Skip to content
rev0Docs

Configuration

rev0 reads its configuration from environment variables. On startup it loads ~/.rev0/.env (or .env under REV0_DATA_ROOT if you moved the data root), and a variable set in the real environment always wins over the file. The one-line installer starts you off with a copy of .env.example.

Many variables only seed a board setting: once you save that setting in Settings, the saved value wins over the variable. Their descriptions start with “Seeds”.

Create an API token at https://id.atlassian.com/manage-profile/security/api-tokens

VariableDefaultWhat it does
REV0_JIRA_URLunsetYour Jira site, e.g. https://your-org.atlassian.net. This template sets it to https://your-org.atlassian.net.
REV0_JIRA_EMAILunsetThe email address of the Jira account the token belongs to. This template sets it to you@yourcompany.com.
REV0_JIRA_TOKENunsetThe Jira API token. This template sets it to your-api-token.

GitHub integration (read-only via the gh CLI)

Section titled “GitHub integration (read-only via the gh CLI)”

Surfaces GitHub threads where you have responsibility (review requests, comments on your PRs, mentions/assignments) as board tickets so an agent can pre-shoot the work. Auth uses your existing gh login (run gh auth login); no token here. NOTHING is ever pushed or commented: that is hard-blocked in ~/.claude/settings.json (permissions.deny for git push / gh pr comment|review|merge / gh issue comment). The per-repo checkout mapping is the github_repos board setting, which has no control in Settings: write it with PUT /config and the access token, as {"github_repos": [{"match": "owner/repo", "path": "/abs/clone"}]}. Without a match, REV0_GITHUB_REPOS_ROOT below is searched.

VariableDefaultWhat it does
REV0_GITHUB_AUTOSTART0Seeds the github_autostart board setting: 1 moves each new import straight to To Do as a command ticket that runs the pre-shoot skill in the repo’s local clone. Off lands them in the column picked in the import modal, like Jira and Slack.
REV0_GITHUB_REPOS_ROOTunsetDirectory holding your local clones, used to find a repo’s checkout when no github_repos entry matches: tries <root>/<repo> then <root>/<owner>/<repo>.

A user token (xoxp-…) is recommended so it can read any conversation you belong to (incl. DMs and private channels) without adding a bot per channel. Scopes: channels:history, groups:history, im:history, mpim:history, users:read, files:read (files:read is required to import images and attachments).

