Credentials
Credentials live in .env in Bishop's own directory, or in the environment, and never in .bishop/config.json. Setup writes each interface's to .env and gitignores it. An exported variable wins over the same one in .env. On a host, keep .env at mode 0600, owned by the user Bishop runs as. In a container, pass them as environment variables.
Bishop runs every interface whose credentials are set.
| Variable | For |
|---|---|
BISHOP_SLACK_BOT_TOKEN, BISHOP_SLACK_APP_TOKEN | Slack. The xoxb- and xapp- tokens, written by bishop slack setup. |
BISHOP_GMAIL_CLIENT_ID, BISHOP_GMAIL_CLIENT_SECRET, BISHOP_GMAIL_REFRESH_TOKEN | Gmail over OAuth. You set the first two, and bishop gmail setup writes the third. |
BISHOP_GMAIL_USER, BISHOP_GMAIL_SERVICE_ACCOUNT | Gmail over domain-wide delegation, instead of the OAuth three. The service account is a path to its JSON key, or the JSON itself. |
BISHOP_TEAMS_CLIENT_ID, BISHOP_TEAMS_CLIENT_SECRET, BISHOP_TEAMS_TENANT_ID | Microsoft Teams, written by bishop teams setup. |
ANTHROPIC_API_KEY or CLAUDE_CODE_OAUTH_TOKEN | The claude harness. Without either, it uses whatever login claude has on the machine. |
CODEX_API_KEY | The codex harness. Without it, it uses codex login. OPENAI_API_KEY isn't read. |
CODEX_HOME | Where the codex harness keeps its state, if not ~/.codex. |
GH_TOKEN | The agent's GitHub credential, written by bishop github setup. |
BISHOP_LOG_LEVEL | The log level, info by default. The one setting of Bishop's own that isn't in the config file. |
Anything else in .env reaches the agent's environment too, which is how GH_TOKEN gets there. Bishop reads .env at startup, so a change needs a restart.
Setup commands that open a browser are meant to run on a laptop. Copy the lines they write to the server's .env.