Every setting AgentFox reads: its environment variable, its agentfox.toml key, its default, and what it changes.
When to use this
Look a setting up here when Install and configure or a guide names one, and before you deploy (Self-hosting). The defaults are offline-first: no egress, the echo provider, five dependency-free detectors, and detector packs in observe.
How a setting is resolved
AGENTFOX_<KEY> in the environment.
The [agentfox] table of the file named by AGENTFOX_CONFIG, or of ./agentfox.toml in the working directory.
The default in the tables below.
The key in the file is the setting name: taint_scope = "argument" in the file is AGENTFOX_TAINT_SCOPE=argument in the environment. Lists are TOML arrays in the file and JSON in the environment. Unknown keys are ignored with a warning naming them. Values are validated, and some (taint_scope, webhook_min_severity) stop startup on a typo rather than falling back. Settings are read once per process.
bash
export AGENTFOX_FAIL_MODE=closed
export AGENTFOX_ENABLED_DETECTORS='["pii.native","secrets.native"]'
python -c "from agentfox.core.config import Settings as S; s = S(); print(s.fail_mode, s.enabled_detectors)"
Output
closed ['pii.native', 'secrets.native']
Database, state and deployment
Key and variable
Default
What it does
database_url AGENTFOX_DATABASE_URL
sqlite:///<state dir>/agentfox.db
Where everything is stored. SQLite by default; postgresql+psycopg://… with the postgres extra. A multi-worker server refuses SQLite at startup.
sql_echo AGENTFOX_SQL_ECHO
false
Log every SQL statement. For debugging only.
evidence_dir AGENTFOX_EVIDENCE_DIR
<state dir>/var/evidence
Where agentfox report evidence writes packages.
org_id AGENTFOX_ORG_ID
org_default
The organisation (tenant) records belong to when no token says otherwise.
environment AGENTFOX_ENVIRONMENT
development
development, staging, production, … Decides whether the development identity header is accepted when auth_mode is auto; anything not recognised as development counts as production.
console_url AGENTFOX_CONSOLE_URL
""
Your dashboard's address, used to turn a decision id in a refusal into a link. Never guessed; empty omits the link.
compliance_dir AGENTFOX_COMPLIANCE_DIR
unset: the compliance packs
A directory to read controls.yaml, obligations.yaml and threats.yaml from instead of the capability packs. Set only to load your own catalog.
policies_dir AGENTFOX_POLICIES_DIR
unset: the built-in packs
A directory to read the shipped policy files from instead of the built-in capability packs.
pack_maturity AGENTFOX_PACK_MATURITY
stable
Which capability packs load: stable, incubating (stable and incubating) or sandbox (all). See agentfox policy packs list --all.
Authentication and secrets
Key and variable
Default
What it does
auth_mode AGENTFOX_AUTH_MODE
auto
auto follows environment; development accepts the X-AgentFox-User header; token requires API tokens; oidc is reserved. Check with agentfox admin auth status.
service_auth_secret AGENTFOX_SERVICE_AUTH_SECRET
dev-insecure-service-secret
Shared between the gateway and the dashboard for the GitHub sign-in provisioning call, which mints owner tokens. Must be identical on both. Outside development the gateway refuses to start while it is the published default.
Retired encryption keys, comma-separated. They still decrypt and never encrypt; agentfox admin keys rotate moves everything to the current key, then remove them.
cron_secret AGENTFOX_CRON_SECRET
unset
Bearer secret for /api/internal/jobs/run. Unset: the route refuses every call. CRON_SECRET is also read.
Comma-separated browser origins allowed to call the public playground, added to localhost.
Policy and enforcement
Key and variable
Default
What it does
default_policy_mode AGENTFOX_DEFAULT_POLICY_MODE
observe
The mode of a policy that does not declare one. Packs that declare a mode keep it: tool-containment declares enforce.
fail_mode AGENTFOX_FAIL_MODE
open
What happens when a detector errors or exceeds its budget: open lets the request through and records the gap; closed refuses.
taint_scope AGENTFOX_TAINT_SCOPE
session
session: a call's provenance is the worst untrusted content in the run so far. argument: only what its own arguments were copied from. Any other value is an error. See Concepts.