VariableDefaultWhat it does
REV0_SLACK_TOKENunsetSlack token used to fetch the messages whose links you paste into the board. Separate from the outbound REV0_SLACK_WEBHOOK below.
VariableDefaultWhat it does
REV0_SLACK_WEBHOOKunsetSlack incoming webhook the board posts ticket events to.
REV0_SLACK_DUE_WEBHOOKunsetA separate, private Slack incoming webhook used only for “your result is due” alerts. Point it at a channel or DM only you see. Unset sends no Slack due ping; the in-app bell and OS notification still fire.
REV0_VAPID_CONTACTmailto:kanban@localhostThe contact (a mailto: or https: URL) sent with browser push notifications, as the VAPID standard requires. The placeholder is fine for self-hosting.
REV0_NOTIFICATION_MUTED_KINDSprogressSeeds the muted notification kinds: a comma-separated list of kinds that never raise a notification. Empty mutes nothing.
VariableDefaultWhat it does
REV0_ASSIGNEEclaude-codeOnly tickets assigned to this name are picked up by the runner.
REV0_MODELunsetSeeds the board’s default model for every run; a per-ticket Model (create form, ticket detail, CLI --model, or the update_ticket MCP tool) overrides it. Any pinned model id works. Set this explicitly: headless runs do NOT inherit the model picked interactively via /model, and the account default may be a smaller model. Unset leaves the agent CLI’s own default. This template sets it to claude-opus-4-8.
REV0_THINKING_LEVELunsetSeeds the board’s default reasoning level; a per-ticket Thinking level overrides it. Levels are each provider’s own effort names: off, low, medium, high, xhigh, max for Claude Code, plus minimal and ultra for Codex (config/thinking_levels.json says which models support which). A level a run’s model does not support is clamped down. Unset leaves the CLI’s own behaviour untouched. auto has every run rated instead (see below).
REV0_THINKING_EVAL_MODELhaikuThe model that rates each run’s task when a thinking level is set to auto, and picks the level that run uses. An alias or a model id on any engine; off skips the rating.
REV0_ENGINEclaudeThe engine that drives runs when neither the ticket nor its model picks one: claude, codex or cursor. A model id with a known prefix (gpt-, codex-) picks its engine by itself, so this is rarely needed.
REV0_ENGINE_MODELSunsetPath to the per-engine model config (default: config/engine_models.json), which maps model id prefixes to engines.
REV0_CODEX_TRANSPORTapp-serverHow the board drives the Codex CLI. app-server is the only transport with an approval channel, so it is the only one the permission gate can hold; exec is an escape hatch that runs ungated.
REV0_MODELSunsetPath to the curated model catalog the model dropdown shows (default: config/models.json).
REV0_MODEL_SCRAPE1Set to 0 to stop discovering models from the installed agent CLIs; the dropdown then shows only the catalog.
REV0_THINKING_LEVELSunsetPath to the per-engine, per-model thinking level ladder (default: config/thinking_levels.json).
REV0_THINKING_SCRAPE1Set to 0 to stop discovering thinking levels from the installed agent CLIs.
REV0_MODEL_WINDOWSunsetPath to the model to context window mapping (default: config/model_context_windows.json).
REV0_MODEL_PROMPTINGunsetPath to the per-model system prompt append (default: config/model_prompting.json).
REV0_CLI_PATHunsetWhich claude binary the board spawns. By default it picks the newest of claude on PATH, the newest native install under ~/.local/share/claude/versions, and the SDK’s bundled CLI, because a bundled CLI older than a model rejects that model before any API call. Set this only to pin a specific binary; it is read once, so a change needs a board restart.
REV0_MAX_IDLE_RESUMES1How many times to auto-resume a run that ended still In Progress without calling finish_ticket or request_action (typically an agent that ended its turn waiting for a background task). After this many attempts the ticket escalates to a human.
REV0_MAX_USAGE_LIMIT_RETRIES8How many times a run that hit a usage or session limit may wait for the quota reset and auto-resume before parking for a human. 0 parks immediately.
REV0_MAX_TRANSIENT_RETRIES4Seeds how many times the runner auto-retries a run that failed on a transient model or API error (connection reset, timeout, 5xx, rate limit) before parking the ticket. Retries resume the saved session with exponential backoff. 0 parks immediately.
REV0_TRANSIENT_BACKOFF_BASE2.0Seeds the base seconds of the transient retry backoff (wait is about base * 2^attempt, with jitter).
REV0_TRANSIENT_BACKOFF_MAX30.0Seeds the cap, in seconds, on a single transient retry wait.
REV0_AGENT_STALL_TIMEOUT300Seeds how long, in seconds, the runner waits on a silent agent CLI before treating the run as stalled and retrying it. Applies only while the CLI waits on the model API; a long tool call is never interrupted.
REV0_RETRY_QUEUE_MAX_ATTEMPTS5For a ticket that opts into the retry queue: how many times a genuinely failed run is re-queued before it parks for good.
