Skip to main content

Environment Variables

Environment variables exist at two levels: process variables that configure the API and workers at startup, and workspace variables that Polygent injects into session commands and tasks.

  1. Process level — set in the operating-system or service environment of the API, Session Worker, or Deployment Worker. They override appsettings.json keys and take effect after a restart.
  2. Workspace level — managed on the workspace Environment Variables tab and injected into that workspace's sessions, hooks, and tasks on every host.

Process level​

Process variables override matching appsettings.json keys, using __ (double underscore) as the section separator — Database:Provider becomes Database__Provider. They take precedence over the file and are the recommended place for secrets.

# Windows Service: set variables for one service in its registry Environment value
reg add "HKLM\SYSTEM\CurrentControlSet\Services\Polygent" /v Environment /t REG_MULTI_SZ `
/d "Database__Provider=PostgreSql\0Database__ConnectionString=Host=db;Database=polygent;Username=polygent;Password=secret\0Login__ClientSecret=..." /f
sc.exe stop Polygent
sc.exe start Polygent
# Linux / container
Database__Provider=PostgreSql
Database__ConnectionString="Host=db;Database=polygent;Username=polygent;Password=secret"
Login__ClientSecret=...
ASPNETCORE_FORWARDEDHEADERS_ENABLED=true

Restrict the service registry key, container definition, and appsettings.json to administrators and the service account.

App-level reference​

These variables configure the API process. Defaults are the values used when the variable and the appsettings.json key are both absent.

Env varappsettings.json pathDefaultPurpose
Database__ProviderDatabase:ProviderSqlite (shipped)Sqlite, SqlServer, or PostgreSql. Blank or invalid prevents startup.
Database__ConnectionStringDatabase:ConnectionString{StoragePath}/polygent.dbProvider-specific connection string.
StoragePathStoragePathservice account's %APPDATA%\PolygentRoot directory for keys, logs, database, working copies. Set an absolute path.
ClientUrlClientUrlhttps://localhost:5173Public base URL used in links and MCP OAuth callbacks.
McpUrlMcpUrl{ClientUrl}/mcpMCP endpoint URL given to agents; must be reachable from every session host.
Login__LoginTypeLogin:LoginTypeGoogleGoogle, Microsoft, or OpenIdConnect.
Login__ClientId / Login__ClientSecretLogin:ClientId / Login:ClientSecretemptyIdentity-provider client credentials.
Login__ClientUrlLogin:ClientUrlhttps://localhost:5173Public URL users return to after sign-in.
Login__TenantIdLogin:TenantIdemptyMicrosoft tenant (common or a tenant ID).
Login__AuthorityLogin:AuthorityemptyOpenID Connect issuer URL.
Login__OidcDisplayName / Login__OidcScopesLogin:OidcDisplayName / Login:OidcScopesemptyOpenID Connect button label and extra scopes.
Login__EnableSeamlessSsoLogin:EnableSeamlessSsofalseMicrosoft only: skip the account picker.
Login__AllowNewUsersLogin:AllowNewUserstrueAuto-register new users on first sign-in.
Login__AccessTokenMinutesLifetimeLogin:AccessTokenMinutesLifetime15Access token lifetime (minutes).
Login__RefreshTokenDaysLifetimeLogin:RefreshTokenDaysLifetime7Refresh token lifetime (days).
Login__EnableTestLoginLogin:EnableTestLoginfalseEvaluation-only email sign-in. Never enable in production — anyone can sign in as any user.
ShowChatInNewMenu / ShowDevelopInNewMenusamefalseShow the built-in Chat / Develop cards in the sidebar New picker.
Tickets__SyncIntervalMinutesTickets:SyncIntervalMinutes15External ticket sync poll interval.
Tickets__EnableReadyForQaSummaryTickets:EnableReadyForQaSummarytrue (shipped false)Generate an AI summary when a ticket enters QA.
ContentAssist__DefaultLanguageContentAssist:DefaultLanguageHebrewDefault Translate and Explain language (Arabic, English, Hebrew, Russian).
LocalHost__EnabledLocalHost:EnabledtrueRun sessions inside the API process.
MergeWorktreePrefixMergeWorktreePrefixmergeFolder prefix for merge-conflict working copies.
MergeAiTimeoutSecondsMergeAiTimeoutSeconds1800Per-attempt limit for AI conflict resolution, excluding capacity wait and merge hooks.
Git__LongRunningTimeoutSecondsGit:LongRunningTimeoutSeconds300Timeout for clone, fetch, pull, push, staging, and working-copy operations.
Mcp__OAuth__AllowedPrivateHosts__0, __1, …Mcp:OAuth:AllowedPrivateHostsemptyPrivate-network hostnames that MCP servers may use.
Harness__DataDirectory or POLYGENT_HARNESS_DATA_DIRHarness:DataDirectory%USERPROFILE%\.polygent\harnessAgent transcript storage (outside StoragePath by default).
Harness__ClaudeConfigDirectoryHarness:ClaudeConfigDirectoryunsetClaude Code configuration folder for command-line models under a service account.
Logging__LogLevel__DefaultLogging:LogLevel:DefaultInformationMinimum log level. Other category keys are ignored.
ANTHROPIC_API_KEY, OPENAI_API_KEY, GEMINI_API_KEY, OPENROUTER_API_KEY—unsetFallback model credentials when no key is saved in Backend Connections. See Models & Backends.
Urls / ASPNETCORE_URLSUrlshttp://localhost:5000Listen addresses, separated by ;. The container image uses http://+:8080.
ASPNETCORE_FORWARDEDHEADERS_ENABLED—unsetSet to true behind a TLS-terminating reverse proxy so OAuth redirects use https.
ASPNETCORE_ENVIRONMENT—ProductionKeep Production. Development disables HSTS and shows detailed error pages.

