOTION_API_KEYnotionNotion integration token.
LINEAR_API_KEYlinearLinear personal API key.
AIRTABLE_API_KEYairtableAirtable personal access token.
TENOR_API_KEYgif-searchTenor API key for GIF search.

Langfuse Observability

Environment variables for the bundled observability/langfuse plugin. Set these in ~/.fabric/.env. The plugin must also be enabled (fabric plugins enable observability/langfuse, or check the box in fabric plugins) before any of these take effect.

VariableDescription
LANGFUSE_PUBLIC_KEYLangfuse project public key (pk-lf-...). Required.
LANGFUSE_SECRET_KEYLangfuse project secret key (sk-lf-...). Required.

Nous Tool Gateway

These variables configure a Managed Tool Route for compatible hosted accounts or self-hosted gateway deployments. Most users should configure the route through fabric tools instead of setting these variables directly.

VariableDescription
TOOL_GATEWAY_DOMAINBase domain for Tool Gateway routing (default: nousresearch.com)
TOOL_GATEWAY_SCHEMEHTTP or HTTPS scheme for gateway URLs (default: https)
TOOL_GATEWAY_USER_TOKENAuth token for the Tool Gateway (normally auto-populated from Nous auth)
FIRECRAWL_GATEWAY_URLOverride URL for the Firecrawl gateway endpoint specifically

Terminal Backend

VariableDescription
TERMINAL_ENVBackend: local, docker, ssh, singularity, modal, daytona
TERMINAL_DOCKER_IMAGEDocker image (default: nikolaik/python-nodejs:python3.11-nodejs20)
TERMINAL_DOCKER_FORWARD_ENVJSON array of env var names to explicitly forward into Docker terminal sessions. Note: skill-declared required_environment_variables are forwarded automatically — you only need this for vars not declared by any skill.
TERMINAL_DOCKER_VOLUMESAdditional Docker volume mounts (comma-separated host:container pairs)
TERMINAL_DOCKER_MOUNT_CWD_TO_WORKSPACEAdvanced opt-in: mount the launch cwd into Docker /workspace (true/false, default: false)
TERMINAL_SINGULARITY_IMAGESingularity image or .sif path
TERMINAL_MODAL_IMAGEModal container image
TERMINAL_DAYTONA_IMAGEDaytona sandbox image
TERMINAL_TIMEOUTCommand timeout in seconds
TERMINAL_LIFETIME_SECONDSMax lifetime for terminal sessions in seconds
TERMINAL_CWDDeprecated direct override for gateway/cron terminal sessions. Prefer terminal.cwd in config.yaml; CLI still uses the launch directory.
SUDO_PASSWORDEnable sudo without interactive prompt

For cloud sandbox backends, persistence is filesystem-oriented. TERMINAL_LIFETIME_SECONDS controls when Fabric cleans up an idle terminal session, and later resumes may recreate the sandbox rather than keep the same live processes running.

SSH Backend

VariableDescription
TERMINAL_SSH_HOSTRemote server hostname
TERMINAL_SSH_USERSSH username
TERMINAL_SSH_PORTSSH port (default: 22)
TERMINAL_SSH_KEYPath to private key
TERMINAL_SSH_PERSISTENTOverride persistent shell for SSH (default: follows TERMINAL_PERSISTENT_SHELL)

Container Resources (Docker, Singularity, Modal, Daytona)

VariableDescription
TERMINAL_CONTAINER_CPUCPU cores (default: 1)
TERMINAL_CONTAINER_MEMORYMemory in MB (default: 5120)
TERMINAL_CONTAINER_DISKDisk in MB (default: 51200)
TERMINAL_CONTAINER_PERSISTENTPersist container filesystem across sessions (default: true)
TERMINAL_SANDBOX_DIRHost directory for workspaces and overlays (default: ~/.fabric/sandboxes/)

Persistent Shell

VariableDescription
TERMINAL_PERSISTENT_SHELLEnable persistent shell for non-local backends (default: true). Also settable via terminal.persistent_shell in config.yaml
TERMINAL_LOCAL_PERSISTENTEnable persistent shell for local backend (default: false)

