Get started
Configuration.
.briar.toml, and a cascading credential store. Secrets never go in .briar.toml: they are env vars the CLI reads at startup.Project config: .briar.toml
Flags that repeat on every run (company, store, repo, model, git identity) can live in a .briar.toml file, or under [tool.briar] in pyproject.toml. Briar uses the nearest one, searching from the current directory up to the filesystem root. Create one with briar init; check what each setting resolves to with briar config show.
$ company = "acme"$ store = "postgres" # knowledge store: file | postgres$ root = "./knowledge" # file-store root$ tracker = "jira"$ repos = ["acme/widgets", "acme/api"] # optional, feeds extract --repo$ [repo]$ owner = "acme"$ repo = "widgets"$ provider = "github"$ [agent]$ model = "claude-sonnet-4-6"$ git_user_name = "acme-bot"$ git_user_email = "[email protected]"
Precedence, highest first: CLI flag, then env var (BRIAR_COMPANY for company, BRIAR_STORE for store), then the project config, then the git origin remote (for owner / repo only), then the built-in default. A value found this way also makes a normally required flag (like extract --company) optional. For briar extract, --repo takes repos when set, else owner/repo from [repo].
Per-company credential env vars
Most providers ship a single account per developer. Briar multi-tenants on top of that by interpolating a {company} token into the env var name. --company acme reads JIRA_ACME_TOKEN; the same flow with --company widgets reads JIRA_WIDGETS_TOKEN. The company token is uppercased and dashes become underscores. GitHub PATs are the exception — they're workspace-wide, so the var is just GITHUB_TOKEN with no company segment.
Use briar secrets doctor
briar secrets doctor (it walks the runbook YAMLs in ./examples by default) and it lists every env var the configured extractors and writers need, marked present / missing.Tracker credentials
| Provider | Env vars |
|---|---|
| GitHub (PAT) | GITHUB_TOKEN (workspace-wide, no company segment) |
| Bitbucket Cloud | BITBUCKET_{COMPANY}_USERNAME, BITBUCKET_{COMPANY}_APP_PASSWORD, BITBUCKET_{COMPANY}_WORKSPACE |
| Jira (token) | JIRA_{COMPANY}_EMAIL, JIRA_{COMPANY}_TOKEN, JIRA_{COMPANY}_URL |
| Jira (session — for SSO tenants) | JIRA_{COMPANY}_SESSION_TOKEN, JIRA_{COMPANY}_XSRF_TOKEN (+ optional JIRA_{COMPANY}_TENANT_SESSION_TOKEN, JIRA_{COMPANY}_USER_AGENT) |
| Linear | LINEAR_{COMPANY}_TOKEN |
Cloud credentials
| Provider | Env vars / notes |
|---|---|
| AWS | AWS_{COMPANY}_ACCESS_KEY_ID, AWS_{COMPANY}_SECRET_ACCESS_KEY, AWS_{COMPANY}_SESSION_TOKEN (optional), AWS_{COMPANY}_REGION. Or use --aws-extract-profile to point at an existing local boto3 profile. |
| GCP / Azure | Use --cloud gcp / --cloud azure + --aws-extract-profile (carries the project ID / subscription ID) + --aws-extract-region. Flag names read AWS-flavoured but are generic; the underlying SDK picks them up. |
Meeting transcripts
| Provider | Env vars |
|---|---|
| Fireflies | FIREFLIES_{COMPANY}_API_KEY |
Chat and notifications
| Use | Env vars |
|---|---|
Slack read (agent --slack-query) | SLACK_{COMPANY}_TOKEN (browser xoxc- token), SLACK_{COMPANY}_COOKIE_D (the d cookie) |
| Slack notify sink | SLACK_{COMPANY}_WEBHOOK_URL |
| Telegram notify sink | TELEGRAM_BOT_TOKEN, TELEGRAM_{COMPANY}_CHAT_ID |
| Email notify sink | SMTP_HOST, SMTP_PORT, SMTP_USER, SMTP_PASSWORD, SMTP_STARTTLS, EMAIL_FROM, EMAIL_{COMPANY}_TO |
| PagerDuty notify sink | PAGERDUTY_{COMPANY}_ROUTING_KEY |
LLM providers
| Provider | Env vars |
|---|---|
| Anthropic | ANTHROPIC_API_KEY (or CLAUDE_CODE_OAUTH_TOKEN for the Claude Code OAuth bundle) |
| OpenAI | OPENAI_API_KEY |
| Google Gemini | GEMINI_API_KEY |
| AWS Bedrock | Uses the same AWS_{COMPANY}_* as the AWS cloud extractor. |
Briar runtime env vars
These influence how the CLI runs, where it persists state, and which features are enabled.
