/ documentation

Environment variables

The CLI's six environment variables: GitHub, directories, API, device credentials, local HTTP, and browser launch behavior.

The CLI reads six environment variables at runtime: GITHUB_TOKEN, MALETA_CLI_HOME, MALETA_API_ORIGIN, MALETA_DEVICE_TOKEN, MALETA_ALLOW_INSECURE_ORIGIN, and MALETA_NO_BROWSER. The packages/core package does not read any environment variables.

#GITHUB_TOKEN

GITHUB_TOKEN
stringoptionaldefault: não definida

Token sent as authorization: Bearer <token> in GitHub API requests. It only raises the request limit for public skills; the CLI works without it.

  • The header is only attached when the request host is in the fixed list: api.github.com, github.com and raw.githubusercontent.com. Any other host is rejected with refusing GitHub token on a non-GitHub host.
  • The value is sent to the child process making the request through stdin, never as a command-line argument, so it does not appear in the process list.
  • The token is never written to disk or printed: it does not appear in [error] … or in --dry-run output.
  • Redirects are followed manually and only to the three allowed hosts; a Location outside them is rejected.
  • A 401 or 403 response becomes the single message GitHub access denied or rate limited — the CLI does not read rate-limit headers.
Token for a single run
bash
GITHUB_TOKEN=ghp_exemplo maleta install --file ./maleta.json

#Directories, API, and device

MALETA_CLI_HOME
stringoptionaldefault: os.homedir()

Overrides the home directory used to build skill destinations and store credentials and state. When set to a non-empty value, ~ points to that value.

MALETA_API_ORIGIN
stringoptionaldefault: https://app.maleta.dev

Overrides the origin used by device commands; trailing slashes are removed. With MALETA_DEVICE_TOKEN, it also sets the origin of the environment-provided credential.

MALETA_DEVICE_TOKEN
stringoptionaldefault: not set

Overrides credentials.json for CI and headless machines. The environment credential takes precedence over the file; login and logout reject operations that would create or remove this external credential.

MALETA_ALLOW_INSECURE_ORIGIN
stringoptionaldefault: not set

When set to exactly 1, allows a non-HTTPS MALETA_API_ORIGIN for local development. Otherwise, the device API rejects the insecure origin.

MALETA_NO_BROWSER
stringoptionaldefault: not set

When set to exactly 1, prevents maleta login from opening a browser. The URL and code are still printed; the CLI also skips the browser when stdout is not a TTY.

  • The value is resolved with path.resolve; a relative path is interpreted from the process's cwd.
  • It only affects the ~/.claude/skills and ~/.agents/skills destinations. It does not change the skill source or the location of packaged assets.
  • The variable is not persisted in any file or copied to maleta.json.
Install in an alternate home directory
bash
MALETA_CLI_HOME=/tmp/qa-home maleta install --file ./maleta.json

#The browser token is separate

On public skill pages, the token is stored in sessionStorage under the key maleta-gh-token for the tab session only and sent as token <valor> exclusively to https://api.github.com. On the first visit, an old copy of that key in localStorage is deleted. This is independent of GITHUB_TOKEN: the CLI does not read browser storage, and the browser does not read the process environment. To learn what is stored and how to delete it, see the privacy policy.