Skip to content

Environment variables ​

Every environment variable humanize reads, and every one it sets in the environment of a process it starts. Variables read only by a coding agent CLI itself are out of scope except where humanize reads them too.

Which process reads them ​

ProcessReads its environment when
hmz (the TUI)at start; terminal and theme variables
a workspace's runs hostforked from the first hmz in that workspace that starts it; every variable read while a run executes is that first hmz's environment, not that of frontends attached later
the daemonforked from the first hmz on the machine that starts it; reads none for a run. TMPDIR decides where it is: two hmz with different ones reach different daemons
hmz execat start, and throughout its run
a Python program using hmz.sdk / hmz.runtimethroughout
hmz internal …at start (flag defaults)
a remote machine's shellHUMANIZE_HOME and CUDA_VISIBLE_DEVICES, read by the probe run over ssh

Values are read with os.environ; hmz changes its own environment in one case only (TEXTUAL_DISABLE_KITTY_KEY, below).

humanize's own ​

VariableValuesDefaultEffect
HUMANIZE_HOMEa path; empty is unset~/.hmzRoot of humanize's home, which holds what it keeps but your own flows (~/.hmz/flows), its cache and this machine's own directory: see Files. A ~/.humanize from before is moved there. On an ssh machine the remote login shell's ${HUMANIZE_HOME:-$HOME/.hmz} decides the directory there; a relative value there is taken under the remote $HOME.
HUMANIZE_DAEMONoff, 0, no (trimmed, case-insensitive) mean off; anything else ononOff: plain hmz, and hmz web, hold runs in their own process instead of the runs host. Not read by hmz exec.
HUMANIZE_NAMEany string; empty is unsetthe login name (getpass.getuser()), else somebodyThe name a frontend attaches under (<name>@<kind>, #2… on a clash).
HUMANIZE_SENTRYon, 1, true, yes → on; off, 0, false, no → off (trimmed, case-insensitive); anything else ignoredthe enable_sentry settingAnswers the error-report question for this process only, without writing anything. /settings shows that the variable overrides the setting.
HUMANIZE_SESSIONSoff, 0, no (trimmed, case-insensitive) mean offonOff: a CLI's sessions stay in the CLI's own home instead of the epic's sessions/<cli>/. See Tracing.
HUMANIZE_WATCHDOGa number of seconds (float); <= 0 disables; a value that is not a number is ignoredper CLI: 900 s; dsh 360 sSeconds a turn may be silent before the watchdog acts on it. Overrides every CLI's own value.
HUMANIZE_PRICESa URL (contains ://) or a file path; "", off, 0, no, none (case-insensitive) disable fetchinghttps://openllmprices.com/data/prices.jsonWhere the price table used for budgets and the tally is refreshed from (at most once per 24 h, by the interface and by every run), into $TMPDIR/humanize-<uid>/prices.json.
HUMANIZE_RELEASESa URL (contains ://) or a file path; "", off, 0, no, none (case-insensitive) disable askinghttps://pypi.org/pypi/hmz/jsonWhere the newest release of hmz is asked for: by hmz update, and, at most once per 24 h, by the interfaces as they open, into $TMPDIR/humanize-<uid>/releases.json.
HUMANIZE_SHADOWSa path (~ expanded); empty is unset~/.cache/humanize/shadowsDirectory of mirror records (<sha16>.json) for this process and its children.
HUMANIZE_SSH_REUSEoff, 0, no, false (trimmed, case-insensitive) or set and empty turn it off; anything else ononOn: every ssh humanize runs adds -o ControlMaster=auto -o ControlPersist=120 -o ControlPath=<dir>/%C[-<digest>], <dir> being $XDG_RUNTIME_DIR/humanize-ssh-<uid> (or the temporary directory). Read once per process.
HUMANIZE_RENDEZVOUSa host or address; empty is unsetthe address this machine uses to reach the outside (UDP route to 192.0.2.1), else 127.0.0.1Default of hmz internal anchor --broker, and the address an in-process rendezvous broker advertises.
HUMANIZE_RENDEZVOUS_PORTan integer0 (any free port)Port of the process's shared rendezvous broker (listening on 0.0.0.0). A non-integer raises ValueError.
HUMANIZE_TARGETssh://HOST, docker://CONTAINER[@ENDPOINT], apple-container://CONTAINER, slurm://JOBID[?python=PATH], tcp://HOST:PORT, peer://TICKET@HOST:PORT, local[:DIR]localDefault of hmz internal anchor --target. Also set by humanize inside an anchored agent (below).
HUMANIZE_HARNESSlocal, same, or a target spellinglocalDefault of hmz internal anchor --harness.
HUMANIZE_SHADOWa path--workspaceDefault of hmz internal anchor --shadow: the mirror directory on the machine the harness runs on. Set by humanize for a remote harness (below).
HUMANIZE_TOKENa stringnoneDefault of --token for hmz internal anchor (the secret a tcp:// target expects) and hmz internal anchor serve (the secret clients must present; a mismatch is refused with invalid token). serve --listen on a non-loopback address without a token fails: hmz: cannot listen on a non-loopback address without --token.
HUMANIZE_LOGdebug, info, warning, error (trimmed, case-insensitive); empty is unsetwarning for anchor and anchor serve; info for anchor rendezvousLog level on stderr of those three commands, where --log-level is not given. Any other value is ignored: the command says hmz: ignoring HUMANIZE_LOG='<value>', which is not one of debug, info, warning, error on stderr and logs at its default.

