Configuration
Ports, state files, the Node path, where each kind of key comes from, and the web search service and memory settings.
Environment variables
| Variable | Purpose |
|---|---|
RNA_AGENT_PORT | Daemon port, default 4317, 1024 to 65535. The CLI uses it to pick a daemon |
RNA_AGENT_STATE | State file location. One state file cannot be written by several daemons |
RNA_AGENT_NODE | Absolute path of the Node binary for the launcher |
RNA_MODEL_API_KEY, etc. | Variables referenced by apiKeyEnv in provider configs; must be visible to the daemon |
TYPESAFE_API_KEY | The JEV key used when none is saved in settings |
TYPESAFE_ENDPOINT | The JEV service address; settable only by environment variable, read-only in the UI |
The old names PI_FORGE_PORT and PI_FORGE_STATE still work; the new names win. The desktop app also has RNA_DESKTOP_DATA (the data folder). Terminals the daemon starts drop variables beginning with RNA_, TYPESAFE_ or OPENVIKING_ and any *API_KEY, so keys never reach a shell you open in a panel.
Data locations
| Case | Location |
|---|---|
| Desktop private service | ~/Library/Application Support/Rna Agent |
| Desktop connection info | desktop-connection.json in the same folder |
| Running from source | The gitignored prototypes/control-center/.state/ in the repository |
| SDK examples | .rna-sdk-state/ or the example’s own state folder |
Next to state.json are a few companion files: <state>.secrets (keys, 0600), <state>.subscriptions (plan sign-ins, 0600) and <state>.rna/ (session logs; with local memory also memory/embedded.sqlite). All of them are included in restore points.
Key sources
Keys for models, web search and memory have two sources:
- saved in Settings, written to the local credentials file (secrets next to
state.json, mode0600); - an environment variable name set in Settings, read at run time.
The JEV key is different: save it in Settings → Advanced → Judgment under “JEV API key”, or use the fixed environment variable TYPESAFE_API_KEY; there is no field for a variable name.
| Service | Where |
|---|---|
| Model providers | Settings → Models |
| ChatGPT plan sign-in | Settings → Models → OpenAI · ChatGPT plan (browser or device-code sign-in, refreshed on each request) |
| JEV judgments | Settings → Advanced → Judgment |
| Web search and fetching | Settings → Advanced → Web tools |
| Project memory (OpenViking) | Settings → Advanced → Memory → Advanced connection settings |
Settings APIs only report whether a key is configured and where it comes from, never echo it.
Web search services
The web_search and web_fetch tools run over the search service you choose. Turn them on in Settings → Advanced → Web tools (off by default); they apply to every project and session. Whichever service you choose, the model sees the same two tools.
| Service | Key | Page reading |
|---|---|---|
| FastCRW (default) | Optional; a self-hosted compatible service works | Through the service |
| Firecrawl | Optional; works without one, capped per IP | Through the service |
| Tavily | Required | Through the service |
| Brave Search | Required | Read directly from this machine |
| Zhipu Web Search | Required (a Zhipu API key) | Through the service |
| Bocha | Required | Read directly from this machine |
- A service that only searches (Brave, Bocha) has pages read straight from this machine: public addresses only, the connection pinned to the checked address, every redirect hop re-checked, and no key sent; local and private addresses are not read, and pages drawn by scripts may come back empty.
- Each service has its own address and key. Choosing another service switches to its official address and clears the saved key and variable name, so a key is never sent to a service it was not saved for; a service that needs a key is not asked without one.
- “Save and check connection” sends one search and one fetch request. The request timeout can be 1 to 120 seconds.
- On the command line:
./rna web-config --enabled true --provider firecrawland./rna web-test; keys are not accepted in plain text. - Firecrawl (without a key) and the direct reader were verified live; Tavily, Brave, Zhipu and Bocha follow their documented request shapes and were tested only against local fixtures.
Memory mode
In Settings → Advanced → Memory choose “OpenViking semantic memory” or “Local memory (built in)”. The setting memory.backend is openviking or embedded, and on the command line ./rna memory-config --backend embedded. Each way keeps its own memory with no migration. See Memory.
Network
- The daemon listens on
127.0.0.1by default, checks Host and Origin, and requiresapplication/jsonfor writes. - Remote model addresses must use HTTPS; local ones may use HTTP.
- Model catalog probing does not follow redirects, and error responses never echo the upstream body.