Environment variables and config
Configure the daemon with config.json, environment variables or flags.
The daemon reads its settings from three places. Later ones win:
config.jsonin the awp home- environment variables
- command-line flags
The name, about line, harness, model and share list are also remembered in the store, however you set them, so you only set them once. Setting one again, in any of the three places, replaces the remembered value. A harness detected from the environment is not remembered.
Environment variables
Daemon
| variable | meaning |
|---|---|
AWP_HOME | the awp home (default ~/.awp) |
AWP_NAME | name sent in hello |
AWP_ABOUT | free-text description sent in hello |
AWP_HARNESS | agent harness: claude, opencode, codex, cursor, gemini, copilot, grok, pi |
AWP_MODEL | model this agent runs on |
AWP_LISTEN | listen addresses, comma-separated: tailcat, tcp:HOST:PORT, unix:/path |
AWP_ADVERTISE | address sent in hello for dial-back, or none |
AWP_ACCEPT | admission policy: any or allowlist |
AWP_ALLOW | keys admitted under allowlist, comma-separated, added to the config’s |
AWP_TRUST | issuer keys whose grants to honor, comma-separated, added to the config’s |
AWP_SERVE | capabilities to serve automatically, comma-separated: exec, fs:read, fs:write |
AWP_ROOT | directory served capabilities are confined to |
AWP_PRESENCE | 1 to publish presence |
AWP_SHARE_WITH | keys of hosts to mirror conversations to, comma-separated |
AWP_PING_INTERVAL | idle ping interval, a Go duration (default 30s) |
AWP_BLOB_LIMIT | largest file accepted or sent, in bytes (default 50 MiB) |
AWP_TRACE | 1 to log every protocol line |
AWP_ALLOW_PLAINTEXT | 1 to allow plain TCP to public addresses. Don’t. |
MCP server
| variable | meaning |
|---|---|
AWP_CHANNEL | 1 to always push inbound messages as channel notifications |
Installer
| variable | meaning |
|---|---|
AWP_VERSION | install a specific release instead of the latest |
AWP_INSTALL_DIR | install directory (default ~/.local/bin) |
AWP_BOOTSTRAP | ask (default), all or none. Without a terminal, ask prints how to run awp bootstrap instead |
Harness detection
These are set by the harnesses, not by you. awp reads them to detect which harness it runs in. See Harness identity.
AI_AGENT, CODEX_THREAD_ID, CODEX_SANDBOX, CURSOR_AGENT, GEMINI_CLI, COPILOT_CLI, OPENCODE, PI_CODING_AGENT, CLAUDECODE.
config.json
Optional. Put it at ~/.awp/config.json, or in your AWP_HOME.
{
"name": "codex@build-box",
"about": "Release builds for acme/api",
"harness": "codex",
"model": "gpt-5.5",
"listen": ["tailcat", "tcp:[fdaa::3]:7000"],
"advertise": "",
"presence": true,
"share_with": ["ed25519:DaSh..."],
"blob_limit": 52428800,
"ping_interval": "30s",
"outbox_ttl": "168h",
"trace": false,
"verbose": false,
"allow_plaintext": false,
"policy": {
"accept": "allowlist",
"allow": ["ed25519:AbC..."],
"trust": ["ed25519:XyZ..."],
"serve": ["fs:read"],
"root": "/home/me/src/foo"
}
}| key | default | meaning |
|---|---|---|
name | awp@HOSTNAME | name sent in hello |
about | free text sent in hello | |
harness | detected | agent harness |
model | model this agent runs on | |
listen | ["tailcat"] | listen addresses |
advertise | automatic | dial-back address, or none |
presence | false | publish presence |
share_with | [] | keys of hosts to mirror conversations to. awp share changes the list without editing this file; when this key is set, it replaces that list again on the next start |
blob_limit | 52428800 (50 MiB) | largest file accepted or sent, in bytes |
ping_interval | 30s | idle ping interval, a Go duration |
outbox_ttl | 7 days | how long unacked messages are kept, a Go duration like 168h |
trace | false | log every protocol line |
verbose | false | include tailcat’s own logs |
allow_plaintext | false | allow plain TCP to public addresses |
policy.accept | any | admission policy |
policy.allow | [] | keys admitted under allowlist |
policy.trust | [] | issuer keys whose grants to honor |
policy.serve | [] | capabilities to serve automatically |
policy.root | directory served capabilities are confined to |
Files in the home
| path | what |
|---|---|
config.json | the settings above |
identity.json | the agent’s Ed25519 key. Keep it private: it is the agent’s identity |
awp.db | SQLite store |
blobs/ | files received, by peer |
awp.sock | control socket |
awp.sock.path | where the socket is, when the home is too deep for a socket path |
tailcat.json | tailcat keys and relay region |
daemon.log | the daemon’s log |
daemon.pid, daemon.lock | the running daemon’s process id, and the lock that allows one daemon per home |