Messaging

VariableDescription
TELEGRAM_BOT_TOKENTelegram bot token (from @BotFather)
TELEGRAM_ALLOWED_USERSComma-separated user IDs allowed to use the bot (applies to DMs, groups, and forums)
TELEGRAM_ALLOW_ALL_USERSAllow any Telegram user to trigger the bot (dev only).
TELEGRAM_GROUP_ALLOWED_USERSComma-separated sender user IDs authorized in groups/forums only (does NOT grant DM access). Chat-ID-shaped values (starting with -) are still honored as chat IDs, with a deprecation warning.
TELEGRAM_GROUP_ALLOWED_CHATSComma-separated group/forum chat IDs; any member is authorized
TELEGRAM_HOME_CHANNELDefault Telegram chat/channel for cron delivery
TELEGRAM_HOME_CHANNEL_NAMEDisplay name for the Telegram home channel
TELEGRAM_CRON_THREAD_IDForum topic ID to receive cron deliveries; overrides TELEGRAM_HOME_CHANNEL_THREAD_ID for cron only. Use in topic mode so replies to cron messages open a new session instead of hitting the system lobby.
TELEGRAM_WEBHOOK_URLPublic HTTPS URL for webhook mode (enables webhook instead of polling)
TELEGRAM_WEBHOOK_PORTLocal listen port for webhook server (default: 8443)
TELEGRAM_WEBHOOK_SECRETSecret token Telegram echoes back in each update for verification. Required whenever TELEGRAM_WEBHOOK_URL is set — the gateway refuses to start without it (GHSA-3vpc-7q5r-276h). Generate with openssl rand -hex 32.
TELEGRAM_REACTIONSEnable emoji reactions on messages during processing (default: false)
TELEGRAM_REQUIRE_MENTIONRequire an explicit trigger before responding in Telegram groups. Equivalent to telegram.require_mention in config.yaml.
TELEGRAM_MENTION_PATTERNSJSON array, newline-separated list, or comma-separated list of regex wake-word patterns accepted when Telegram group mention gating is enabled. Equivalent to telegram.mention_patterns.
TELEGRAM_EXCLUSIVE_BOT_MENTIONSWhen enabled, explicit @...bot mentions in Telegram groups route only to the mentioned bot usernames before reply or wake-word fallbacks run. Default: true. Equivalent to telegram.exclusive_bot_mentions.
TELEGRAM_REPLY_TO_MODEReply-reference behavior: off, first (default), or all. Matches the Discord pattern.
TELEGRAM_IGNORED_THREADSComma-separated Telegram forum topic/thread IDs where the bot never responds
TELEGRAM_PROXYProxy URL for Telegram connections — overrides HTTPS_PROXY. Supports http://, https://, socks5://
DISCORD_BOT_TOKENDiscord bot token
DISCORD_ALLOWED_USERSComma-separated Discord user IDs allowed to use the bot
DISCORD_ALLOW_ALL_USERSAllow any Discord user to trigger the bot (dev only).
DISCORD_ALLOWED_ROLESComma-separated Discord role IDs allowed to use the bot (OR with DISCORD_ALLOWED_USERS). Auto-enables the Members intent. Useful when moderation teams churn — role grants propagate automatically.
DISCORD_ALLOWED_CHANNELSComma-separated Discord channel IDs. When set, the bot only responds in these channels (plus DMs if allowed). Overrides config.yaml discord.allowed_channels.
DISCORD_PROXYProxy URL for Discord connections — overrides HTTPS_PROXY. Supports http://, https://, socks5://
DISCORD_HOME_CHANNELDefault Discord channel for cron delivery
DISCORD_HOME_CHANNEL_NAMEDisplay name for the Discord home channel
DISCORD_COMMAND_SYNC_POLICYDiscord slash-command startup sync policy: safe (diff and reconcile), bulk (legacy tree.sync()), or off
DISCORD_REQUIRE_MENTIONRequire an @mention before responding in server channels
DISCORD_FREE_RESPONSE_CHANNELSComma-separated channel IDs where mention is not required
DISCORD_AUTO_THREADAuto-thread long replies when supported
DISCORD_ALLOW_ANY_ATTACHMENTWhen true, accept attachments of any file type (not just the built-in PDF/text/zip/office allowlist). Unknown types are cached and surfaced to the agent as a local path so it can inspect them via terminal / read_file / ffprobe. Default false.
DISCORD_MAX_ATTACHMENT_BYTESMaximum bytes per attachment the gateway will cache. Default 33554432 (32 MiB). Set to 0 for no cap (attachments are held in memory while being written).
DISCORD_REACTIONSEnable emoji reactions on messages during processing (default: true)
DISCORD_IGNORED_CHANNELSComma-separated channel IDs where the bot never responds
DISCORD_NO_THREAD_CHANNELSComma-separated channel IDs where bot responds without auto-threading
DISCORD_REPLY_TO_MODEReply-reference behavior: off, first (default), or all
DISCORD_ALLOW_MENTION_EVERYONEAllow the bot to ping @everyone/@here (default: false). See Mention Control.
DISCORD_ALLOW_MENTION_ROLESAllow the bot to ping @role mentions (default: false).
DISCORD_ALLOW_MENTION_USERSAllow the bot to ping individual @user mentions (default: true).
DISCORD_ALLOW_MENTION_REPLIED_USERPing the author when replying to their message (default: true).
SLACK_BOT_TOKENSlack bot token (xoxb-...)
SLACK_APP_TOKENSlack app-level token (xapp-..., required for Socket Mode)
SLACK_ALLOWED_USERSComma-separated Slack user IDs
SLACK_ALLOW_ALL_USERSAllow any Slack user to trigger the bot (dev only).
SLACK_HOME_CHANNELDefault Slack channel for cron delivery
SLACK_HOME_CHANNEL_NAMEDisplay name for the Slack home channel
GOOGLE_CHAT_PROJECT_IDGCP project hosting the Pub/Sub topic (falls back to GOOGLE_CLOUD_PROJECT)
GOOGLE_CHAT_SUBSCRIPTION_NAMEFull Pub/Sub subscription path, projects/{proj}/subscriptions/{sub} (legacy alias: GOOGLE_CHAT_SUBSCRIPTION)
