Skip to content

Configuration

The openbase CLI is configured with a few environment variables and a couple of global flags. Credentials are stored on disk by the shared sign-in flow.

Environment Variables

Variable Purpose Default
OPENBASE_APP Default app for -a/--app, so you can omit the flag —
OPENBASE_API_URL Override the Openbase Cloud base URL https://app.openbase.cloud
OPENBASE_HOST Alias for OPENBASE_API_URL —
AGENT_SESSION_ID Vendor-neutral agent/session UUID used for mutation attribution CODEX_THREAD_ID when available

Set a default app for a shell session:

export OPENBASE_APP=my-app
openbase logs --tail        # no -a needed

Agent Attribution

Every mutation (config changes, deploys, restarts, hostname edits, teardowns) is recorded against whoever made it. Agent runtimes export the session UUID as AGENT_SESSION_ID automatically (with Codex's native CODEX_THREAD_ID as a fallback); other callers can provide one explicitly:

export AGENT_SESSION_ID=cac5ccd4-2499-4784-a2a6-05e3b2caa98b
openbase config set -a my-app FEATURE_FLAG=on

The CLI sends the resolved ID as the X-Openbase-Agent-Id header. AGENT_SESSION_ID takes precedence over automatic runtime detection. When no ID is available, the CLI sends nothing and Openbase Cloud records the mutation as human. Attribution shows up in the AGENT column of openbase releases and in release webhook notifications.

Credentials

Sign-in is delegated to the openbase-coder CLI and writes to a shared file:

~/.openbase/auth.json

Both openbase and openbase-coder read this file, so signing in with either tool authenticates both. openbase logout removes it. See login and logout.

Global Flags

Flag Description
-V, --version Print the CLI version and exit
-h, --help Show help for the CLI or any subcommand
-a, --app NAME Target app for app-scoped commands (or OPENBASE_APP)
--json Machine-readable JSON output (supported by most read commands)

JSON Output

Most read commands accept --json for scripting. Secret config values are never returned by the API; in openbase config get --json (and the full listing) they appear as null. The full config listing prompts for confirmation on a terminal and warns (deprecation) when run non-interactively without --confirm — pass --confirm, or better, request only the keys you need with config get.

openbase apps --json
openbase config get -a my-app --json SOME_KEY   # only the keys you ask for
openbase config -a my-app --confirm --json      # full dump (deliberate)
openbase usage --json

Talking to a Different Backend

Point the CLI at a non-production Openbase Cloud API (for example a staging environment) with OPENBASE_API_URL:

OPENBASE_API_URL=https://app-staging.openbase.cloud openbase apps