---
url: https://bishop.agentdeployment.co/reference/credentials.md
description: Every credential Bishop reads, and where it reads them from.
---

# Credentials

Credentials live in `.env` in Bishop's own directory, or in the environment, and never in `.bishop/config.json`. Setup writes each interface's to `.env` and gitignores it. An exported variable wins over the same one in `.env`. On a host, keep `.env` at mode `0600`, owned by the user Bishop runs as. In a [container](/deploying/container), pass them as environment variables.

Bishop runs every interface whose credentials are set.

| Variable | For |
|---|---|
| `BISHOP_SLACK_BOT_TOKEN`, `BISHOP_SLACK_APP_TOKEN` | Slack. The `xoxb-` and `xapp-` tokens, written by `bishop slack setup`. |
| `BISHOP_GMAIL_CLIENT_ID`, `BISHOP_GMAIL_CLIENT_SECRET`, `BISHOP_GMAIL_REFRESH_TOKEN` | Gmail over OAuth. You set the first two, and `bishop gmail setup` writes the third. |
| `BISHOP_GMAIL_USER`, `BISHOP_GMAIL_SERVICE_ACCOUNT` | Gmail over domain-wide delegation, instead of the OAuth three. The service account is a path to its JSON key, or the JSON itself. |
| `BISHOP_TEAMS_CLIENT_ID`, `BISHOP_TEAMS_CLIENT_SECRET`, `BISHOP_TEAMS_TENANT_ID` | Microsoft Teams, written by `bishop teams setup`. |
| `ANTHROPIC_API_KEY` or `CLAUDE_CODE_OAUTH_TOKEN` | The `claude` harness. Without either, it uses whatever login `claude` has on the machine. |
| `CODEX_API_KEY` | The `codex` harness. Without it, it uses `codex login`. `OPENAI_API_KEY` isn't read. |
| `CODEX_HOME` | Where the `codex` harness keeps its state, if not `~/.codex`. |
| `GH_TOKEN` | The agent's GitHub credential, written by [`bishop github setup`](/running/github). |
| `BISHOP_LOG_LEVEL` | The log level, `info` by default. The one setting of Bishop's own that isn't in the config file. |

Anything else in `.env` reaches the agent's environment too, which is how `GH_TOKEN` gets there. Bishop reads `.env` at startup, so a change needs a restart.

Setup commands that open a browser are meant to run on a laptop. Copy the lines they write to the server's `.env`.
