Environment variables
Velaclaw pulls environment variables from multiple sources. The rule is never override existing values.Precedence (highest → lowest)
- Process environment (what the Gateway process already has from the parent shell/daemon).
.envin the current working directory (dotenv default; does not override).- Global
.envat~/.velaclaw/.env(aka$VELACLAW_STATE_DIR/.env; does not override). - Config
envblock in~/.Zavianx/velaclaw-dev.json(applied only if missing). - Optional login-shell import (
env.shellEnv.enabledorVELACLAW_LOAD_SHELL_ENV=1), applied only for missing expected keys.
~/.config/velaclaw/gateway.env as a compatibility fallback after the global .env. If both files exist and disagree, Velaclaw keeps ~/.velaclaw/.env and prints a warning.
If the config file is missing entirely, step 4 is skipped; shell import still runs if enabled.
Config env block
Two equivalent ways to set inline env vars (both are non-overriding):
Shell env import
env.shellEnv runs your login shell and imports only missing expected keys:
VELACLAW_LOAD_SHELL_ENV=1VELACLAW_SHELL_ENV_TIMEOUT_MS=15000
Runtime-injected env vars
Velaclaw also injects context markers into spawned child processes:VELACLAW_SHELL=exec: set for commands run through theexectool.VELACLAW_SHELL=acp: set for ACP runtime backend process spawns (for exampleacpx).VELACLAW_SHELL=acp-client: set forvelaclaw acp clientwhen it spawns the ACP bridge process.VELACLAW_SHELL=tui-local: set for local TUI!shell commands.
UI env vars
VELACLAW_THEME=light: force the light TUI palette when your terminal has a light background.VELACLAW_THEME=dark: force the dark TUI palette.COLORFGBG: if your terminal exports it, Velaclaw uses the background color hint to auto-pick the TUI palette.
Env var substitution in config
You can reference env vars directly in config string values using${VAR_NAME} syntax:
Secret refs vs ${ENV} strings
Velaclaw supports two env-driven patterns:
${VAR}string substitution in config values.- SecretRef objects (
{ source: "env", provider: "default", id: "VAR" }) for fields that support secrets references.
Path-related env vars
Logging
VELACLAW_HOME
When set, VELACLAW_HOME replaces the system home directory ($HOME / os.homedir()) for all internal path resolution. This enables full filesystem isolation for headless service accounts.
Precedence: VELACLAW_HOME > $HOME > USERPROFILE > os.homedir()
Example (macOS LaunchDaemon):
VELACLAW_HOME can also be set to a tilde path (e.g. ~/svc), which gets expanded using $HOME before use.
nvm users: web_fetch TLS failures
If Node.js was installed via nvm (not the system package manager), the built-infetch() uses
nvm’s bundled CA store, which may be missing modern root CAs (ISRG Root X1/X2 for Let’s Encrypt,
DigiCert Global Root G2, etc.). This causes web_fetch to fail with "fetch failed" on most HTTPS sites.
On Linux, Velaclaw automatically detects nvm and applies the fix in the actual startup environment:
velaclaw gateway installwritesNODE_EXTRA_CA_CERTSinto the systemd service environment- the
velaclawCLI entrypoint re-execs itself withNODE_EXTRA_CA_CERTSset before Node startup
node ... launches):
Export the variable before starting Velaclaw:
~/.velaclaw/.env for this variable; Node reads
NODE_EXTRA_CA_CERTS at process startup.