hmz internal flags: CLI and Remote execution.

Terminal ​

VariableValuesEffect
NO_COLORany non-empty valueNo colour in hmz exec output. Checked first.
TERMdumbNo colour, as NO_COLOR.
FORCE_COLORnon-empty and not 0Colour even into a pipe.
TEXTUAL_THEMEa Textual theme name; unknown names ignoredThe TUI's theme. Default: the terminal theme.
TMUX, TERM_PROGRAM, LC_TERMINALWhere TMUX is empty or unset and TERM_PROGRAM is iTerm.app or LC_TERMINAL is iTerm2, hmz sets TEXTUAL_DISABLE_KITTY_KEY=1 in its own environment (if unset) before the TUI starts, so input-method text reaches the prompt.

System ​

VariableRead byEffect
HOMEeverything (~)Home directory. When a turn runs under an account, the backend home is resolved against that turn's HOME.
PATHCLI discovery; fenceWhere a CLI is found; every PATH directory is readable inside the fence for a script's #!/usr/bin/env interpreter.
XDG_CONFIG_HOMEbackend profiles, Cursor AgentDefault ~/.config. Locates CLI credentials kept there (Claude Code anthropic, Cursor cursor/auth.json), skills directories of opencode, MiMo Code and Cursor, and Cursor's fence write grant.
XDG_RUNTIME_DIRssh transportParent of the ssh control-socket directory humanize-ssh-<uid>; else the temporary directory.
DOCKER_HOSTdocker transportA docker target with no context of its own is "this machine" where DOCKER_HOST is unset, empty, or unix://….
CUDA_VISIBLE_DEVICESlocal and ssh environmentsComma list of indices or GPU- UUID prefixes, read up to the first entry that matches no GPU. Set but empty: 0 GPUs. Unset: every GPU nvidia-smi lists. Decides the GPUs an environment reports against GPUEnvMixin.
TMPDIR, TEMP, TMPPython's tempfileTemporary directories (indirectly).

Backend homes ​

Where each CLI keeps its state and logs. Read to find sessions to trace, to fence the CLI, and to locate its credentials. <var> set: <var>[/<sub>]; unset: <HOME>/<default>.

CLIVariableSubDefault
claudeCLAUDE_CONFIG_DIR~/.claude
codexCODEX_HOME~/.codex
dshDSH_HOME~/.dsh
grokGROK_HOME~/.grok
kimiKIMI_CODE_HOME~/.kimi-code
piPI_CODING_AGENT_DIR~/.pi/agent
ompPI_CODING_AGENT_DIR~/.omp/agent
qwenQWEN_HOME~/.qwen
opencodeXDG_DATA_HOMEopencode~/.local/share/opencode
mimoXDG_DATA_HOMEmimocode~/.local/share/mimocode
cursor-agentCURSOR_CONFIG_DIR~/.cursor
mcodeMINIMAX_DATA_DIR~/.minimax
agynone (its --app_data_dir, in an account's arguments, moves it)~/.gemini/antigravity-cli

The fence's grants for a CLI's own state use fixed ~/… paths, not these variables.