GOOGLE_CHAT_SERVICE_ACCOUNT_JSONPath to Service Account JSON, or the JSON inline (falls back to GOOGLE_APPLICATION_CREDENTIALS)
GOOGLE_CHAT_ALLOWED_USERSComma-separated user emails allowed to chat with the bot
GOOGLE_CHAT_ALLOW_ALL_USERSAllow any Google Chat user to trigger the bot (dev only)
GOOGLE_CHAT_HOME_CHANNELDefault space (e.g. spaces/AAAA...) for cron delivery
GOOGLE_CHAT_HOME_CHANNEL_NAMEDisplay name for the Google Chat home space
GOOGLE_CHAT_MAX_MESSAGESPub/Sub FlowControl max in-flight messages (default: 1)
GOOGLE_CHAT_MAX_BYTESPub/Sub FlowControl max in-flight bytes (default: 16777216, 16 MiB)
GOOGLE_CHAT_BOOTSTRAP_SPACESComma-separated extra space IDs to probe at startup when resolving the bot's own users/{id}
GOOGLE_CHAT_DEBUG_RAWSet to any value to log redacted Pub/Sub envelopes at DEBUG level (debugging only)
WHATSAPP_ENABLEDEnable the WhatsApp bridge (true/false)
WHATSAPP_MODEbot (separate number) or self-chat (message yourself)
WHATSAPP_ALLOWED_USERSComma-separated phone numbers (with country code, no +), or * to allow all senders
WHATSAPP_ALLOW_ALL_USERSAllow all WhatsApp senders without an allowlist (true/false)
WHATSAPP_HOME_CHANNELDefault chat ID for cron / notification delivery.
WHATSAPP_HOME_CHANNEL_NAMEDisplay name for the WhatsApp home channel.
WHATSAPP_DEBUGLog raw message events in the bridge for troubleshooting (true/false)
WHATSAPP_CLOUD_PHONE_NUMBER_IDMeta Phone Number ID from the WhatsApp Business Cloud API (15–17 digits; not the phone number itself)
WHATSAPP_CLOUD_ACCESS_TOKENMeta access token (starts with EAA); temporary tokens expire after 24h, System User tokens are permanent
WHATSAPP_CLOUD_APP_SECRET32-char hex app secret used to verify inbound webhook signatures
WHATSAPP_CLOUD_VERIFY_TOKENShared secret for Meta's webhook verification handshake (auto-generated by the setup wizard)
WHATSAPP_CLOUD_ALLOWED_USERSComma-separated wa_ids (phone numbers with country code, no +) allowed to message the bot
WHATSAPP_CLOUD_ALLOW_ALL_USERSAllow all WhatsApp Cloud senders without an allowlist (true/false)
WHATSAPP_CLOUD_APP_IDOptional Meta App ID (for future analytics integration)
WHATSAPP_CLOUD_WABA_IDOptional WhatsApp Business Account ID (for future analytics integration)
WHATSAPP_CLOUD_WEBHOOK_HOSTInterface the inbound webhook server binds to (default 0.0.0.0)
WHATSAPP_CLOUD_WEBHOOK_PORTPort the inbound webhook server binds to (default 8090)
WHATSAPP_CLOUD_WEBHOOK_PATHURL path Meta posts inbound messages to (default /whatsapp/webhook)
WHATSAPP_CLOUD_API_VERSIONMeta Graph API version to call (default v20.0)
WHATSAPP_CLOUD_HOME_CHANNELwa_id to use as the bot's home channel (for cron jobs etc.)
WHATSAPP_CLOUD_DM_POLICYDM gating for the Cloud adapter (open/allowlist/disabled); falls back to WHATSAPP_DM_POLICY when unset
WHATSAPP_CLOUD_ALLOW_FROMComma-separated senders allowed when dm_policy: allowlist (bare wa_ids; Baileys-style JIDs are normalized)
WHATSAPP_CLOUD_GROUP_POLICYGroup gating for the Cloud adapter (open/allowlist/disabled); falls back to WHATSAPP_GROUP_POLICY when unset
WHATSAPP_CLOUD_GROUP_ALLOW_FROMComma-separated group chat IDs allowed when group_policy: allowlist
SIGNAL_HTTP_URLsignal-cli daemon HTTP endpoint (for example http://127.0.0.1:8080)
SIGNAL_ACCOUNTBot phone number in E.164 format
SIGNAL_ALLOWED_USERSComma-separated E.164 phone numbers or UUIDs
SIGNAL_GROUP_ALLOWED_USERSComma-separated group IDs, or * for all groups
SIGNAL_HOME_CHANNEL_NAMEDisplay name for the Signal home channel
SIGNAL_IGNORE_STORIESIgnore Signal stories/status updates
SIGNAL_ALLOW_ALL_USERSAllow all Signal users without an allowlist
TWILIO_ACCOUNT_SIDTwilio Account SID (shared with telephony skill)
TWILIO_AUTH_TOKENTwilio Auth Token (shared with telephony skill; also used for webhook signature validation)
TWILIO_PHONE_NUMBERTwilio phone number in E.164 format (shared with telephony skill)
SMS_WEBHOOK_URLPublic URL for Twilio signature validation — must match the webhook URL in Twilio Console (required)
SMS_WEBHOOK_PORTWebhook listener port for inbound SMS (default: 8080)
SMS_WEBHOOK_HOSTWebhook bind address (default: 0.0.0.0)
SMS_INSECURE_NO_SIGNATURESet to true to disable Twilio signature validation (local dev only — not for production)
SMS_ALLOWED_USERSComma-separated E.164 phone numbers allowed to chat
SMS_ALLOW_ALL_USERSAllow all SMS senders without an allowlist
SMS_HOME_CHANNELPhone number for cron job / notification delivery
SMS_HOME_CHANNEL_NAMEDisplay name for the SMS home channel
EMAIL_ADDRESSEmail address for the Email gateway adapter
EMAIL_PASSWORDPassword or app password for the email account
EMAIL_IMAP_HOSTIMAP hostname for the email adapter
EMAIL_IMAP_PORTIMAP port
EMAIL_SMTP_HOSTSMTP hostname for the email adapter
EMAIL_SMTP_PORTSMTP port
EMAIL_ALLOWED_USERSComma-separated email addresses allowed to message the bot
EMAIL_HOME_ADDRESSDefault recipient for proactive email delivery
EMAIL_HOME_ADDRESS_NAMEDisplay name for the email home target
EMAIL_POLL_INTERVALEmail polling interval in seconds
EMAIL_ALLOW_ALL_USERSAllow all inbound email senders
DINGTALK_CLIENT_IDDingTalk bot AppKey from developer portal (open.dingtalk.com)
DINGTALK_CLIENT_SECRETDingTalk bot AppSecret from developer portal
