# EvoScientist — cp .env.example .env && fill in your keys # LLM provider (pick at least one) ANTHROPIC_API_KEY= # console.anthropic.com OPENAI_API_KEY= # platform.openai.com GOOGLE_API_KEY= # aistudio.google.com/api-keys NVIDIA_API_KEY= # build.nvidia.com # Direct providers (optional) MINIMAX_API_KEY= # platform.minimaxi.com (China, default) or platform.minimax.io (Global) MINIMAX_BASE_URL= # https://api.minimaxi.com/anthropic (default) or https://api.minimax.io/anthropic ZHIPU_API_KEY= # open.bigmodel.cn (智谱) VOLCENGINE_API_KEY= # volcengine.com (火山引擎) DASHSCOPE_API_KEY= # dashscope.aliyuncs.com (阿里云) MOONSHOT_API_KEY= # platform.moonshot.cn (月之暗面) KIMI_API_KEY= # kimi.com/code (Kimi 代码计划) # Aggregator platforms (optional) SILICONFLOW_API_KEY= # siliconflow.cn OPENROUTER_API_KEY= # openrouter.ai # Custom endpoints (optional) CUSTOM_OPENAI_API_KEY= # OpenAI-compatible endpoint CUSTOM_OPENAI_BASE_URL= CUSTOM_ANTHROPIC_API_KEY= # Anthropic-compatible endpoint CUSTOM_ANTHROPIC_BASE_URL= # Local models (optional) OLLAMA_BASE_URL= # http://localhost:11434 (default) # Web search (optional) TAVILY_API_KEY= # app.tavily.com # WebUI provider editor. Local processes running as the same OS user share # ~/.config/evoscientist/provider-admin-token automatically. For different # hosts, users, or containers, set the same random value on both processes. # Integrated `EvoSci` WebUI mode also passes a shared token automatically. EVOSCIENTIST_PROVIDER_ADMIN_TOKEN= # WebUI conversation workspace policy. EVOSCIENTIST_WORKSPACE_DIR is the # deployment root, not a per-conversation directory. In isolated modes each # conversation is stored under /.evoscientist/conversations//. # # EVOSCIENTIST_WORKSPACE_ISOLATION accepts exactly: # - legacy: all WebUI conversations share the deployment root. Compatibility # rollback only; files are visible to every conversation using this deployment. # - optional: default. New WebUI conversations receive isolated scope folders; # missing Registry/token/scope fails the request instead of silently sharing. # - required: isolated scopes plus strict runtime validation. It requires a # completed cutover and a verified OCI executor; no legacy fallback exists. # # This is a deployment-startup security setting. Change it only during a # maintenance window, restart backend and WebUI afterwards, and never use it to # convert an existing conversation between shared and isolated directories. EVOSCIENTIST_WORKSPACE_DIR= EVOSCIENTIST_WORKSPACE_ISOLATION=optional # Required mode supports only a single-host Registry topology in v1. EVOSCIENTIST_SCOPE_REGISTRY_TOPOLOGY=single-host # Required mode: use a pinned image digest, preserve single-host topology, and # keep the Code Interpreter disabled unless its scoped implementation is enabled. # Do not put EVOSCIENTIST_BACKEND_SERVICE_TOKEN here for a same-host `EvoSci # deploy`: it is generated and passed privately at startup. # EVOSCIENTIST_WORKSPACE_ISOLATION=required # EVOSCIENTIST_STRICT_EXECUTOR=oci # EVOSCIENTIST_STRICT_EXECUTOR_IMAGE=registry.example/evoscientist-runtime@sha256:replace-with-verified-digest # EVOSCIENTIST_STRICT_CODE_INTERPRETER=disabled # Conversation workspace isolation retention defaults (used by workspace_maintenance.py). EVOSCIENTIST_DRAFT_WORKSPACE_TTL_HOURS=24 EVOSCIENTIST_WORKSPACE_TRASH_RETENTION_DAYS=7