Skip to main content
An Environment holds the variables and secrets your cloud sessions’ tools need, such as a GitHub token or a database URL. Load one into a run with --env <name>. Commands never print stored values, only names and fingerprints. Model keys do not go in an Environment; they come from LLM providers.

Before you start

Sign in and select a workspace: see Installation. Environments belong to the selected workspace, or the one --workspace <name-or-id> names. Without a workspace, every command on this page exits 3.

mutagent env set

Create an Environment, or add entries to an existing one. Entries you do not name are kept. Both variables and secrets are set as environment variables in the sandbox. A name cannot be both.
Here .env.secrets holds KEY=VALUE lines, such as GITHUB_TOKEN=<github-token>. With --json, success returns:
Check that each name is in variables or secrets as you meant. created is true when this command made the Environment. Names: Environment names use letters, digits, ., _ and -, up to 64 characters. Entry names use A-Z, 0-9 and _, and do not start with a digit. A value may contain =: TOKEN=a=b stores a=b. An Environment holds up to 64 KiB. To keep secrets out of your shell history, pass them with --secrets-from-file.

mutagent env list

List the workspace’s Environments and their entry names. mutagent env ls is the same command.
The JSON has environments (each with name, vars, secrets, createdAt, updatedAt) and count. vars and secrets list names and fingerprints, never values. An empty list means the workspace has no Environments yet.

mutagent env show

List one Environment’s entry names, whether each is a variable or a secret, and a fingerprint of each value. An unknown name is an error.
The fingerprint is 8 hex characters computed on the server with a key only the server holds. It stays the same while the value is unchanged, so comparing two show runs tells you whether a value changed. You cannot compute it yourself. To make sure a value is what you expect, set it again with mutagent env set.

mutagent env unset

Remove entries from an Environment. A name that does not exist is not an error. A removed secret cannot be read back, so the command needs --force.

mutagent env delete

Delete an Environment and its secrets. mutagent env rm is the same command. Sandboxes that are already running keep the values they were given; the next run that names the Environment fails.
See Environments for size limits and which value is used when names collide.

unset and delete need —force

mutagent env unset removes values that cannot be read back, so it follows the rule for delete commands: it refuses without --force and sends nothing, with or without --json. The error code is CONFIRMATION_REQUIRED and the exit code is 1. The same applies to env delete.

If it fails

See Errors and exit codes.