DINGTALK_ALLOWED_USERSComma-separated DingTalk user IDs allowed to message the bot
DINGTALK_WEBHOOK_URLStatic robot webhook URL for cross-platform / cron delivery.
DINGTALK_HOME_CHANNELDefault conversation ID for cron / notification delivery.
DINGTALK_HOME_CHANNEL_NAMEDisplay name for the DingTalk home channel.
FEISHU_APP_IDFeishu/Lark bot App ID from open.feishu.cn
FEISHU_APP_SECRETFeishu/Lark bot App Secret
FEISHU_DOMAINfeishu (China) or lark (international). Default: feishu
FEISHU_CONNECTION_MODEwebsocket (recommended) or webhook. Default: websocket
FEISHU_ENCRYPT_KEYOptional encryption key for webhook mode
FEISHU_VERIFICATION_TOKENOptional verification token for webhook mode
FEISHU_ALLOWED_USERSComma-separated Feishu user IDs allowed to message the bot
FEISHU_ALLOW_BOTSnone (default) / mentions / all — accept inbound messages from other bots. See bot-to-bot messaging
FEISHU_REQUIRE_MENTIONtrue (default) / false — whether group messages must @mention the bot. Override per-chat via group_rules.<chat_id>.require_mention.
FEISHU_HOME_CHANNELFeishu chat ID for cron delivery and notifications
FEISHU_HOME_CHANNEL_NAMEDisplay name for the Feishu home channel.
FEISHU_ALLOW_ALL_USERSAllow any Feishu user to trigger the bot (dev only).
WECOM_BOT_IDWeCom AI Bot ID from admin console
WECOM_SECRETWeCom AI Bot secret
WECOM_WEBSOCKET_URLCustom WebSocket URL (default: wss://openws.work.weixin.qq.com)
WECOM_ALLOWED_USERSComma-separated WeCom user IDs allowed to message the bot
WECOM_HOME_CHANNELWeCom chat ID for cron delivery and notifications
WECOM_CALLBACK_CORP_IDWeCom enterprise Corp ID for callback self-built app
WECOM_CALLBACK_CORP_SECRETCorp secret for the self-built app
WECOM_CALLBACK_AGENT_IDAgent ID of the self-built app
WECOM_CALLBACK_TOKENCallback verification token
WECOM_CALLBACK_ENCODING_AES_KEYAES key for callback encryption
WECOM_CALLBACK_HOSTCallback server bind address (default: 0.0.0.0)
WECOM_CALLBACK_PORTCallback server port (default: 8645)
WECOM_CALLBACK_ALLOWED_USERSComma-separated user IDs for allowlist
WECOM_CALLBACK_ALLOW_ALL_USERSSet true to allow all users without an allowlist
WEIXIN_ACCOUNT_IDWeixin account ID obtained via QR login through iLink Bot API
WEIXIN_TOKENWeixin authentication token obtained via QR login through iLink Bot API
WEIXIN_BASE_URLOverride Weixin iLink Bot API base URL (default: https://ilinkai.weixin.qq.com)
WEIXIN_CDN_BASE_URLOverride Weixin CDN base URL for media (default: https://novac2c.cdn.weixin.qq.com/c2c)
WEIXIN_DM_POLICYDirect message policy: open, allowlist, pairing, disabled (default: open)
WEIXIN_GROUP_POLICYGroup message policy: open, allowlist, disabled (default: disabled)
WEIXIN_ALLOWED_USERSComma-separated Weixin user IDs allowed to DM the bot
WEIXIN_GROUP_ALLOWED_USERSComma-separated Weixin group chat IDs (not member user IDs) allowed to interact with the bot. The variable name is legacy — it expects group IDs. Only takes effect when iLink actually delivers group events; QR-login iLink bot identities (...@im.bot) typically don't receive ordinary WeChat group messages.
WEIXIN_HOME_CHANNELWeixin chat ID for cron delivery and notifications
WEIXIN_HOME_CHANNEL_NAMEDisplay name for the Weixin home channel
WEIXIN_ALLOW_ALL_USERSAllow all Weixin users without an allowlist (true/false)
BLUEBUBBLES_SERVER_URLBlueBubbles server URL (e.g. http://192.168.1.10:1234)
BLUEBUBBLES_PASSWORDBlueBubbles server password
BLUEBUBBLES_WEBHOOK_HOSTWebhook listener bind address (default: 127.0.0.1)
BLUEBUBBLES_WEBHOOK_PORTWebhook listener port (default: 8645)
BLUEBUBBLES_HOME_CHANNELPhone/email for cron/notification delivery
BLUEBUBBLES_ALLOWED_USERSComma-separated authorized users
BLUEBUBBLES_ALLOW_ALL_USERSAllow all users (true/false)
QQ_APP_IDQQ Bot App ID from q.qq.com
QQ_CLIENT_SECRETQQ Bot App Secret from q.qq.com
QQ_STT_API_KEYAPI key for external STT fallback provider (optional, used when QQ built-in ASR returns no text)
QQ_STT_BASE_URLBase URL for external STT provider (optional)
QQ_STT_MODELModel name for external STT provider (optional)
QQ_ALLOWED_USERSComma-separated QQ user openIDs allowed to message the bot
QQ_GROUP_ALLOWED_USERSComma-separated QQ group IDs for group @-message access
QQ_ALLOW_ALL_USERSAllow all users (true/false, overrides QQ_ALLOWED_USERS)
QQBOT_HOME_CHANNELQQ user/group openID for cron delivery and notifications
QQBOT_HOME_CHANNEL_NAMEDisplay name for the QQ home channel
QQ_PORTAL_HOSTOverride the QQ portal host (set to sandbox.q.qq.com to route through the sandbox gateway; default: q.qq.com).
QQ_SANDBOXEnable QQ sandbox mode for development testing (true/false)
MATTERMOST_URLMattermost server URL (e.g. https://mm.example.com)
MATTERMOST_TOKENBot token or personal access token for Mattermost
MATTERMOST_ALLOWED_USERSComma-separated Mattermost user IDs allowed to message the bot
MATTERMOST_ALLOW_ALL_USERSAllow any Mattermost user to trigger the bot (dev only).
MATTERMOST_ALLOWED_CHANNELSIf set, the bot only responds in these channels (whitelist).
MATTERMOST_HOME_CHANNELChannel ID for proactive message delivery (cron, notifications)
MATTERMOST_REQUIRE_MENTIONRequire @mention in channels (default: true). Set to false to respond to all messages.
MATTERMOST_FREE_RESPONSE_CHANNELSComma-separated channel IDs where bot responds without @mention