REV0_RETRY_QUEUE_BACKOFF_BASE60For the retry queue: the first delay in seconds, doubled after each attempt and capped at one hour.
REV0_COMPACT_ENABLEDunsetSet to 0 to never compact a session before resuming it. Unset follows config/model_context_windows.json, which enables it. The Settings value wins over both.
REV0_COMPACT_THRESHOLDunsetFraction of the context window at which a resumed session is compacted before the real prompt is sent. Unset follows config/model_context_windows.json, then 0.75.
REV0_MAX_BUFFER_SIZE20971520Largest single message, in bytes, the runner accepts from the agent CLI. The SDK’s own 1 MB default can kill a run on one wide diff or big file read.
REV0_TOOL_RESULT_MAX_CHARS64000How many characters of each tool result are stored on the ticket. Anything past it is flagged as dropped rather than silently cut.
REV0_MCP_MAX_FIELD_CHARS6000Long string fields in a ticket returned by the kanban MCP tools are clipped to this many characters. The web UI and REST API always see the full text.
REV0_MCP_MAX_RESULT_CHARS40000Any single kanban MCP tool result larger than this many characters is cut, with a notice that says how to get the rest.
REV0_FINAL_SUMMARY_ENABLED1Seeds the Agent final summary setting: 0 tells agents not to end a turn or a ticket with a recap of what they did.
VariableDefaultWhat it does
REV0_BASH_COMPRESS0Set to 1 to compress noisy Bash output before the model reads it: repeated lines collapse, whitespace is stripped and huge outputs keep their head and tail, while test failures are preserved. It only changes what the model sees, never what the command does.
REV0_RTK_ENABLEDunsetSet to 1 to rewrite simple, allow-listed shell commands to their rtk equivalent so their output is filtered at the source. Unset follows config/rtk.json, then off. The Settings toggle wins over both. Install the binary with rev0 install-rtk.
REV0_RTK_CONFIGunsetPath to the rtk config (default: config/rtk.json).
REV0_PONYTAIL_ENABLEDunsetSet to 1 to append the ponytail “lazy senior developer” rules to every agent’s system prompt. Unset follows config/ponytail.json, then off. The Settings toggle wins.
REV0_PONYTAIL_LEVELunsetSeeds the ponytail intensity: lite, full or ultra. Unset follows config/ponytail.json, then full.
REV0_PONYTAIL_CONFIGunsetPath to the ponytail config (default: config/ponytail.json).
VariableDefaultWhat it does
REV0_BROWSER1Every agent run gets a real headless Chromium through the Playwright MCP server, so it can read JS-heavy and anti-bot pages WebFetch cannot. The safe browser_* tools are pre-approved; browser_file_upload and browser_run_code_unsafe still ask. Set to 0 to disable it, or override it with a playwright entry via REV0_MCP_CONFIG.
REV0_COMPUTER_CHROMEunsetThe Chrome binary for the ticket’s computer: the Chromium the board starts per ticket, in the default browser_session_mode “ticket”, for the agent to use and a human to watch and take over. Unset uses installed Google Chrome when present, else Playwright’s Chromium.
REV0_MCP_CONFIGunsetPath to a JSON file in Claude’s mcp.json format ({"mcpServers": {"name": {...}}}) listing extra MCP servers for every agent run, on top of the built-in kanban and browser servers. Their tools are not auto-approved. See config/extra_mcp.example.json.
REV0_ALLOW_MCP_EDIT1Whether the MCP server list can be edited from Settings. A server’s command runs on the runner host, so set 0 to make the list read-only (REV0_MCP_CONFIG still works).
REV0_PLUGIN_PATHSunsetSeeds the external plugin folders, separated by the platform path separator (: on macOS and Linux).
REV0_PLUGIN_CACHEunsetWhere the board clones repo plugin sources (default: ~/.rev0/plugins).
REV0_SKILLS_CONFIGunsetPath to the per-mode skill filter (default: config/skills.json).
REV0_SKILL_PACKS_CONFIGunsetPath to the skill pack manifest (default: config/skill_packs.json).
REV0_AGENT_TOOLS_CONFIGunsetPath to the built-in agent tool config (default: config/agent_tools.json).
REV0_UI_KIT_ENABLED1Seeds the Reusable UI kit setting: steer agents to build visual deliverables from the ui-factory component library instead of hand-written HTML.
REV0_UI_KIT_GUIDANCEunsetPath to the UI kit guidance appended to agent prompts (default: config/ui_kit.json).
REV0_HARNESSESunsetPath to the agent CLI update config (default: config/harnesses.json).
REV0_HARNESS_UPDATEunsetSet to 1 or 0 to force updating the agent CLIs (claude, codex, cursor) on or off. Unset follows the Auto-update the agent CLIs setting (Settings > Agents > Model & thinking, on by default), which updates at startup and every 6 hours.
REV0_HARNESS_CHANNELunsetThe release channel the agent CLIs update from. Unset follows config/harnesses.json, then latest.
VariableDefaultWhat it does
REV0_ORCHESTRATOR_ENABLED1Seeds the Agent orchestration setting: give planning and top-level agents the orchestrator playbook, so they can fan independent work out into subtickets. 0 keeps every ticket a solo agent.