DSH_HOME is also read directly for DeepSeek Harness's settings.yaml, .credentials.yaml and .env. For a dsh turn with no account, the API key variable's name is llm-deepseek.apiKeyEnv in $DSH_HOME/settings.yaml (default DEEPSEEK_API_KEY); the key is taken from that variable, then .credentials.yaml, then the project's .env, then $DSH_HOME/.env, and DEEPSEEK_BASE_URL likewise.

Account variables ​

A CLI reads its credentials and endpoint from the environment. humanize reads the same variables to decide which hosts a fenced session may reach, to list an account's models, and to keep a shell's credentials from overriding an account's.

Hushing. A turn run under an account starts with every variable in its CLI's hushed set removed, then the account's own env added: a key exported in a shell profile never outranks the account. A turn with no account (@local) keeps the shell's.

Endpoint. Where the account (or, with no account, the shell) sets the CLI's endpoint variable, the model list is read from GET <endpoint>/models.

CLIEndpoint variable
claudeANTHROPIC_BASE_URL
agyGOOGLE_GEMINI_BASE_URL
codexCODEX_PROVIDER_URL
dshDEEPSEEK_BASE_URL
grokGROK_XAI_API_BASE_URL
kimiKIMI_MODEL_BASE_URL
qwenOPENAI_BASE_URL
mimoMIMO_GATEWAY_URL
pi, omp, opencode, cursor-agent, mcode, acpnone

Reachable hosts under online NONE. The hosts the CLI's model and sign-in are at, plus the host (and port) of every variable in the turn's environment whose name ends in _URL, _BASE, _HOST, _ENDPOINT, _ORIGIN or _ISSUER, plus, for Claude Code (and for omp, the CLAUDE_CODE_USE_FOUNDRY row):

Switch (non-empty)Region/resource variableOverride
CLAUDE_CODE_USE_BEDROCKAWS_REGION (default us-east-1)ANTHROPIC_BEDROCK_BASE_URL
CLAUDE_CODE_USE_VERTEXCLOUD_ML_REGION (default us-east5)ANTHROPIC_VERTEX_BASE_URL
CLAUDE_CODE_USE_FOUNDRYANTHROPIC_FOUNDRY_RESOURCEANTHROPIC_FOUNDRY_BASE_URL

A region or resource must be a DNS label.

Hushed sets.