| Variable | Effect |
|---|---|
BRIAR_VERBOSE | 1/true turns on DEBUG logging, same as --verbose. |
BRIAR_LOG_LEVEL | Explicit log level (DEBUG, INFO, WARNING, ERROR) when --verbose is not set. |
BRIAR_LIB_DEBUG | Enables third-party library debug logging (boto3, urllib3, anthropic SDK). |
BRIAR_COMPANY | Default for every --company flag. Wins over .briar.toml. |
BRIAR_STORE | Default knowledge --store (file / postgres). Wins over store in .briar.toml. Since v1.1.64; before that the knowledge store read BRIAR_DEFAULT_STORE. |
BRIAR_DEFAULT_STORE | Default for briar auth --cred-store when it names a credential store (falls back to envfile). Credentials only. |
BRIAR_SECRETS_FILE | Override the envfile-store path. Without it, briar uses /etc/briar/secrets.env if that file exists, else $XDG_CONFIG_HOME/briar/secrets.env (default ~/.config/briar/secrets.env). |
BRIAR_DATABASE_URL | Postgres DSN for the postgres knowledge / plan / journal backend. Per-company override: BRIAR_{COMPANY}_DATABASE_URL. |
BRIAR_PG_POOL_SIZE | SQLAlchemy connection-pool size (default 4). |
BRIAR_PG_POOL_OVERFLOW | SQLAlchemy overflow size (default 2). |
BRIAR_JOURNAL | off / 0 / no disables the journal entirely. |
BRIAR_JOURNAL_STORE | Journal store backend (default file). |
BRIAR_JOURNAL_ROOT | File-store root (default ./journal). |
BRIAR_JOURNAL_SINKS | Comma-separated sink list (default file). |
BRIAR_NOTIFY_SINKS | Comma-separated notify-sink list for runbook serve failures. Choices: email, pagerduty, slack, telegram. |
BRIAR_TELEMETRY | off / errors-only / full. Per-process override of the persisted tier. |
BRIAR_SENTRY_DSN | Override the Sentry DSN to route telemetry to your own project. |
BRIAR_ENV | Sentry environment tag (default production). |
BRIAR_GITHUB_CLIENT_ID | OAuth App client ID used by briar auth login github-device. Required for that target. |
BRIAR_NO_DEFAULT_MCP | Skip the built-in default MCP servers in agent runs (same as --no-default-mcp). |
BRIAR_NO_UPDATE_CHECK | 1 turns off the "newer version available" notice on stderr. It is also off when DO_NOT_TRACK=1 or BRIAR_TELEMETRY=off. |
DO_NOT_TRACK | Industry-standard. 1 disables all telemetry. Wins over BRIAR_TELEMETRY and any persisted tier. |
Credential stores
Briar reads credentials from one store at a time, picked with --cred-store on auth / secrets commands (the old spelling --store still works there). Four stores ship:
envfile: text file at~/.config/briar/secrets.env(seeBRIAR_SECRETS_FILEabove). Default.aws-secretsmanager— AWS Secrets Manager.ssm— AWS Systems Manager Parameter Store.vault: HashiCorp Vault (KV v2). ReadsVAULT_ADDRandVAULT_TOKEN; needspip install "briar-cli[vault]".
$ briar auth login github-pat --cred-store vault --company acme$ briar auth list --cred-store aws-secretsmanager --company acme
Bootstrap on startup
Bootstraps run before every command and pre-populate os.environ from a remote source. Onlyenvfile ships today (loads secrets.env).
$ briar secrets bootstrap --kind envfile # one-off$ briar secrets bootstrap --dry-run # print keys only
Production hosts
secrets.env world-readable. Use chmod 600 and chown to the user the briar service runs as.Where to go next
- briar auth · secrets · telemetry — the commands that consume everything on this page.
- briar extract — the first command you'll run that needs credentials.