The environment variables murk reads, and the CLI flags they mirror where one exists. This is the terse reference; the narrative version with resolution order and interactions lives in the Environment variables concept page.
| Variable |
Description |
MURK_KEY |
Your raw age private key (AGE-SECRET-KEY-1…), inline. Rejected for hardware-plugin identity strings (AGE-PLUGIN-…) — use MURK_KEY_FILE for those. |
MURK_KEY_FILE |
Path to a private-key file: a raw age key, an SSH PEM key, or an age plugin identity file. murk init writes this reference into .env. |
MURK_VAULT |
Vault filename, defaulting to .murk. Equivalent to passing --vault on every command (the one variable in the clap model). |
| Variable |
Description |
MURK_STRICT |
Truthy fails closed rather than let a secret touch disk, and disables the automatic key lookup under ~/.config/murk/keys. |
MURK_AGENT |
Marks the process as running for an AI agent. Forces strict mode unconditionally; murk agent exec sets it on its child. |
MURK_SELF_SCOPE |
Truthy holds your own key to the vault’s agent allow-tag policy, as if you were an agent. Implied inside an agent context. |
MURK_NO_SIGNER_PIN |
Opts out of signer-registry pinning (TOFU) on load — an escape hatch for a deliberate signer-key change, not for everyday use. |
| Variable |
Description |
CI |
Truthy prints a one-line nudge toward the scoped-agent path when a pipeline decrypts with a personal key. Advisory only. |
EDITOR, VISUAL |
Editor launched by murk edit, checking EDITOR then VISUAL, falling back to vi. |
XDG_RUNTIME_DIR |
Preferred (typically tmpfs) scratch location for murk edit’s temporary file, over /tmp. |
HOME (USERPROFILE on Windows) |
Base directory for murk state: ~/.config/murk/keys, agent-keys, and signer-pins. |