CLIVariables
claudeANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN, ANTHROPIC_BASE_URL, ANTHROPIC_CONFIG_DIR, ANTHROPIC_CUSTOM_HEADERS, ANTHROPIC_MODEL, ANTHROPIC_OAUTH_TOKEN, ANTHROPIC_VERTEX_PROJECT_ID, AWS_PROFILE, AWS_REGION, CLAUDE_CODE_API_KEY_FILE_DESCRIPTOR, CLAUDE_CODE_OAUTH_REFRESH_TOKEN, CLAUDE_CODE_OAUTH_TOKEN, CLAUDE_CODE_OAUTH_TOKEN_FILE_DESCRIPTOR, CLAUDE_CODE_USE_BEDROCK, CLAUDE_CODE_USE_FOUNDRY, CLAUDE_CODE_USE_GATEWAY, CLAUDE_CODE_USE_VERTEX, CLOUD_ML_REGION
agyAGY_ADC_AUTH, AGY_LLM_GATEWAY_API_KEY, AGY_LLM_GATEWAY_CA_CERT, AGY_LLM_GATEWAY_HEADERS, AGY_LLM_GATEWAY_MODELS, AGY_LLM_GATEWAY_PROXY_URL, AGY_LLM_GATEWAY_URL, AGY_LLM_GATEWAY_WIRE_PROTOCOL, CLOUD_CODE_URL, GEMINI_API_KEY, GOOGLE_API_KEY, GOOGLE_APPLICATION_CREDENTIALS, GOOGLE_GEMINI_BASE_URL
codexAWS_BEARER_TOKEN_BEDROCK, AWS_PROFILE, AWS_REGION, AZURE_OPENAI_API_KEY, AZURE_OPENAI_API_VERSION, AZURE_OPENAI_BASE_URL, CODEX_ACCESS_TOKEN, CODEX_API_KEY, CODEX_AUTHAPI_BASE_URL, CODEX_OSS_BASE_URL, CODEX_PROVIDER_KEY, CODEX_PROVIDER_URL, OPENAI_API_BASE, OPENAI_API_KEY, OPENAI_BASE_URL, OPENAI_FEDERATION_RULE_ID, OPENAI_IDENTITY_TOKEN_FILE
dshDEEPSEEK_API_KEY, DEEPSEEK_BASE_URL, DEEPSEEK_SEARCH_BASE_URL, DSH_GATEWAY_API
grokGROK_AUTH, GROK_AUTH_PATH, GROK_AUTH_PROVIDER_COMMAND, GROK_AUTH_PROVIDER_LABEL, GROK_AUTH_TOKEN_TTL, GROK_CLI_CHAT_PROXY_BASE_URL, GROK_CODE_XAI_API_KEY, GROK_CONFIG, GROK_CONFIG_PATH, GROK_DEFAULT_MODEL, GROK_GATEWAY_API_BACKEND, GROK_MODELS_BASE_URL, GROK_MODELS_LIST_URL, GROK_OAUTH2_CLIENT_ID, GROK_OAUTH2_ISSUER, GROK_OIDC_AUDIENCE, GROK_OIDC_CLIENT_ID, GROK_OIDC_ISSUER, GROK_OIDC_SCOPES, GROK_XAI_API_BASE_URL, XAI_API_KEY
kimiKIMI_API_KEY, KIMI_BASE_URL, KIMI_CODE_BASE_URL, KIMI_CODE_CUSTOM_HEADERS, KIMI_CODE_OAUTH_HOST, KIMI_MODEL_ADAPTIVE_THINKING, KIMI_MODEL_API_KEY, KIMI_MODEL_BASE_URL, KIMI_MODEL_CAPABILITIES, KIMI_MODEL_DISPLAY_NAME, KIMI_MODEL_MAX_COMPLETION_TOKENS, KIMI_MODEL_MAX_CONTEXT_SIZE, KIMI_MODEL_MAX_OUTPUT_SIZE, KIMI_MODEL_MAX_TOKENS, KIMI_MODEL_NAME, KIMI_MODEL_PROVIDER_TYPE, KIMI_MODEL_REASONING_KEY, KIMI_MODEL_TEMPERATURE, KIMI_MODEL_THINKING_EFFORT, KIMI_MODEL_THINKING_KEEP, KIMI_MODEL_TOP_P, KIMI_OAUTH_HOST, KIMI_REGION, KIMI_REGISTRY_API_KEY, MOONSHOT_API_KEY