MATTERMOST_REPLY_MODEReply style: thread (threaded replies) or off (flat messages, default)
MATRIX_HOMESERVERMatrix homeserver URL (e.g. https://matrix.org)
MATRIX_ACCESS_TOKENMatrix access token for bot authentication
MATRIX_USER_IDMatrix user ID (e.g. @assistant:matrix.org) — required for password login, optional with access token
MATRIX_PASSWORDMatrix password (alternative to access token)
MATRIX_ALLOWED_USERSComma-separated Matrix user IDs allowed to message the bot (e.g. @alice:matrix.org)
MATRIX_ALLOW_ALL_USERSAllow any Matrix user to trigger the bot (dev only).
MATRIX_HOME_CHANNELDefault room ID for cron / notification delivery.
MATRIX_HOME_CHANNEL_NAMEDisplay name for the Matrix home room.
MATRIX_ALLOWED_ROOMSComma-separated Matrix room IDs allowed to trigger bot responses
MATRIX_HOME_ROOMRoom ID for proactive message delivery (e.g. !abc123:matrix.org)
MATRIX_ENCRYPTIONEnable end-to-end encryption (true/false, default: false)
MATRIX_E2EE_MODEMatrix E2EE behavior: off, optional, or required. Overrides MATRIX_ENCRYPTION when set.
MATRIX_DEVICE_IDStable Matrix device ID for E2EE persistence across restarts (e.g. BOT_DEVICE). Without this, E2EE keys rotate every startup and historic-room decrypt breaks.
MATRIX_REACTIONSEnable processing-lifecycle emoji reactions on inbound messages (default: true). Set to false to disable.
MATRIX_REQUIRE_MENTIONRequire @mention in rooms (default: true). Set to false to respond to all messages.
MATRIX_FREE_RESPONSE_ROOMSComma-separated room IDs where bot responds without @mention
MATRIX_IGNORE_USER_PATTERNSComma-separated regular expressions for Matrix bridge/appservice ghost user IDs to ignore
MATRIX_PROCESS_NOTICESProcess inbound Matrix m.notice events (default: false)
MATRIX_SESSION_SCOPEMatrix session scope for project rooms: auto, room, or thread (default: auto)
MATRIX_TOOLS_ALLOW_CROSS_ROOMAllow Matrix tools to target explicit rooms other than the current room (default: false)
MATRIX_TOOLS_ALLOW_CROSS_ROOM_DESTRUCTIVEAllow cross-room Matrix redaction/invite-like tools; requires MATRIX_TOOLS_ALLOW_CROSS_ROOM=true (default: false)
MATRIX_TOOLS_ALLOW_REDACTIONAllow Matrix message redaction tool execution (default: false)
MATRIX_TOOLS_ALLOW_INVITESAllow Matrix invite tool execution (default: false)
MATRIX_TOOLS_ALLOW_ROOM_CREATEAllow Matrix room creation tool execution (default: false)
MATRIX_ALLOW_ROOM_MENTIONSAllow outbound @room mentions to notify all room members (default: false)
MATRIX_AUTO_THREADAuto-create threads for room messages (default: true)
MATRIX_DM_AUTO_THREADAuto-create threads for DM messages in Matrix (default: false)
MATRIX_DM_MENTION_THREADSCreate a thread when bot is @mentioned in a DM (default: false)
MATRIX_APPROVAL_REQUIRE_SENDERRequire approval/model-picker reactions to come from the original requester when known (default: true)
MATRIX_APPROVAL_TIMEOUT_SECONDSTimeout for Matrix reaction approval/model-picker prompts (default: 300)
MATRIX_ALLOW_PUBLIC_ROOMSAllow Matrix room-creation tools to create public rooms (default: false)
MATRIX_MAX_MEDIA_BYTESMaximum Matrix media upload/download size in bytes (default: 104857600)
MATRIX_RECOVERY_KEYRecovery key for cross-signing verification after device key rotation. Recommended for E2EE setups with cross-signing enabled.
MATRIX_RECOVERY_KEY_OUTPUT_FILEOptional one-time path for a generated Matrix recovery key. Created with mode 0600 and never overwritten.
HASS_TOKENHome Assistant Long-Lived Access Token (enables HA platform + tools)
HASS_URLHome Assistant URL (default: http://homeassistant.local:8123)
WEBHOOK_ENABLEDEnable the webhook platform adapter (true/false)
WEBHOOK_PORTHTTP server port for receiving webhooks (default: 8644)
WEBHOOK_SECRETGlobal HMAC secret for webhook signature validation (used as fallback when routes don't specify their own)
API_SERVER_ENABLEDEnable the OpenAI-compatible API server (true/false). Runs alongside other platforms.
API_SERVER_KEYBearer token for API server authentication. Required whenever the API server is enabled.
API_SERVER_CORS_ORIGINSComma-separated browser origins allowed to call the API server directly (for example http://localhost:3000,http://127.0.0.1:3000). Default: disabled.
API_SERVER_PORTPort for the API server (default: 8642)
API_SERVER_HOSTHost/bind address for the API server (default: 127.0.0.1). API_SERVER_KEY is still required on loopback; use a narrow API_SERVER_CORS_ORIGINS allowlist for browser access.
API_SERVER_MODEL_NAMEModel name advertised on /v1/models. Defaults to the profile name (or fabric-agent for the default profile). Useful for multi-user setups where frontends like Open WebUI need distinct model names per connection.
GATEWAY_PROXY_URLURL of a remote Fabric API server to forward messages to (proxy mode). When set, the gateway handles platform I/O only — all agent work is delegated to the remote server. Also configurable via gateway.proxy_url in config.yaml.
GATEWAY_PROXY_KEYBearer token for authenticating with the remote API server in proxy mode. Must match API_SERVER_KEY on the remote host.
GATEWAY_ALLOWED_USERSComma-separated user IDs allowed across all platforms
GATEWAY_ALLOW_ALL_USERSAllow all users without allowlists (true/false, default: false)

