Configuration Reference
Every environment variable AutoControl reads, in one place. Each row names the page that explains the feature; this page only says what the variable is, what it accepts and what happens when it is unset.
Nothing here is required. With no variable set, AutoControl picks the platform
backend by itself, servers bind 127.0.0.1, and every opt-in feature
(signature enforcement, RBAC, USB passthrough, tool-path roots) is off.
test/unit_test/headless/test_modernization_examples.py compares this page
with the code: a variable the package reads and this page does not name fails
CI, in both languages.
Platform backends
Variable |
Values (default first) |
Effect |
|---|---|---|
|
|
Windows keyboard and mouse backend. |
|
unset / a path |
Full path of |
|
|
Interception device id keyboard events are sent to. |
|
|
Interception device id mouse events are sent to. |
|
|
X11 input backend. |
|
|
Which Linux backend loads. |
Wayland
See Capabilities and authorisation on Wayland. probe_capabilities() shows
the effect of each of these without side effects.
Variable |
Values (default first) |
Effect |
|---|---|---|
|
|
|
|
unset / |
Runs the libei session in a helper process instead of in-process. |
|
|
Applies to absolute moves on the |
|
unset / a command line |
Your own screenshot command, with |
|
unset / comma-separated paths |
The |
Logging and local state
Variable |
Values (default first) |
Effect |
|---|---|---|
|
unset / a path |
Where the log file is written. Unset:
|
|
unset / a path / |
File the main window keeps its theme, text size, navigation panel and
geometry in, and the Config Sync tab its server, user and folder
fields (never the shared secret: the file is plain text). Unset:
|
|
|
The active environment of the asset store ( |
|
|
Default screenshot redaction policy. An unknown name is an error, not
|
|
unset / a directory |
Where a remote-desktop viewer stores files its host sends. Unset:
|
|
unset / a directory |
Where the pytest plugin writes failure screenshots when a test did not
request the |
Executing and signing action files
See Keywords & Executor and New Features (2026-06-17) — Automation Toolkit.
Variable |
Values (default first) |
Effect |
|---|---|---|
|
unset / comma-separated names |
Packages |
|
unset / |
Every path that runs an action file refuses one without a valid signature sidecar. |
|
unset / a path |
Ed25519 private key (PEM). Set it on the signing machine only; signing then writes a version-2 sidecar. |
|
unset / a path |
The matching public key. Set it on every machine that executes: it verifies and cannot sign. |
|
unset / a passphrase |
Passphrase of the private key, when it was created with one. |
|
unset / |
Migration mode: once a public key is configured, HMAC sidecars written before version 2 are refused unless this is set. Switch it off again when every file has been re-signed. |
MCP server
See MCP Server (Use AutoControl from Claude).
Variable |
Values (default first) |
Effect |
|---|---|---|
|
unset / |
Only tools marked read-only are offered and callable. |
|
|
How much of the registry |
|
unset / comma-separated entries |
Tool names and |
|
|
Whether the short aliases ( |
|
unset / a token |
Bearer token of the HTTP transport. Not accepted once RBAC is on. |
|
unset / comma-separated origins |
Extra browser origins (exact, e.g. |
|
unset / |
Destructive tools ask the client for confirmation (MCP elicitation) before they run. |
|
unset / directories |
Directories (separated by |
|
unset / |
Also accept the roots the MCP client reports through |
|
unset / comma-separated names |
Environment variables |
|
unset / a path |
JSON-lines file that receives one record per |
|
unset / a directory |
A screenshot is saved there each time a tool fails. |
|
unset / |
The MCP server records mouse, keyboard and clipboard calls in memory instead of performing them, for CI without a display. |
Access control and servers
See Operations & Admin Layer and Cross-Machine Config Sync.
Variable |
Values (default first) |
Effect |
|---|---|---|
|
unset / a path |
The user store file. Setting it is what switches roles on for the REST API and the MCP HTTP transport; unset leaves both on their shared token. |
|
unset / |
Enables USB passthrough opcodes on the remote-desktop channel. |
|
unset / a directory |
The only directory the chat-ops |
|
unset / a secret |
Shared secret of the signaling / config-sync server
( |
|
unset / a path |
SQLite file the signaling server keeps config-sync buckets in. Unset:
|