Skip to content

Environment variables (reference)

The environment variables murk reads, and the CLI flags they mirror where one exists. This is the terse reference. The narrative version with resolution order and interactions lives in the Environment variables concept page.

Variable Description
MURK_KEY Your raw age private key (AGE-SECRET-KEY-1…), inline. Rejected for hardware-plugin identity strings (AGE-PLUGIN-…) — use MURK_KEY_FILE for those.
MURK_KEY_FILE Path to a private-key file: a raw age key, an SSH PEM key, or an age plugin identity file. murk init writes this reference into .env.
MURK_VAULT Vault filename, defaulting to .murk. Equivalent to passing --vault on every command (the one variable in the clap model).
Variable Description
MURK_STRICT Truthy fails closed rather than let a secret touch disk, and disables the automatic key lookup under ~/.config/murk/keys.
MURK_AGENT Marks the process as running for an AI agent. Forces strict mode unconditionally. murk agent exec sets it on its child.
MURK_SELF_SCOPE Truthy holds your own key to the vault’s agent allow-tag policy, as if you were an agent. Implied inside an agent context.
MURK_NO_SIGNER_PIN Opts out of signer-registry pinning (TOFU) on load — an escape hatch for a deliberate signer-key change, not for everyday use.
Variable Description
CI Truthy prints a nudge toward the scoped-agent path when a pipeline decrypts with a personal key. Advisory only.
EDITOR, VISUAL Editor launched by murk edit, checking EDITOR then VISUAL, falling back to vi.
XDG_RUNTIME_DIR Preferred (typically tmpfs) scratch location for murk edit’s temporary file, over /tmp.
HOME (USERPROFILE on Windows) Base directory for murk state: ~/.config/murk/keys, agent-keys, and signer-pins.