REV0_ORCHESTRATOR_GUIDANCEunsetPath to the orchestrator playbook (default: config/orchestrator.json).
REV0_ORCHESTRATOR_WORKER_MODELsonnetSeeds the model a fan-out subticket defaults to. Blank makes a child inherit its parent’s model.
REV0_ORCHESTRATOR_MAX_CHILDREN6Seeds the advisory cap on how many parallel subtickets one orchestration fans out to.
REV0_ORCH_SELF_APPROVAL0Seeds Orchestrator self-approval: 1 lets an orchestrator approve or correct the plans of its own subtickets without a human.
REV0_ORCH_PERM_DELEGATION0Seeds Orchestrator permission delegation: 1 lets an orchestrator resolve its own subtickets’ permission requests, passing on only grants it already holds.
REV0_DEFAULT_PLAN_TYPEspa_planSeeds the default plan type agents produce when nothing names one: spa_plan, flow_plan or plan_required.
REV0_LOOP_TRIGGERS1Set to 0 to stop polling for Loop event triggers. Only runs with the runner.
REV0_LOOP_POLL_INTERVAL300Seconds between Loop event trigger polls.
REV0_LOOP_RUN_ARCHIVEend_of_daySeeds when a finished Loop run leaves the board for its Loop’s History tab: immediately, end_of_day, never, or a number of minutes.
REV0_LOOP_SCRIPT_SANDBOXsrtSeeds how a Loop script node’s Python is isolated: srt (sandbox-runtime, falling back to a hardened subprocess when it is not installed) or off (in-process, not recommended).
REV0_LOOP_SCRIPT_SANDBOX_NETWORK_DOMAINSunsetSeeds the comma-separated domains a sandboxed Loop script node may reach. Empty denies all network access.
REV0_WEBHOOK_SECRETunsetThe secret that signs per-Loop webhook trigger URLs. Unset falls back to REV0_AUTH_TOKEN; with neither set, webhooks are refused.
VariableDefaultWhat it does
REV0_BTW_MODELunsetModel that answers a side question asked on a ticket while its agent works. Unset uses the ticket’s model, then REV0_MODEL.
REV0_BTW_MAX_TURNS12Most turns a side question may take.
REV0_BTW_TIMEOUT_S300Wall-clock ceiling, in seconds, on one side question.
REV0_BTW_MAX_CONCURRENT2Side questions in flight at once across all tickets. Separate from the agent cap, so a question never costs the board a work slot.
REV0_CHAT_TITLE_MODELhaikuModel that writes chat titles. 0 or off turns titling off.
REV0_DIAGRAM_MODELunsetModel for generated diagrams. Unset uses the ticket’s model, then REV0_MODEL.
REV0_FLOW_MODELunsetModel for flow plan graphs. Unset uses REV0_DIAGRAM_MODEL, then the ticket’s model.
REV0_SUBTASK_MAP_MODELunsetModel for Subtask Map explanations. Unset uses REV0_DIAGRAM_MODEL, then the root ticket’s model.
REV0_SUBTASK_MAP_EXPLAIN0Seeds Subtask map explanations: 1 offers an LLM-written purpose for each subticket and a label for each arrow, generated when you click Explain.
VariableDefaultWhat it does
REV0_MAX_PARALLEL3Seeds how many tickets the runner works on at once, until setup runs: every setup profile writes 8 to Max concurrent agents (Settings > Workspace > Board), which then wins. Different repos are always safe; same-repo tickets run in isolated git worktrees, and the same non-git directory runs one ticket at a time.
REV0_WORKTREE_ROOTunsetWhere per-ticket worktrees live. Unset uses a sibling <repo>.agent_worktrees directory.
REV0_DEFAULT_WORKDIRunsetSeeds the repo a ticket belongs to when neither it nor its parents name one (per board in Settings). Blank means such a ticket runs in scratch.
REV0_SCRATCH_ROOTunsetWhere a ticket that belongs to no repo works: nothing to merge, deliverables on the board. Unset uses ~/.rev0/scratch. Must be outside every checkout.
REV0_REPOS_ROOTunsetSeeds the directory scanned one level deep for git repos, each offered as a quick-pick in a new ticket’s Working directory field. Blank turns the quick-pick off.
REV0_BASE_BRANCHunsetBranch the agent branches off when a ticket does not pick one. Unset auto-detects origin/HEAD, then main or master, then the current branch.
REV0_DELETE_BRANCH_ON_MERGE1On a clean integration, delete the ticket branch.
REV0_GITHUB_CREATE_PR0Default for the per-ticket “Open a GitHub PR” opt-in. Off means integration is local-only: merge the branch into its base, no PR. A ticket’s own flag also enables it.
REV0_GITHUB_AUTO_MERGE0Default for the per-ticket auto-merge opt-in: merge the GitHub PR without a review. Only has an effect when a PR is being opened.
REV0_PR_MERGE_METHODmergeHow auto-merged PRs are merged: merge, squash or rebase.
REV0_MAX_CONFLICT_ATTEMPTS2How many times the runner lets an agent try to resolve a merge conflict before the ticket parks for a human.
REV0_CONFLICT_MAX_TURNS40Most turns one conflict-resolution run may take.
REV0_MAX_DIRTY_RETRIES10How many integration passes (one per poll) a requested merge may wait on a base branch with uncommitted changes before it escalates to a human.
REV0_GIT_NAMEunsetSeeds the name agents commit as. Unset falls back to your global git identity, else rev0.
REV0_GIT_EMAILunsetSeeds the email agents commit as. Unset falls back to your global git identity, else rev0@local.