Web Dashboard & Fabric

Auth for the web dashboard and for connecting Fabric to a remote backend is configured under dashboard in config.yaml.

Three dashboard-auth providers ship in the box. For an internet-facing dashboard, prefer the self-hosted OIDC provider configured under dashboard.oauth.self_hosted. The bundled username/password provider is configured under dashboard.basic_auth and is intended for a trusted LAN or VPN, not direct public-internet exposure. A Nous OAuth provider is also available. In every case, a non-loopback bind (fabric dashboard --host 0.0.0.0) engages the auth gate. See Web Dashboard → Authentication for the full picture.

There are no dedicated dashboard credential environment variables. Set dashboard.basic_auth.{password_hash,password,secret} and dashboard.oauth.self_hosted.client_secret in config.yaml. If an operator does not want the underlying value written there, use config's standard ${VAR} interpolation and define the operator-chosen variable in ~/.fabric/.env.

Microsoft Graph (Teams Meetings)

App-only credentials for the Microsoft Graph REST client used by the upcoming Teams meeting summary pipeline. See Register a Microsoft Graph application for the Azure portal walkthrough and the exact API permissions required.

VariableDescription
MSGRAPH_TENANT_IDAzure AD tenant ID (directory GUID) for the Graph app registration.
MSGRAPH_CLIENT_IDApplication (client) ID of the Azure app registration.
MSGRAPH_CLIENT_SECRETClient secret value for the app registration. Store in ~/.fabric/.env with chmod 600; rotate periodically via the Azure portal.
MSGRAPH_SCOPEOAuth2 scope for the client-credentials token request (default: https://graph.microsoft.com/.default).
MSGRAPH_AUTHORITY_URLMicrosoft identity platform authority (default: https://login.microsoftonline.com). Override only for national/sovereign clouds (e.g. https://login.microsoftonline.us for GCC High).

Microsoft Graph Webhook Listener

Inbound change-notification listener for Graph events (Teams meetings, calendar, chat, etc.). See Microsoft Graph Webhook Listener for setup and security hardening.

VariableDescription
MSGRAPH_WEBHOOK_ENABLEDEnable the msgraph_webhook gateway platform (true/1/yes).
MSGRAPH_WEBHOOK_PORTPort the listener binds to (default: 8646).
MSGRAPH_WEBHOOK_CLIENT_STATEShared secret Graph echoes in every notification; compared with hmac.compare_digest. Generate with openssl rand -hex 32.
MSGRAPH_WEBHOOK_ACCEPTED_RESOURCESComma-separated allowlist of Graph resource paths/patterns (e.g. communications/onlineMeetings,chats/*/messages). Trailing * is prefix-matching. Empty = accept all.
MSGRAPH_WEBHOOK_ALLOWED_SOURCE_CIDRSComma-separated CIDR ranges allowed to POST to the listener (e.g. 52.96.0.0/14,52.104.0.0/14). Empty = allow all (default). Restrict to Microsoft Graph's published egress ranges in production.

Teams Meeting Summary Delivery

Only used when the teams_pipeline plugin is enabled. Settings are also configurable under platforms.teams.extra in config.yaml — env vars take priority when both are set. See Microsoft Teams → Meeting Summary Delivery.

VariableDescription
TEAMS_DELIVERY_MODEgraph or incoming_webhook.
TEAMS_INCOMING_WEBHOOK_URLTeams-generated webhook URL; required when TEAMS_DELIVERY_MODE=incoming_webhook.
TEAMS_GRAPH_ACCESS_TOKENPre-acquired delegated access token for Graph delivery. Rarely needed — the writer falls back to the MSGRAPH_* app credentials when unset.
TEAMS_TEAM_IDTarget Team ID for channel delivery (graph mode).
TEAMS_CHANNEL_IDTarget channel ID (paired with TEAMS_TEAM_ID).
TEAMS_CHAT_IDTarget 1:1 or group chat ID (alternative to team+channel for graph mode).

LINE Messaging API

Used by the bundled LINE platform plugin (plugins/platforms/line/). See Messaging Gateway → LINE for full setup.

VariableDescription
LINE_CHANNEL_ACCESS_TOKENLong-lived channel access token from the LINE Developers Console (Messaging API tab). Required.
LINE_CHANNEL_SECRETChannel secret (Basic settings tab); used for HMAC-SHA256 webhook signature verification. Required.
LINE_HOSTWebhook bind host (default: 0.0.0.0).
LINE_PORTWebhook bind port (default: 8646).
LINE_PUBLIC_URLPublic HTTPS base URL (e.g. https://my-tunnel.example.com). Required for image / audio / video sends — LINE only accepts HTTPS-reachable URLs.
LINE_ALLOWED_USERSComma-separated user IDs allowed to DM the bot (U-prefixed).
LINE_ALLOWED_GROUPSComma-separated group IDs the bot will respond in (C-prefixed).
LINE_ALLOWED_ROOMSComma-separated room IDs the bot will respond in (R-prefixed).
LINE_ALLOW_ALL_USERSDev-only escape hatch — accepts any source. Default: false.
LINE_HOME_CHANNELDefault delivery target for cron jobs with deliver: line.
LINE_SLOW_RESPONSE_THRESHOLDSeconds before the slow-LLM Template Buttons postback fires (default: 45). Set 0 to disable and always Push-fallback.
LINE_PENDING_TEXTBubble text shown alongside the postback button.
LINE_BUTTON_LABELPostback button label (default: Get answer).
LINE_DELIVERED_TEXTReply when an already-delivered postback is tapped again (default: Already replied ✅).
LINE_INTERRUPTED_TEXTReply when a /stop-orphaned postback button is tapped (default: Run was interrupted before completion.).

ntfy (push notifications)

ntfy is a lightweight HTTP-based push notification service. Subscribe to a topic from the ntfy mobile app, publish to that topic to talk to the agent.

