Agent-readable docs index: /llms.txt. Full docs in one file: /llms-full.txt. Download /docs.zip to grep all markdown files locally.

Configuration and environment variables

Global flags

Most commands that resolve the login, project or environment accept these, and each has an environment variable. A flag wins over its variable, and both over what sigillo login and sigillo setup saved.
FlagEnvironment variableWhat it sets
--token <sig_xxx>SIGILLO_TOKENAn API or machine token to use instead of a login
--api-url <url>SIGILLO_API_URLYour instance. There is no default; sigillo login --api-url saves it
--project <id> / -p <id>SIGILLO_PROJECTThe project, by ID or name
--env <slug> / --config <slug> / -c <slug>SIGILLO_ENVIRONMENTThe environment's slug, such as dev or prod
The CLI reference lists every command's own flags.

Workload identity

Without a token or a login, the CLI exchanges a workload's JWT for a token of one hour, from the first of these that is set. Empty variables count as unset.
Environment variableWhat it holds
SIGILLO_OIDC_TOKEN_FILEA file with the JWT, such as a Kubernetes projected service account token
SIGILLO_OIDC_TOKENThe JWT itself
ACTIONS_ID_TOKEN_REQUEST_URL, ACTIONS_ID_TOKEN_REQUEST_TOKENSet by GitHub Actions in a job with id-token: write: the CLI asks GitHub for a JWT for your instance
With workload identity, SIGILLO_PROJECT must be the project's ID. See workload identity.

self-host

Environment variableWhat it sets
CLOUDFLARE_API_TOKENThe Cloudflare API token to deploy with, like --api-token
SIGILLO_SELFHOST_PASSPHRASEThe passphrase of ~/.sigillo/selfhost.json, for runs without a terminal
SIGILLO_ENCRYPTION_KEYYour own encryption key, on the first deploy only
self-host's flags are on Self-host your instance.

Files

The CLI keeps its files in ~/.sigillo, or %APPDATA%\sigillo on Windows:
FileWhat's in it
config.jsonYour logins, one per server, and the project and environment sigillo setup saved for each directory
audit.jsonThe newest row of each history chain sigillo audit verify has seen, and the instance's signing key
selfhost.jsonWritten by self-host, in ~/.sigillo on every system: the keys and settings of your deployments, encrypted with your passphrase. See your deploy file
bin/sigilloThe CLI itself, when installed with the curl script

Scoped logins

A login is saved for a directory and everything below it, / unless you say otherwise. To use another login, or a token, in one directory:
sigillo login --api-url https://secrets.acme.com --scope . sigillo login --api-url https://secrets.acme.com --token sig_xxx --scope .
sigillo login always starts a new login, also when one is saved, so run it again when the CLI says not signed in, or the session expired. A saved login is only sent to the server it was saved for.