VariableDefaultWhat it does
REV0_CMD_POLICYsafesafe runs any command that is not flagged dangerous, and only dangerous ones ask. allowlist runs only allow-listed commands, and everything else asks.
REV0_ALLOWED_CMD_PREFIXESunsetA JSON array of command prefixes that REPLACES the built-in safe baseline (uv, git status, npm, …). A value saved in Settings wins over it.
REV0_DANGEROUS_CMD_PATTERNSunsetA JSON array that REPLACES the built-in dangerous command patterns. Each entry is a regex, a [regex, reason] pair or a [regex, reason, highlight_regex] triple. A malformed value falls back to the defaults.
REV0_DANGEROUS_CMD_DISABLE0Set to 1 to turn dangerous command detection off entirely. Not recommended.
REV0_CHILD_ENV_ALLOWLIST0Seeds Allow-list the agent’s environment: 1 builds every agent process’s environment from an allow-list instead of inheriting the board’s, dropping its API token, Jira and Slack tokens and SSH_AUTH_SOCK.
REV0_CHILD_ENV_PASSTHROUGHunsetSeeds the comma-separated variable NAMES to keep on top of that allow-list, such as SSH_AUTH_SOCK or GH_TOKEN.
VariableDefaultWhat it does
REV0_BUDGET_ENFORCEMENT0Seeds Enforce spend budgets: 1 parks a ticket in Pending Action before a turn once a ceiling below is exceeded.
REV0_BUDGET_DAILY_USD400Seeds the ceiling, in US dollars, on agent spend since 00:00 UTC. 0 disables it.
REV0_BUDGET_WEEKLY_USD2000Seeds the ceiling on spend since Monday 00:00 UTC. 0 disables it.
REV0_BUDGET_MONTHLY_USD6000Seeds the ceiling on spend since the 1st of the month (UTC). 0 disables it.
VariableDefaultWhat it does
REV0_AUTH_TOKENunsetShared secret that gates the board when you expose it beyond localhost (for example serve --host 0.0.0.0 for a phone on your Wi-Fi or tailnet). It turns on a one-time cookie login at /login, and the CLI, MCP server and runner pick it up automatically. Unset and bound to localhost, the board stays open with zero config. Generate one: python -c “import secrets;print(secrets.token_urlsafe(32))”
REV0_ALLOW_INSECURE0Set to 1 to start on a non-loopback host with no REV0_AUTH_TOKEN, which is otherwise refused. A loud warning is logged on every start.
REV0_TAILSCALE_HTTPSunsetHow the board uses Tailscale for HTTPS: serve (private tailnet HTTPS), funnel (public HTTPS, requires REV0_AUTH_TOKEN) or off. Unset uses serve when bound off loopback and does nothing on localhost.
VariableDefaultWhat it does
REV0_ARTIFACT_SHARE0Seeds Allow sharing artifacts publicly: 1 shows the Share publicly and Public link controls.
REV0_ARTIFACT_SHARE_TUNNELmanualSeeds the public reachability provider: tailscale, cloudflared, ngrok or manual.
REV0_ARTIFACT_SHARE_BASE_URLunsetSeeds the public base URL used with the manual provider.
VariableDefaultWhat it does
REV0_BOARD_NAMEunsetSeeds what the board calls itself when it writes on a ticket. Unset uses the name generated when the board was created; blank in Settings resets it to “board”.
REV0_USER_NAMEunsetSeeds what agents call you. Blank addresses you impersonally.
REV0_APP_SPACE1Seeds App Space, the top bar gallery of reusable single-page tools.
REV0_KB1Seeds the Knowledge Base app.
REV0_DEBUG_TOOLS0Seeds Debug tools, for people working on the board itself.
REV0_UPDATE_CHECK1Seeds the update check: every 6 hours the board downloads the release manifest to see whether a newer release is out. 0 turns it off.
REV0_UPDATE_URLhttps://github.com/cpc-studio/rev0-releases/releases/latest/download/latest.jsonWhere the update check finds the release manifest, latest.json. Change it only to serve releases from your own mirror; it must be HTTPS.
REV0_SPEND_PILL1Seeds the spend readout in the usage popover.
REV0_USAGE_METERS1Seeds the Claude and Codex rate limit meters.
REV0_TOKENMAXXING_BAR0Seeds the context window usage bar on cards and in the ticket view.
REV0_COLUMN_PAGE_SIZE50Seeds how many cards a column renders before revealing the rest as you scroll.
REV0_TIMELINE_COLLAPSEnoneSeeds which indented timeline levels start folded: none, machinery or indented (every indented level).
REV0_ACTIVITY_RETENTION_DAYS0Seeds how many days the raw agent transcript of a finished ticket is kept. Comments, plans and status history are never deleted. 0 keeps everything.
REV0_WORKSPACE_RETENTION_DAYS0Seeds how many idle days before a ticket’s workspace is cleaned automatically, with the same rules as the Storage section’s Clean selected. 0 never cleans automatically.
REV0_WORKSPACE_CLEAN_ON_MERGEaskSeeds what happens to a ticket’s worktree once its branch merges: ask, instant or days.
REV0_SLICER_OPEN_ENABLED1Seeds the Open in Bambu Studio and Send to printer buttons on 3D model artifacts.
REV0_SLICER_APPBambu StudioSeeds the app a raw 3D model opens in, such as OrcaSlicer.
REV0_STT_MODELfaster-whisper/baseSeeds the local speech-to-text model used for voice input.
REV0_STT_LANGUAGEenSeeds the language spoken into the mic: en, fr, or empty to auto-detect.

