Subshell Docs

Environment variables

Look up the environment values used by the server and pane integrations.

Server configuration

Before changing a value, use Files and paths to locate the active configuration and choose the correct environment layer.

Process environment overrides config.env, then development .env, then defaults. CLI initialization persists production-specific paths and a generated authentication secret; raw boot defaults are not identical to an initialized installation.

VariableDefault or behavior
SERVER_PORT3080.
HOST0.0.0.0.
APP_BASE_URLhttp://localhost:<SERVER_PORT> on raw boot.
TRUSTED_ORIGINSOperator extras; raw default includes localhost Vite origins on ports 5174 and 5173. Derived origins are added separately.
BETTER_AUTH_SECRETUnique secret generated by initialization. Production refuses the built-in placeholder.
SUBSHELL_SERVER_CONFIG_DIR~/.config/subshell-server.
DATABASE_PATHRaw default ./data/subshell.db; initialization selects the deployment's persistent path.
SUBSHELL_SERVER_DATA_DIRDefaults to the database's directory, resolved absolutely.
SUBSHELL_NODE_ARTIFACTS_DIRnode-artifacts beneath server data.
SUBSHELL_RELEASE_URLProject GitHub release API; empty disables release fetches.
SUBSHELL_PLUGIN_REGISTRY_URLDefault npm registry; operator-selected mirrors are trusted configuration.
SUBSHELL_FS_ROOTUnset allows broad server-side browser filesystem exploration; set restricts that picker to a resolved tree.
SUBSHELL_EMERGENCY_PASSWORDUnset; when enabled, emergency admin sign-in rewrites the password.

Retention and diagnostics

VariableDefault or behavior
SUBSHELL_DB_BACKUPS_KEEPFive database snapshots.
SUBSHELL_LOG_RETENTION_DAYSThirty days for terminated pane logs; zero disables the sweep.
SUBSHELL_VERBOSE1 or true increases console detail.
SUBSHELL_DEBUG_LOGGINGAdditional file logging; false by default.
SUBSHELL_TERMINAL_REPLAY_LINESDefault 100 lines for initial terminal replay.
SUBSHELL_ATTACH_DEBUGDebug screen dumps when enabled; these may contain sensitive output.
SUBSHELL_DASHBOARD_PORTOverride the node's loopback management listener.

Binary detection

Harness manifests declare CLAUDE_PATH, CODEX_PATH, OPENCODE_PATH, HERMES_PATH, and PI_PATH. Network manifests declare TAILSCALE_PATH, NETBIRD_PATH, and CLOUDFLARED_PATH. Terminal uses SHELL to select the execution account's shell.

These select binaries in the applicable execution environment. Setting one in a shell does not automatically change an existing service's environment.

Pane identity

The host injects SUBSHELL_API_KEY, SUBSHELL_ID, SUBSHELL_BASE_URL, SUBSHELL_DATA_DIR, and optional SUBSHELL_NAME for MCP. They identify the pane and its storage; do not replace them with a shared system key.

SUBSHELL_CHANNEL_PIN defaults to strict peer-key pinning. trust disables the pin check and persistence.

Installer settings

The server installation script accepts SUBSHELL_SERVER_VERSION, release API/base overrides, and address variables prefixed SUBSHELL_SERVER_. SUBSHELL_NO_SERVICE=1 skips its service setup. These installer variables are distinct from the server's persisted configuration names.

See also

Configuration, Files and paths, and MCP configuration.

Edit on GitHub

Last updated on

On this page