VariableDescription
NTFY_TOPICTopic to subscribe to (incoming messages). Required.
NTFY_SERVER_URLServer URL (default: https://ntfy.sh). Point at a self-hosted ntfy for privacy.
NTFY_TOKENOptional auth token. Bearer token (e.g. tk_xyz) or user:pass for Basic auth.
NTFY_PUBLISH_TOPICTopic for outgoing replies (defaults to NTFY_TOPIC).
NTFY_MARKDOWNSet true to send replies with X-Markdown: true header. Default: false.
NTFY_ALLOWED_USERSAllowlist (treated as user IDs; on ntfy these are topic names). Typically set to the same value as NTFY_TOPIC.
NTFY_ALLOW_ALL_USERSDev-only escape hatch — only safe on access-controlled private topics. Default: false.
NTFY_HOME_CHANNELDefault delivery target for cron jobs with deliver: ntfy.
NTFY_HOME_CHANNEL_NAMEHuman label for the home channel (defaults to the topic name).

See the ntfy messaging guide — particularly the identity model section — before deploying with untrusted topics.

IRC

Connect Fabric to an IRC server. No external dependencies. See the IRC messaging guide.

VariableDescription
IRC_SERVERIRC server hostname (e.g. irc.libera.chat). Required.
IRC_CHANNELChannel(s) to join (e.g. #fabric); comma-separate for multiple. Required.
IRC_NICKNAMEBot nickname (default: fabric-bot). Required.
IRC_PORTServer port (default: 6697 with TLS, 6667 without).
IRC_USE_TLSUse TLS (true/false; default true on port 6697).
IRC_SERVER_PASSWORDServer password for the PASS command (optional).
IRC_NICKSERV_PASSWORDNickServ password for automatic IDENTIFY on connect (optional).
IRC_ALLOWED_USERSComma-separated nicks allowed to talk to the bot.
IRC_ALLOW_ALL_USERSAllow anyone in the channel to talk to the bot (dev only).
IRC_HOME_CHANNELChannel for cron / notification delivery (defaults to IRC_CHANNEL).

SimpleX

Connect Fabric to a SimpleX Chat network via a local simplex-chat daemon. See the SimpleX messaging guide.

VariableDescription
SIMPLEX_WS_URLWebSocket URL of the simplex-chat daemon (e.g. ws://127.0.0.1:5225).
SIMPLEX_ALLOWED_USERSComma-separated SimpleX contact IDs allowed to talk to the bot.
SIMPLEX_ALLOW_ALL_USERSAllow any contact to talk to the bot (dev only — disables allowlist).
SIMPLEX_AUTO_ACCEPTAuto-accept incoming contact requests (default: true).
SIMPLEX_GROUP_ALLOWEDComma-separated SimpleX group IDs the bot should participate in, or * to allow any group. Omit to ignore group messages entirely (safer default — a bot in a group otherwise processes every member's traffic).
SIMPLEX_HOME_CHANNELDefault contact/group ID for cron / notification delivery.
SIMPLEX_HOME_CHANNEL_NAMEHuman label for the home channel (defaults to the ID).

Photon

Connect Fabric to Photon / Spectrum (iMessage and other Spectrum platforms) via the Node sidecar. See the Photon messaging guide.

VariableDescription
PHOTON_PROJECT_IDSpectrum project id (the project's spectrumProjectId; set by fabric photon setup).
PHOTON_PROJECT_SECRETProject secret paired with the Spectrum project id (set by fabric photon setup).
PHOTON_ALLOWED_USERSComma-separated E.164 phone numbers allowed to talk to the bot.
PHOTON_ALLOW_ALL_USERSAllow any sender to trigger the bot (dev only — disables allowlist).
PHOTON_REQUIRE_MENTIONIgnore group-chat messages unless they match a mention wake word (true/false, default false).
PHOTON_MENTION_PATTERNSMention wake-word regexes for group chats (JSON list or comma/newline-separated; defaults to Fabric wake words).
PHOTON_HOME_CHANNELDefault Photon target for cron / notification delivery: Spectrum space id, DM GUID, or bare E.164 phone number.
PHOTON_HOME_CHANNEL_NAMEHuman label for the home channel.
PHOTON_MARKDOWNSend agent replies as markdown — iMessage renders it natively, other Spectrum platforms degrade to plain text (true/false, default true).
PHOTON_REACTIONSTapback 👀/👍/👎 on messages as processing status and route tapbacks on bot messages to the agent (true/false, default false).
PHOTON_TELEMETRYEnable Spectrum SDK telemetry in the sidecar (true/false, default false; toggle with `fabric photon telemetry on
PHOTON_SIDECAR_PORTLoopback port for the Node sidecar control + inbound channel (default 8789).
PHOTON_SIDECAR_AUTOSTARTSpawn the Node sidecar on connect (true/false, default true).
PHOTON_NODE_BINPath to the node binary (default: shutil.which('node')).
PHOTON_DASHBOARD_HOSTPhoton Dashboard API host (default https://app.photon.codes).
PHOTON_SPECTRUM_HOSTPhoton Spectrum API host (default https://spectrum.photon.codes).

Microsoft Teams (adapter)

The Microsoft Teams platform adapter (Bot Framework / Azure AD), distinct from the Microsoft Graph (Teams Meetings) integration above. See the Teams messaging guide.

VariableDescription
TEAMS_CLIENT_IDAzure AD application (Bot Framework) client ID.
TEAMS_CLIENT_SECRETAzure AD application client secret.
TEAMS_TENANT_IDAzure AD tenant ID hosting the bot application.
TEAMS_PORTWebhook listen port (Bot Framework default: 3978).
TEAMS_ALLOWED_USERSComma-separated Teams user IDs / UPNs allowed to talk to the bot.
TEAMS_ALLOW_ALL_USERSAllow any Teams user to trigger the bot (dev only).
TEAMS_HOME_CHANNELDefault chat/channel ID for cron / notification delivery.
TEAMS_HOME_CHANNEL_NAMEDisplay name for the Teams home channel.

