> ## Documentation Index
> Fetch the complete documentation index at: https://docs.switchagents.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> These docs moved from docs.flintai.dev to docs.switchagents.ai. Use docs.switchagents.ai for every link and request.
> To search these docs from an AI tool, connect the MCP server at https://docs.switchagents.ai/mcp. The page index is at https://docs.switchagents.ai/llms.txt.

# Environment variables

> Configure Switch Trust CLI behavior with environment variables

**Make `flintai-cli` work for you.** Set these environment variables to customize scans and evals. Defaults work out of the box.

<h2 id="where-settings-come-from">
  Where settings come from
</h2>

Switch Trust CLI reads settings from the following places, highest precedence first:

1. **Your shell or CI environment.** Anything already exported, or set inline on the command (`GENERATOR_MODEL=openai:gpt-5.4 flintai scan ...`), wins over both files below.
2. **A project `.env`.** The nearest `.env` in your working directory or one of its parents. Use this to give a project its own model, keys, and limits.
3. **The global `~/.flintai/.env`.** The fallback for anything the project file doesn't set. It always loads, so a project `.env` can override a setting but never hide one that lives only here.

The two files are merged rather than one replacing the other, so a project `.env` only needs the settings it changes.

<Warning>
  **`flintai init` writes to a project `.env` when there is one.** If the directory you run it from contains a `.env`, `flintai init` replaces that file's contents with the settings it collects, instead of writing to `~/.flintai/.env`. To keep an existing project file, run `flintai init` from somewhere else and set project-specific values by hand afterwards.
</Warning>

## Using environment variables in config.json

Reference environment variables in your config file using `${VAR_NAME}` syntax:

```json theme={null}
{
  "models": [
    {
      "id": "my-chatbot",
      "type": "anthropic",
      "name": "Claude Haiku 4.5",
      "model_name": "claude-haiku-4-5",
      "key": "${ANTHROPIC_API_KEY}",
      "temperature": 0
    }
  ]
}
```

You can use this syntax anywhere in your config.json:

* API keys: `"key": "${ANTHROPIC_API_KEY}"`
* Endpoints: `"host": "${STAGING_URL}"`
* Any string value: `"name": "${AGENT_NAME}"`

<Warning>
  **Security:** Use `${...}` references for API keys rather than pasting them as plaintext. This keeps credentials out of config files.
</Warning>

***

## API keys

Switch Trust CLI uses an LLM to analyze your agent code and filter false positives. Choose one provider:

<Tabs>
  <Tab title="Google Gemini (recommended)">
    **GEMINI\_API\_KEY**

    Free tier available. Get your key: [aistudio.google.com/apikey](https://aistudio.google.com/apikey)
  </Tab>

  <Tab title="OpenAI">
    **OPENAI\_API\_KEY**

    For GPT models. Get your key: [platform.openai.com/api-keys](https://platform.openai.com/api-keys)
  </Tab>

  <Tab title="Anthropic">
    **ANTHROPIC\_API\_KEY**

    For Claude models. Get your key: [console.anthropic.com/settings/keys](https://console.anthropic.com/settings/keys)
  </Tab>

  <Tab title="LiteLLM">
    **Provider-specific API key**

    LiteLLM supports 100+ providers via proxy. Set whichever key your chosen backend expects, such as **OPENAI\_API\_KEY** or **GEMINI\_API\_KEY**. See [docs.litellm.ai](https://docs.litellm.ai/docs/)
  </Tab>
</Tabs>

### How to set your API key

<Tabs>
  <Tab title="flintai init (recommended)">
    Run the interactive setup wizard:

    ```bash theme={null}
    flintai init
    ```

    This writes your provider, API key, and runtime settings to a `.env` — see [where settings come from](#where-settings-come-from) for which one — and creates a `~/.flintai/config.json` skeleton.
  </Tab>

  <Tab title="Manual setup">
    Create `~/.flintai/.env`, or a `.env` in your project, with one of these:

    ```bash theme={null}
    GEMINI_API_KEY=your-key-here
    OPENAI_API_KEY=your-key-here
    ANTHROPIC_API_KEY=your-key-here
    ```

    <Tip>
      For LiteLLM, set the API key for your backend provider. See [docs.litellm.ai](https://docs.litellm.ai/docs/)
    </Tip>
  </Tab>
</Tabs>

<Warning>
  **Production and CI/CD environments**

  The `.env` file stores API keys as plaintext on disk. For production or shared infrastructure, use an external secret manager:

  <Tabs>
    <Tab title="1Password CLI">
      ```bash theme={null}
      op run --env-file=.env -- flintai scan ...
      ```
    </Tab>

    <Tab title="AWS Secrets Manager">
      ```bash theme={null}
      export GEMINI_API_KEY=$(aws secretsmanager get-secret-value --secret-id flintai-api-key --query SecretString --output text)
      ```
    </Tab>

    <Tab title="Google Secret Manager">
      ```bash theme={null}
      export GEMINI_API_KEY=$(gcloud secrets versions access latest --secret="flintai-api-key")
      ```
    </Tab>

    <Tab title="Azure Key Vault">
      ```bash theme={null}
      export GEMINI_API_KEY=$(az keyvault secret show --name flintai-api-key --vault-name your-vault --query value -o tsv)
      ```
    </Tab>
  </Tabs>

  Never commit `.env` files to version control.
</Warning>

<h2 id="generator-model">
  GENERATOR\_MODEL
</h2>

<ParamField path="GENERATOR_MODEL" type="string" required>
  Controls which LLM reads your agent code and filters false positives during scan.