piAI_GATEWAY_API_KEY, ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN, ANTHROPIC_OAUTH_TOKEN, ANT_LING_API_KEY, AWS_ACCESS_KEY_ID, AWS_BEARER_TOKEN_BEDROCK, AWS_PROFILE, AWS_REGION, AWS_SECRET_ACCESS_KEY, AZURE_OPENAI_API_KEY, AZURE_OPENAI_API_VERSION, AZURE_OPENAI_BASE_URL, AZURE_OPENAI_DEPLOYMENT_NAME_MAP, AZURE_OPENAI_RESOURCE_NAME, BASETEN_API_KEY, CEREBRAS_API_KEY, CLAUDE_CODE_OAUTH_TOKEN, CLOUDFLARE_ACCOUNT_ID, CLOUDFLARE_API_KEY, CLOUDFLARE_GATEWAY_ID, DEEPSEEK_API_KEY, FIREWORKS_API_KEY, GEMINI_API_KEY, GOOGLE_API_KEY, GROK_CODE_XAI_API_KEY, GROQ_API_KEY, KIMI_API_KEY, MINIMAX_API_KEY, MISTRAL_API_KEY, MOONSHOT_API_KEY, NVIDIA_API_KEY, OPENAI_API_KEY, OPENCODE_API_KEY, OPENROUTER_API_KEY, QWEN_TOKEN_PLAN_API_KEY, QWEN_TOKEN_PLAN_CN_API_KEY, TOGETHER_API_KEY, XAI_API_KEY, XIAOMI_API_KEY, XIAOMI_TOKEN_PLAN_AMS_API_KEY, XIAOMI_TOKEN_PLAN_CN_API_KEY, XIAOMI_TOKEN_PLAN_SGP_API_KEY, ZAI_API_KEY, ZAI_CODING_CN_API_KEY
ompABLITERATION_API_KEY, AIAND_API_KEY, AIMLAPI_API_KEY, AI_GATEWAY_API_KEY, ALIBABA_CODING_PLAN_API_KEY, ALIBABA_TOKEN_PLAN_API_KEY, ANTHROPIC_API_KEY, ANTHROPIC_FOUNDRY_API_KEY, ANTHROPIC_OAUTH_TOKEN, AWS_ACCESS_KEY_ID, AWS_BEARER_TOKEN_BEDROCK, AWS_PROFILE, AWS_REGION, AWS_SECRET_ACCESS_KEY, AZURE_OPENAI_API_KEY, BAILIAN_TOKEN_PLAN_API_KEY, BASETEN_API_KEY, BIGMODEL_API_KEY, CEREBRAS_API_KEY, CHARM_HYPER_API_KEY, CLAUDE_CODE_OAUTH_TOKEN, CLAUDE_CODE_USE_FOUNDRY, CLINE_API_KEY, CLOUDFLARE_AI_GATEWAY_API_KEY, COMMAND_CODE_API_KEY, COPILOT_GITHUB_TOKEN, COREWEAVE_API_KEY, COREWEAVE_PROJECT, CURSOR_ACCESS_TOKEN, DEEPINFRA_API_KEY, DEEPSEEK_API_KEY, DEVIN_API_KEY, FIREPASS_API_KEY, FIREWORKS_API_KEY, FOUNDRY_BASE_URL, FUGU_API_KEY, GEMINI_API_KEY, GITLAB_TOKEN, GMI_API_KEY, GOOGLE_API_KEY, GOOGLE_APPLICATION_CREDENTIALS, GOOGLE_CLOUD_API_KEY, GOOGLE_CLOUD_LOCATION, GOOGLE_CLOUD_PROJECT, GROK_CODE_XAI_API_KEY, GROQ_API_KEY, HF_TOKEN, HUGGINGFACE_HUB_TOKEN, HYPER_API_KEY, KILO_API_KEY, KIMI_API_KEY, LITELLM_API_KEY, LLAMA_CPP_API_KEY, LM_STUDIO_API_KEY, META_API_KEY, MINIMAX_API_KEY, MINIMAX_CODE_API_KEY, MINIMAX_CODE_CN_API_KEY, MISTRAL_API_KEY, MODEL_API_KEY, MOONSHOT_API_KEY, NANO_GPT_API_KEY, NOVITA_API_KEY, NVIDIA_API_KEY, OLLAMA_API_KEY, OLLAMA_CLOUD_API_KEY, OMP_AUTH_BROKER_TOKEN, OMP_AUTH_BROKER_URL, OPENAI_API_KEY, OPENAI_CODEX_OAUTH_TOKEN, OPENCODE_API_KEY, OPENROUTER_API_KEY, QIANFAN_API_KEY, QWEN_OAUTH_TOKEN, QWEN_PORTAL_API_KEY, SAKANA_API_KEY, SILICONFLOW_API_KEY, SILICONFLOW_CN_API_KEY, SYNTHETIC_API_KEY, TOGETHER_API_KEY, UMANS_AI_CODING_PLAN_API_KEY, VENICE_API_KEY, VERCEL_AI_GATEWAY_API_KEY, VLLM_API_KEY, WAFER_SERVERLESS_API_KEY, WANDB_API_KEY, XAI_API_KEY, XAI_OAUTH_TOKEN, XIAOMI_API_KEY, XIAOMI_TOKEN_PLAN_AMS_API_KEY, XIAOMI_TOKEN_PLAN_CN_API_KEY, XIAOMI_TOKEN_PLAN_SGP_API_KEY, YOLO_AUTO_API_KEY, ZAI_API_KEY, ZENMUX_API_KEY, ZHIPU_API_KEY
qwenANTHROPIC_API_KEY, ANTHROPIC_BASE_URL, ANTHROPIC_MODEL, BAILIAN_CODING_PLAN_API_KEY, BAILIAN_TOKEN_PLAN_API_KEY, GEMINI_API_KEY, GEMINI_MODEL, GOOGLE_API_KEY, GOOGLE_CLOUD_LOCATION, GOOGLE_CLOUD_PROJECT, GOOGLE_GEMINI_BASE_URL, GOOGLE_GENAI_USE_VERTEXAI, GOOGLE_MODEL, GOOGLE_VERTEX_BASE_URL, OPENAI_API_BASE, OPENAI_API_KEY, OPENAI_BASE_URL, OPENAI_MODEL, QWEN_API_KEY, QWEN_BASE_URL, QWEN_CODE_MODEL, QWEN_DEFAULT_AUTH_TYPE, QWEN_MODEL, QWEN_OAUTH_MODELS
opencodeANTHROPIC_API_KEY, ANTHROPIC_BASE_URL, DEEPSEEK_API_KEY, GEMINI_API_KEY, GITHUB_TOKEN, GOOGLE_API_KEY, OPENAI_API_KEY, OPENCODE_API_KEY, OPENCODE_AUTH_CONTENT, OPENCODE_CONFIG_CONTENT, OPENCODE_WELLKNOWN, OPENROUTER_API_KEY
mimoANTHROPIC_API_KEY, ANTHROPIC_BASE_URL, AWS_BEARER_TOKEN_BEDROCK, AWS_PROFILE, AWS_REGION, AZURE_API_KEY, AZURE_RESOURCE_NAME, DEEPSEEK_API_KEY, GOOGLE_CLOUD_PROJECT, GOOGLE_GENERATIVE_AI_API_KEY, GOOGLE_VERTEX_LOCATION, GROK_CODE_XAI_API_KEY, MIMOCODE_AUTH_CONTENT, MIMOCODE_CONFIG_CONTENT, MIMO_API_KEY, MIMO_GATEWAY_API, MIMO_GATEWAY_KEY, MIMO_GATEWAY_MODEL, MIMO_GATEWAY_URL, OPENAI_API_KEY, OPENROUTER_API_KEY, XAI_API_KEY, XIAOMI_API_KEY
cursor-agentCURSOR_API_BASE_URL, CURSOR_API_ENDPOINT, CURSOR_API_KEY, CURSOR_API_URL, CURSOR_AUTH_TOKEN, CURSOR_LOCAL_AGENT_API_KEY
mcodeMAVIS_REGION, MCODE_API_BASE_URL, MCODE_AUTH_BASE_URL, MCODE_AUTH_PROVIDER, MCODE_CLIENT_ID, MCODE_GATEWAY_FORMAT, MCODE_GATEWAY_MODEL, MCODE_GATEWAY_URL, MCODE_PROVIDER_API_KEY, MCODE_REGION, MINIMAX_API_KEY, MINIMAX_CN_API_KEY
acpnone