Raft

VariableDescription
RAFT_PROFILERaft agent profile slug — auto-enables the adapter when set.

Advanced Messaging Tuning

Advanced per-platform knobs for throttling the outbound message batcher. Most users never need to touch these; defaults are set to respect each platform's rate limits without feeling sluggish.

VariableDescription
GATEWAY_RELAY_URLExperimental relay connector WebSocket base URL. When set, the gateway registers the generic relay adapter and dials the connector outbound. Mirrors gateway.relay_url in config.yaml.
GATEWAY_RELAY_IDRelay gateway identifier assigned by fabric gateway enroll or managed self-provisioning. Mirrors gateway.relay_id.
GATEWAY_RELAY_SECRETPer-gateway relay secret used to authenticate the WebSocket. If this is already configured, managed self-provisioning is skipped. Mirrors gateway.relay_secret.
GATEWAY_RELAY_DELIVERY_KEYConnector-issued delivery key retained for relay/passthrough authentication compatibility. Current relay inbound messages arrive on the outbound WebSocket rather than a gateway-side HTTP receiver.
GATEWAY_RELAY_ENROLL_TOKENEnrollment token consumed by fabric gateway enroll when --token is not passed explicitly.
GATEWAY_RELAY_PLATFORMOptional platform name advertised in the relay capability descriptor.
GATEWAY_RELAY_BOT_IDOptional bot identifier advertised in the relay capability descriptor.
GATEWAY_RELAY_ENDPOINTOptional gateway endpoint advertised for connector modes that need a callback/passthrough URL; not required for the default WS-only inbound relay path. Mirrors gateway.relay_endpoint.
GATEWAY_RELAY_ROUTE_KEYSComma-separated relay route keys advertised to the connector. Mirrors gateway.relay_route_keys.

Agent Behavior

VariableDescription
CODEX_HOMEWhen Codex app-server runtime is enabled, override the directory Codex CLI reads its config + auth from (default: ~/.codex). Fabric's migration writes the managed block to <CODEX_HOME>/config.toml.
DELEGATION_MAX_CONCURRENT_CHILDRENMax parallel subagents per delegate_task batch (default: 3, floor of 1, no ceiling). Also configurable via delegation.max_concurrent_children in config.yaml — the config value takes priority.

Bundled skills and the official optional-skill catalog are executable trust roots. Fabric resolves them only from immutable data shipped with the installed distribution (or from explicit source-checkout paths during development), never from environment variables or profile state.

Interface

VariableDescription
FABRIC_TUI_DIRPath to a prebuilt ui-tui/ directory (must contain dist/entry.js and populated node_modules). Used by distros and Nix to skip the first-launch npm install.

Session Settings

VariableDescription
SESSION_IDLE_MINUTESReset sessions after N minutes of inactivity (default: 1440)
SESSION_RESET_HOURDaily reset hour in 24h format (default: 4 = 4am)

Context Compression (config.yaml only)

Context compression is configured exclusively through config.yaml — there are no environment variables for it. Threshold settings live in the compression: block, while the summarization model/provider lives under auxiliary.compression:.

compression:
enabled: true
threshold: 0.50
target_ratio: 0.20 # fraction of threshold to preserve as recent tail
protect_last_n: 20 # minimum recent messages to keep uncompressed
Legacy migration

Older configs with compression.summary_model, compression.summary_provider, and compression.summary_base_url are automatically migrated to auxiliary.compression.* on first load.

Auxiliary Task Overrides

VariableDescription
AUXILIARY_VISION_PROVIDEROverride provider for vision tasks
AUXILIARY_VISION_MODELOverride model for vision tasks
AUXILIARY_VISION_BASE_URLDirect OpenAI-compatible endpoint for vision tasks
AUXILIARY_VISION_API_KEYAPI key paired with AUXILIARY_VISION_BASE_URL
AUXILIARY_WEB_EXTRACT_PROVIDEROverride provider for web extraction/summarization
AUXILIARY_WEB_EXTRACT_MODELOverride model for web extraction/summarization
AUXILIARY_WEB_EXTRACT_BASE_URLDirect OpenAI-compatible endpoint for web extraction/summarization
AUXILIARY_WEB_EXTRACT_API_KEYAPI key paired with AUXILIARY_WEB_EXTRACT_BASE_URL

For task-specific direct endpoints, Fabric uses the task's configured API key or OPENAI_API_KEY. It does not reuse OPENROUTER_API_KEY for those custom endpoints.

Fallback Providers (config.yaml only)

The primary model fallback chain is configured exclusively through config.yaml — there are no environment variables for it. Add a top-level fallback_providers list with provider and model keys to enable automatic failover when your main model encounters errors. Auxiliary tasks whose provider is auto also consult this chain before Fabric's built-in auxiliary discovery chain.

fallback_providers:
- provider: openrouter
model: anthropic/claude-sonnet-4

The older top-level fallback_model single-provider shape is still read for backward compatibility, but new configuration should use fallback_providers. For task-specific auxiliary policy, use auxiliary.<task>.fallback_chain in config.yaml; there is no environment variable equivalent.

See Fallback Providers for full details.

Provider Routing (config.yaml only)

These go in ~/.fabric/config.yaml under the provider_routing section:

KeyDescription
sortSort providers: "price" (default), "throughput", or "latency"
onlyList of provider slugs to allow (e.g., ["anthropic", "google"])
ignoreList of provider slugs to skip
orderList of provider slugs to try in order
require_parametersOnly use providers supporting all request params (true/false)
data_collection"allow" (default) or "deny" to exclude data-storing providers
tip

Use fabric config set to set environment variables — it automatically saves them to the right file (.env for secrets, config.yaml for everything else).