Skip to content

Environment Variables

This is the canonical reference for supported operator-facing ORCA_* variables. Public variables configure normal use. Diagnostic variables opt into advanced or live verification paths. Internal process handshakes are omitted because operators must not set them.

VariablePurposeValues or formatDefault and precedenceSecurity or spending
ORCA_BACKENDSelect the backend used by selectBackend().claude, codex, opencode, or pi--backend sets it; otherwise it overrides selectBackend({ default }).A live run may spend against the selected backend account.
ORCA_BACKEND_MODELOverride the selected backend model.Backend model identifierOverrides perBackend[tag].model and shared config.model; unset keeps code configuration.Model choice can change cost and data handling.
ORCA_BASELINE_POLICYChoose generated-workflow baseline behavior.repair, strict, or accept-dirtyDefaults to repair; --baseline wins.accept-dirty permits user-owned changes, so use it only deliberately.
ORCA_CLAUDE_TRANSPORTChoose Claude transport.stream-json or acpstream-json by default; claude({ transport }) wins over the environment.Both paths use Claude credentials and may spend tokens. ACP is explicit opt-in pending compatibility proof.
ORCA_INSTALL_DIRSet release installer destination.Writable directory$HOME/.local/binThe installer writes executables here; use a trusted directory on PATH.
ORCA_LOOP_EVENTSupply one loop firing event.JSON text; invalid JSON is delivered as a raw stringUnset means no event. orcats serve sets it for child firings.Treat event data as untrusted input and avoid putting secrets in shell history.
ORCA_MONITOR_DIRSet the monitoring-log directory used by packaged run and summary tools.Directory path<current-directory>/.orca/monitoringLogs can contain paths, failures, usage, and cost data; protect them accordingly.
ORCA_VERSIONPin release installation.Version with or without a leading vUnset downloads latest release.Installer still verifies the release checksum.
VariablePurposeValues or formatDefault and precedenceSecurity or spending
ORCA_CLAUDE_ACP_COMMANDOverride the executable used by explicit Claude ACP transport.Executable name or pathclaude-agent-acpExecutes the selected program with your Claude access; trust the path.
ORCA_CODEX_ACP_COMMANDOverride the experimental Codex ACP executable.Executable name or pathVersion-pinned adapter through npxExecutes the selected program with your Codex access; trust the path.
ORCA_EXPERIMENTAL_ACP_BACKENDSEnable experimental ACP paths.1 or comma-separated claude,codexDisabledDiagnostic only; may start credentialed backend processes. Prefer ORCA_CLAUDE_TRANSPORT=acp for Claude.
ORCA_REAL_BACKENDSelect the backend for the gated integration smoke.claude, codex, opencode, or picodexHas no effect unless the live-smoke gate is enabled.
ORCA_REAL_BACKEND_SMOKEPermit a bounded live readiness or integration turn.Exactly 1Disabled; --smoke is the doctor equivalent.Spends a small number of tokens and sends the smoke prompt to the provider. Require explicit consent before enabling it.
ORCA_ACP_BENCHMARK_LIVEPermit live ACP benchmark workloads.Exactly 1DisabledCan run many credentialed turns and spend tokens. Enable only for an intentional benchmark.
ORCA_ACP_CAPTURE_LIVEPermit live ACP transcript scenarios.Exactly 1Disabled for live scenariosCan spend tokens and writes backend transcripts; review captured data before sharing.

The documentation checker derives names from runtime, CLI, installer, packaged skill scripts, and gated diagnostic sources. It requires every public and diagnostic name on this page and in the in-repo reference.