  **Format:** `<provider>:<model-name>`

  **Supported providers:** `gemini`, `openai`, `anthropic`, `litellm`

  `flintai init` sets this for you, using the default it offers for the provider you choose. See [where settings come from](#where-settings-come-from) for which file it writes to.

  **Why this matters:**

  * Faster models = faster scans
  * More capable models = better false positive filtering
  * Cost varies by provider and model

  **Where it's used:**

  * Scan: AI reasoning to analyze agent code and filter false positives
  * Eval: LLM-as-judge scoring, security probe generation

  **Examples:**

  ```bash theme={null}
  # Use Claude Sonnet for better reasoning
  export GENERATOR_MODEL=anthropic:claude-sonnet-4-6

  # Use OpenAI
  export GENERATOR_MODEL=openai:gpt-5.4
  ```
</ParamField>

<h2 id="scanner-reasoning-effort">
  SCANNER\_REASONING\_EFFORT
</h2>

<ParamField path="SCANNER_REASONING_EFFORT" type="string" default="medium">
  Sets how much reasoning a scan asks for when `GENERATOR_MODEL` is an OpenAI GPT-5 reasoning model.

  It applies to those models only. Other providers ignore it, and so do the `gpt-5-chat` variants, which are plain chat models. If a model rejects the value, the scan drops it and continues rather than failing.

  Raise it for closer analysis of complex agent code, lower it for faster and cheaper scans. Your provider's reference lists the levels it accepts.

  **Example:**

  ```bash theme={null}
  export SCANNER_REASONING_EFFORT=high
  flintai scan /path/to/agent
  ```
</ParamField>

<h2 id="flintai-telemetry-consent">
  FLINTAI\_TELEMETRY\_CONSENT
</h2>

<ParamField path="FLINTAI_TELEMETRY_CONSENT" type="boolean" default="false">
  Controls whether Switch Trust CLI shares anonymous usage analytics. Only `true` enables sharing; any other value, or no value at all, keeps it off.

  The first time you run a command, the CLI asks. The prompt accepts on Enter, so pressing Enter turns analytics on. Set this variable before your first run to skip the prompt entirely and use the value you set.

  Your answer is written to your [`.env`](#where-settings-come-from), so run `flintai init` first if you don't have one yet — without it there's nothing to record your answer in, and you're asked again next time. Edit the file to change your answer later.

  In CI the CLI never asks and never shares.

  **Example:**

  ```bash theme={null}
  # Turn analytics off
  FLINTAI_TELEMETRY_CONSENT=false
  ```

  **Shared:** the command you ran, the CLI version, your Python version and operating system, how long the command took, the error type if it failed, whether the run was in CI, and a random client ID that counts installations.

  **Never shared:** your code, file paths, prompts, model responses, scan and eval findings, API keys, and anything that identifies you or your organization.
</ParamField>

<ParamField path="FLINTAI_CLIENT_ID" type="string">
  A random identifier the CLI generates once and stores in your [`.env`](#where-settings-come-from) so analytics can count installations without identifying you. It's tied to nothing else about you or your machine. Delete the line to get a new one.
</ParamField>

## Scan limits

Control how much agent code Switch Trust CLI scans. Raise these if scanning large codebases.

<ParamField path="ADK_MAX_ITERATIONS" type="number" default="40">
  Maximum analysis iterations per agent file.

  **When to change:** Large agents with complex logic need more iterations to analyze thoroughly.

  **Example:**

  ```bash theme={null}
  export ADK_MAX_ITERATIONS=100
  flintai scan /path/to/agent
  ```
</ParamField>

<ParamField path="ADK_MAX_FILES_FETCHED" type="number" default="50">
  Maximum number of files to analyze.

  **When to change:** Scanning a very large codebase (100+ Python files).

  **Example:**

  ```bash theme={null}
  export ADK_MAX_FILES_FETCHED=200
  flintai scan /path/to/large-project
  ```
</ParamField>

<ParamField path="ADK_MAX_FETCH_TOKENS" type="number" default="200000">
  Maximum tokens allowed for file content during scan. Scan stops when limit is reached.

  **When to change:** Scan stops early with "token budget exhausted" on large codebases.

  **Example:**

  ```bash theme={null}
  export ADK_MAX_FETCH_TOKENS=500000
  flintai scan /path/to/agent
  ```
</ParamField>

<ParamField path="ADK_LOOP_TIMEOUT_SECS" type="number" default="600">
  Maximum seconds for analysis before timeout (default is 10 minutes).

  **When to change:** Scanning times out on large codebases or slow models.

  **Example:**

  ```bash theme={null}
  export ADK_LOOP_TIMEOUT_SECS=600  # 10 minutes
  flintai scan /path/to/agent
  ```
</ParamField>

## Eval limits

Eval concurrency is set with `--concurrency` on `flintai eval run`, not with an environment variable:

```bash theme={null}
flintai eval run --model my-agent --concurrency 8
```

***

**Need help?** See [Troubleshooting](/switch-trust-cli/troubleshooting/common-issues#installation) for common configuration issues.
