You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Pyrite reads ~/.pyrite/config.yaml (or $PYRITE_CONFIG_DIR/config.yaml), then
applies PYRITE_* environment variables on top. An environment variable always
wins when it is set. Nothing here is required: a fresh install works with no
config file at all.
Where things live
Variable
Default
Meaning
PYRITE_CONFIG_DIR
~/.pyrite
Directory holding config.yaml. When unset, a .pyrite/config.yaml found in the current directory or any parent is used instead of ~/.pyrite — a repo-local registry, so a checkout's kb/ resolves to that checkout.
PYRITE_DATA_DIR
~/.pyrite
Directory for the index (index.db) and cloned repos (repos/). Set this in containers and point a volume at it.
PYRITE_STATIC_DIR
<checkout>/web/dist
Built web UI to serve at /. Needed when the package is installed into site-packages rather than run from a checkout.
PYRITE_BRANDING_DIR
built-in
Folder of white-label branding assets (see deploy/branding-examples/)
Server
Variable
Default
Meaning
PYRITE_HOST
127.0.0.1
Bind address. Containers need 0.0.0.0.
PYRITE_PORT
8088
Port
PYRITE_CORS_ORIGINS
localhost dev ports
Comma-separated allowed origins
PYRITE_API_KEY
unset
Single admin API key (legacy single-key mode). Prefer api_keys in config.yaml — hashed keys with a role each.
config.yaml:
settings:
host: 127.0.0.1port: 8088api_keys:
- key_hash: "<sha256 of the key>"role: read # read | write | adminlabel: "Reader"
Authentication (multi-user)
Variable
Default
Meaning
PYRITE_AUTH_ENABLED
false
Turn on user accounts and per-KB permissions
PYRITE_AUTH_ANONYMOUS_TIER
unset
What an unauthenticated request may do when auth is enabled (read, write, admin, or none for nothing). Unset falls back to the API-key role.
If set, stored GitHub access tokens are encrypted at rest with it. Set it on any shared instance.
Per-KB access: each KB in config.yaml may carry default_role: read (public
to any authenticated user), write, or none (private: explicit grants only).
Grants are managed over the REST API by an admin
(GET/POST /api/kbs/{name}/permissions) or in the web UI's KB settings; there
is no CLI command for them yet.
Search and embeddings
Variable
Default
Meaning
PYRITE_SEARCH_MODE
keyword
Default search mode: keyword, semantic, hybrid
PYRITE_AUTO_EMBED
true
Embed entries when they are written. 0/false turns it off: keyword search only, no torch import and no model download on the write path. pyrite index embed backfills later.
PYRITE_PREWARM_EMBEDDINGS
false
Load the embedding model at server start instead of on the first write or semantic search
config.yaml also sets embedding_model (default all-MiniLM-L6-v2, ~90 MB,
downloaded on first use) and search_backend (sqlite or postgres, with
database_url for the latter).
AI features
Variable
Default
Meaning
PYRITE_AI_PROVIDER
unset
openai or anthropic
PYRITE_AI_MODEL
provider default
Model name
API keys for providers are the providers' own variables (OPENAI_API_KEY,
ANTHROPIC_API_KEY); Pyrite is bring-your-own-key.
Plugins
Variable
Default
Meaning
PYRITE_STRICT_PLUGINS
false
Fail startup if any installed plugin fails to load, instead of skipping it. Recommended in CI.
Seeing the effective configuration
pyrite-admin config show # merged config with secrets masked
pyrite kb list # registered KBs and their paths
curl localhost:8088/health # server: index path, embedding readiness