Aliases hushed together: CLAUDE_CODE_OAUTH_TOKEN/ANTHROPIC_OAUTH_TOKEN, GEMINI_API_KEY/GOOGLE_API_KEY, MOONSHOT_API_KEY/KIMI_API_KEY, OPENAI_BASE_URL/OPENAI_API_BASE, XAI_API_KEY/GROK_CODE_XAI_API_KEY.

Other variables read for a CLI. NODE_COMPILE_CACHE (pi, qwen) and NODE_OPTIONS (appended to, never replaced) are respected if already set; QWEN_CODE_SYSTEM_DEFAULTS_PATH is read from the turn's environment to know which files to watch.

Set for processes humanize starts ​

VariableSet inValue
HUMANIZEan anchored agent (supervised: its environment; native: an env prefix on the target command)humanize's version
HUMANIZE_TARGETthe samethe target, as --target spells it
HUMANIZE_WORKSPACEthe samethe workspace as the target names it
PWDan anchored agent; every command run on a targetthe working directory
TERMa command run on a target with a terminalxterm-256color unless set
HUMANIZE_SHADOWhmz internal anchor started for a harness on another machineits mirror: $HOME/.cache/humanize-mirrors/<sha16> on an ssh machine, /tmp/humanize-mirrors/<sha16> in a container
HUMANIZE_TOKENa local hmz internal anchor serve --stdio childthe token
the account's envevery turn, sign-in and model listing under an accountfrom providers/<cli>/<name>/provider.json (Files); includes fixed values a sign-in way sets (e.g. CLAUDE_CODE_USE_BEDROCK=1, AWS_REGION=us-east-1)
a CLI's home variable and XDG_CONFIG_HOMEa native turn on another machine under an account whose credential files live in the CLI's homea per-session mktemp -d directory on the target holding copies of those files, removed after the turn
CLAUDE_CODE_DISABLE_BACKGROUND_TASKSevery claude turn1
OPENCODE_PERMISSION, MIMOCODE_PERMISSIONopencode/mimo turns with a rung, web switch or fence to expressa JSON permission table
MIMOCODE_DISABLE_CLAUDE_CODEmimo turns whose fence does not allow reading ~/.claude.json1
MIMO_GATEWAY_MODELmimo turns under a gateway accountthe turn's model, without a leading humanize/
QWEN_CODE_SYSTEM_SETTINGS_PATHevery qwen turna per-session settings file
NODE_COMPILE_CACHEpi, qwen turns on this machine, unless already set$TMPDIR/humanize-<uid>/compiled/pi, …/compiled/qwen
NODE_OPTIONS, HMZ_PRELOAD_ATkimi, pi, qwen, mimo turns on this machine with an on_pre_tool_use hook hung--require <preload> appended; the preload's report socket (the preload sets HMZ_PRELOAD_IN itself and removes all three from programs the CLI starts)
DSH_HOMEdsh turnsthe kept directory
DSH_PERMISSION_MODEdsh turnsdanger-full-access
DEEPSEEK_API_KEY, DEEPSEEK_BASE_URLdsh turns with no accountas resolved (see Backend homes)
PKG_NATIVE_CACHE_PATHfenced dsh turnsthe fence's scratch directory
TMPDIR, TMP, TEMPeverything inside hmz internal fencethe fence's scratch directory
XDG_CACHE_HOME, UV_CACHE_DIR, npm_config_cache, PIP_CACHE_DIR, GOCACHEinside the fence, where the current location is not writable under it<scratch>/cache/<name in lower case>
HTTPS_PROXY, HTTP_PROXY, ALL_PROXY and lower-case forms; NO_PROXY=, no_proxy=; NODE_USE_ENV_PROXY=1inside the fence, where online is NONEhttp://127.0.0.1:<proxy port>
DOCKER_HOST, DOCKER_CONTEXT, DOCKER_TLS, DOCKER_TLS_VERIFY, DOCKER_CERT_PATH (removed)every docker command addressing a provider's own daemon—
PATHdocker commands to an ssh:// daemon with ssh options$TMPDIR/humanize-<uid>/docker-ssh/<sha16>:$PATH (a shim that removes itself)
SSH_ASKPASS_REQUIREthe ssh that checks a runtimenever (fail rather than prompt)
HOME, NVIDIA_VISIBLE_DEVICES, and the provider's envcontainers of docker environmentsHOME=/tmp; NVIDIA_VISIBLE_DEVICES=void unless GPUs are handed out
the variables an ACP agent asks forcommands an acp agent asks humanize to runas asked
TEXTUAL_DISABLE_KITTY_KEYhmz's own environment, direct iTerm2 only1 if unset

A variable humanize removes: every hushed account variable not set by the account (see Account variables).

What crosses to a target. A command run on another machine gets the caller's environment layered over the target's, less DISPLAY, HOME, HOSTNAME, HOSTTYPE, LOGNAME, MACHTYPE, MAIL, OLDPWD, OSTYPE, PATH, PWD, SECURITYSESSIONID, SHELL, SHLVL, TEMP, TMP, TMPDIR, USER, WAYLAND_DISPLAY, _, and every variable starting Apple, DYLD_, HUMANIZE_, LD_, SSH_, XDG_, XPC_ or __CF, and any named with --private.

Released under the Apache-2.0 licence.