Session Worker variables​

These configure a standalone Session Worker; they are top-level keys in its appsettings.json and take effect after restarting the worker.

Env varDefaultPurpose
ApiUrlemptyPublic base URL of the Polygent API.
ApiKeyemptySession Worker host API key.
StoragePathnone — requiredWorker data directory. The worker writes crash.log beside its executable and exits when this is blank. Must be unique per worker instance.
MaxConcurrentSessions8Seeds the host's session limit on first registration only; later changes are made on the Hosts page.
DisplayHostnamemachine nameName shown on the Hosts page.
ShutdownDrainTimeoutSeconds600How long a service stop waits for running sessions and hook tasks to finish. 0 stops immediately.
MergeWorktreePrefixmergeFolder prefix for merge-conflict working copies on this worker.
Git__LongRunningTimeoutSeconds300Timeout for long Git operations.
Mcp__OAuth__AllowedPrivateHosts__0, …emptyPrivate-network hostnames that MCP servers may use; keep in step with the API.
Harness__DataDirectory / Harness__ClaudeConfigDirectorysee aboveSame as the API keys, for sessions on this worker.
Logging__LogLevel__DefaultInformationMinimum log level.
Model provider keysunsetFallback only; keys saved in Backend Connections are delivered to workers automatically.

Deployment Worker variables​

These configure a Deployment Worker; they live in the Agent section of its appsettings.json and take effect after restarting the worker.

Env varDefaultPurpose
Agent__NameemptyName shown on the Hosts page.
Agent__ServerIdempty (IP fallback)Stable, unique worker identity.
Agent__MainServerUrlemptyPublic base URL of the Polygent API.
Agent__ApiKeyemptyDeploy Worker host API key.
Agent__StoragePathworker install folderWhere slots are checked out and run.
Agent__DisableGitSslVerificationfalseDisable Git certificate verification for worker-managed Git operations. Keep false.
Agent__HeartbeatIntervalSeconds30Keep the default; values near 60 make the host appear offline intermittently.
Agent__ReconnectDelaySeconds__0, …1, 2, 5, 10, 30Reconnect backoff sequence.
Logging__LogLevel__DefaultDebug (shipped)Set Information for production.

See Deployment Worker for details.

Workspace level​

Workspace variables are managed in the application and injected into every session, hook, task, and agent command in the workspace, on local and remote hosts.

Configure​

  1. Open the workspace.
  2. Open the Environment Variables tab (requires Edit Workspaces).
  3. Add name/value pairs; mark sensitive values Secret.
  4. Choose whether each variable is available to agent shell commands (Bash, on by default) and to agent web requests (WebFetch header, off by default).
  5. Use Import / Export to move sets of variables (.env, appsettings.json, or YAML). Imported variables are not marked secret.

Reserved names​

Names that control credentials, profiles, and trust are reserved and rejected for workspaces: home and profile folders (HOME, USERPROFILE, APPDATA, LOCALAPPDATA, XDG_*), agent tool configuration folders, model provider keys and base URLs (ANTHROPIC_API_KEY, OPENAI_API_KEY, OPENAI_BASE_URL, GEMINI_API_KEY, OPENROUTER_API_KEY, and similar), and TLS/CA controls (NODE_TLS_REJECT_UNAUTHORIZED, NODE_EXTRA_CA_CERTS, SSL_CERT_FILE, SSL_CERT_DIR, CURL_CA_BUNDLE, REQUESTS_CA_BUNDLE). Configure model credentials in Models & Backends.

Security​

Workspace variables are a secret and command-execution boundary.

  • Variables are injected only into sessions of their own workspace.
  • Secret values are encrypted at rest, masked in the UI, and never returned to the browser after saving.
  • Polygent does not log variable values, but any command or agent can print them; treat printed values as disclosed.
  • Prefer variables (or per-user tokens) over secrets in prompts, scripts, or commit messages.

Resolution order​

When a session command or task starts, variables resolve in this order (later wins):

  1. The host service's own environment.
  2. Workspace environment variables.
  3. Variables Polygent requires for the run; these cannot be overridden.

Workflow parameters that reference $env:VAR_NAME resolve against the workspace variables when the step runs and are written into the prompt text.

Per-user tokens (TFS PAT)​

Azure DevOps / TFS can use a per-user, per-workspace personal access token saved under Profile → TFS Tokens. It is encrypted, not visible to other members, and never written to logs. See Ticket Sync.

See also​