Latency ceiling for the whole pre-flight pipeline on one surface.
detector_timeout_ms AGENTFOX_DETECTOR_TIMEOUT_MS
40
Default per-detector budget.
request_budget_ms AGENTFOX_REQUEST_BUDGET_MS
350
Ceiling across every surface one governed call touches. Kept above enforcement_budget_ms.
policy_engine AGENTFOX_POLICY_ENGINE
native
native, or opa to evaluate through an Open Policy Agent sidecar (falls back to native if it is unreachable).
opa_url AGENTFOX_OPA_URL
http://localhost:8181
The OPA sidecar, when policy_engine is opa.
streaming_mode AGENTFOX_STREAMING_MODE
buffered
buffered enforces streamed output exactly like non-streamed, at the cost of first-token latency; windowed forwards as it goes and cannot recall what it already sent.
Guardrails AI Hub validator slugs for rails.guardrails_ai (validators extra). Each must be installed separately.
Judgment tiers and egress
Key and variable
Default
What it does
allow_egress AGENTFOX_ALLOW_EGRESS
false
Master switch for anything leaving the machine: hosted model providers, hosted judgment tiers, webhooks, write-back to LangSmith or Langfuse. Off by default.
judgment_backend AGENTFOX_JUDGMENT_BACKEND
local
local keeps every judgment in-process; remote and auto may call a hosted judgment model, only with allow_egress on.
judgment_tiers AGENTFOX_JUDGMENT_TIERS
["deterministic"]
Evaluators that may be consulted: deterministic (always on), local_model, local_llm, jev, llm. Each tier is forbidden from the decisions it measured worse on.
Retired signing keys, comma-separated. Checkpoints they signed still verify; agentfox admin keys rotate verifies the chain and re-signs them with the current key, then remove them.
A few variables are read straight from the environment, because they decide where settings come from or are used by a separate program. None of them can go in agentfox.toml.
Variable
What it does
AGENTFOX_STATE_DIR
Directory for the default database and evidence. It decides the defaults of database_url and evidence_dir, so it is not itself a setting.
AGENTFOX_CONFIG
Path to the TOML file to read. It must exist. none, off or - turns file loading off.
AGENTFOX_AGENT
Agent slug for agentfox.auto() when none is passed. Then OTEL_SERVICE_NAME, SERVICE_NAME, APP_NAME, K_SERVICE, the script name, and finally default-agent.
Where agentfox scan --submit sends a redacted summary, and the credential it uses.
AGENTFOX_AUDIT_KEY
Then AGENTFOX_AUDIT_SIGNING_KEY. Read by the verify_chain.py inside an evidence package to check checkpoint signatures.
AGENTFOX_MCP_LOG_LEVEL
Log level of agentfox serve mcp. Default WARNING.
CRON_SECRET
Accepted in addition to cron_secret by /api/internal/jobs/run (Vercel Cron sets it).
JEV_API_KEY
Key for the hosted jev judgment tier. Without it that tier is unavailable.
Dashboard
The web app is a separate Next.js process with its own variables. Each AGENTFOX_ name below falls back to its AGENTFOX_ spelling (for example AGENTFOX_API_URL) when unset. They are read at request time, so one image can point at any gateway.
Variable
Default
What it does
AGENTFOX_API_URL
http://127.0.0.1:8080
The gateway the dashboard calls, server to server. Include the scheme.
AGENTFOX_API_TOKEN
unset
A static operator token for the dashboard's own calls. A signed-in user's token takes precedence.
AGENTFOX_USER
admin@example.com
The development identity header value, used when there is no token. A gateway outside development refuses it.
AGENTFOX_PLAYGROUND_API_URL
AGENTFOX_API_URL
The gateway address the visitor's browser uses on the public playground page.
AGENTFOX_SERVICE_AUTH_SECRET
unset
Must equal the gateway's service_auth_secret, or GitHub sign-in fails at provisioning.
AGENTFOX_SITE_URL
the public site
Canonical URL used in page metadata.
AGENTFOX_SELF_HOSTED
unset
Marks a self-hosted dashboard in the interface.
GITHUB_CLIENT_ID, GITHUB_CLIENT_SECRET
unset
The GitHub OAuth app for sign-in. Unset: sign-in is unavailable.
What can go wrong
A hosted provider or webhook does nothing.allow_egress is false. A configured key or URL with egress off sends nothing.
A detector you enabled never fires. Its extra or weights are missing, so it is unavailable and skipped. agentfox doctor lists the available ones.
The development header is refused.environment is not a development name, so auth_mode = auto requires tokens. agentfox admin auth status says which.
GitHub sign-in fails at provisioning.service_auth_secret differs between the gateway and the dashboard.