Skip to content

Credentials ​

Credentials live in .env in Bishop's own directory, or in the environment, and never in .bishop/config.json. Setup writes each interface's to .env and gitignores it. An exported variable wins over the same one in .env. On a host, keep .env at mode 0600, owned by the user Bishop runs as. In a container, pass them as environment variables.

Bishop runs every interface whose credentials are set.

VariableFor
BISHOP_SLACK_BOT_TOKEN, BISHOP_SLACK_APP_TOKENSlack. The xoxb- and xapp- tokens, written by bishop slack setup.
BISHOP_GMAIL_CLIENT_ID, BISHOP_GMAIL_CLIENT_SECRET, BISHOP_GMAIL_REFRESH_TOKENGmail over OAuth. You set the first two, and bishop gmail setup writes the third.
BISHOP_GMAIL_USER, BISHOP_GMAIL_SERVICE_ACCOUNTGmail over domain-wide delegation, instead of the OAuth three. The service account is a path to its JSON key, or the JSON itself.
BISHOP_TEAMS_CLIENT_ID, BISHOP_TEAMS_CLIENT_SECRET, BISHOP_TEAMS_TENANT_IDMicrosoft Teams, written by bishop teams setup.
ANTHROPIC_API_KEY or CLAUDE_CODE_OAUTH_TOKENThe claude harness. Without either, it uses whatever login claude has on the machine.
CODEX_API_KEYThe codex harness. Without it, it uses codex login. OPENAI_API_KEY isn't read.
CODEX_HOMEWhere the codex harness keeps its state, if not ~/.codex.
GH_TOKENThe agent's GitHub credential, written by bishop github setup.
BISHOP_LOG_LEVELThe log level, info by default. The one setting of Bishop's own that isn't in the config file.

Anything else in .env reaches the agent's environment too, which is how GH_TOKEN gets there. Bishop reads .env at startup, so a change needs a restart.

Setup commands that open a browser are meant to run on a laptop. Copy the lines they write to the server's .env.