Skip to main content
Early access. Cloud sessions and managed agent runs are not open to every account yet: we are letting accounts in gradually while we test. They run in a cloud sandbox operated by Mutagent, so there is nothing to host. A sandbox with nothing to do for 15 minutes stops; send the session a message and it wakes up, delivers your message and carries on in the same conversation.
An Environment holds the variables and secrets your cloud sessions need: a GitHub token, a database URL, a feature flag. Your local shell variables are not sent to the sandbox, so anything a tool reads from its environment goes into an Environment. Do not put model keys in an Environment. They come from your LLM providers. Before you start: sign in and select a workspace (see LLM providers and models). Environments belong to one workspace. Pass --workspace <name> to work in another one for a single command.

Create an Environment and use it

Put secrets in a file in .env format (KEY=VALUE lines) and keep them off the command line:
env set creates the Environment if it does not exist and adds the entries. --env demo loads them into the sandbox as environment variables when the session starts. With --json, env set returns created (true when this command made the Environment), variables and secrets (the names stored as each). Check that every name landed where you meant it to. The command exits 0 on success. --secret KEY=VALUE on the command line also works, but the value stays in your shell history.

Variables and secrets

Positional KEY=VALUE entries are variables. --secret KEY=VALUE entries are secrets. A name cannot be both. A value may contain =; the split is at the first one. --secret takes every KEY=VALUE that follows it, so put variables before --secret.

Load entries from files

The CLI reads the files on your machine and sends their entries. A value on the command line wins over the same name in a file. env set merges: entries you do not name stay. --replace replaces the whole Environment and removes every entry you did not name, secrets included, so it also needs --force. Without --force it refuses with CONFIRMATION_REQUIRED (exit 1), names the entries it would remove, and writes nothing:

Manage Environments

Stored values are never returned. The fingerprint is 8 hex characters computed on the server with a key only the server holds. It stays the same while the value is unchanged, so comparing two show runs tells you whether a value changed. You cannot compute it yourself; to be sure a value is right, set it again. A change applies to sessions that start after it; a running session keeps the values it started with. Environment names use letters, digits, ., _, and -, up to 64 characters. Entry names use uppercase letters, digits, and _, and cannot start with a digit. An Environment holds up to 64 KiB.

Which value is used

A sandbox receives environment variables from up to three sources. When two set the same name, the later one is used: A few names are set by the platform in every sandbox and always keep the platform’s value. An Environment cannot store one: saving it is refused, and the error names the entry. Rename it.

Overriding a model key

env set refuses a variable named like an LLM provider key, such as ANTHROPIC_API_KEY, because it would replace the workspace key in every run that loads the Environment. If you need that override, pass --allow-provider-key and store the value as a secret. It does not add models to mutagent helix models or change the default.

If it fails

More in Troubleshooting cloud runs.