static/ (the served UI bundle) is build output and is not committed to git. When it is missing, serve builds it on startup: npm install (only if frontend/node_modules is absent) then npm run deploy. If npm is unavailable or a step fails, it serves a placeholder page instead.

VariableDefaultWhat it does
REV0_BUILD_ON_STARTUP11 builds only when static/ is missing, 0 never builds (CI, or a deploy pipeline that builds out of band), force rebuilds on every startup (same as serve --rebuild).
VariableDefaultWhat it does
CLAUDE_CODE_OAUTH_TOKENunsetClaude Code auth for the runner when there is no interactive claude login (hosted, containers). Get one with claude setup-token on a machine where you are signed in. Subscription auth: no ANTHROPIC_API_KEY needed.
REV0_DATA_ROOTunsetWhere the complete runtime tree lives: database, uploads, scratch, plugin clones, background jobs and .env. Unset uses ~/.rev0; the Docker image sets /data. See deploy/DEPLOY.md.
VariableDefaultWhat it does
REV0_DBunsetPath to the SQLite database. Unset uses rev0.db in the data root.
REV0_BGJOBS_DIRunsetWhere background task logs and exit files live. Unset uses background_jobs in the data root.
REV0_APIhttp://127.0.0.1:8000The board URL the CLI, MCP server and runner talk to.