> ## Documentation Index
> Fetch the complete documentation index at: https://docs.githits.com/llms.txt
> Use this file to discover all available pages before exploring further.

# GitHits CLI environment variable reference

> GitHits CLI environment variables for authentication, request grouping, storage, profiling, and output.

The GitHits CLI reads several environment variables at startup. You can use them to authenticate without a browser, switch credential storage modes, or suppress update notifications.

| Variable | Purpose | Default |
| - | - | - |
| `GITHITS_API_TOKEN` | API token for authentication (format: `ghi-...`) | — |
| `GITHITS_AUTH_STORAGE` | Override OAuth storage mode: `keychain` or `file` | `keychain` |
| `GITHITS_SESSION_ID` | Explicit request-grouping identifier, 1–64 ASCII letters, digits, `_`, or `-` | Automatically detected and hashed |
| `GITHITS_TELEMETRY` | Emit end-of-run timing spans to stderr when set to `1`, `true`, `yes`, or `on` | — |
| `GITHITS_DISABLE_UPDATE_CHECK` | Disable npm latest-version update notices | — |
| `GITHITS_DISABLE_SKILL_UPDATE` | Disable automatic refresh of installed MCP guidance | — |
| `NO_COLOR` | Disable ANSI color output when present, including an empty value | — |

***

## GITHITS\_API\_TOKEN

Set an API token to authenticate without browser OAuth. This is the recommended approach for CI pipelines, automation scripts, and headless environments where a browser login isn't practical.

Tokens follow the format `ghi-...` and can be generated from your [GitHits account settings](https://githits.com).

When `GITHITS_API_TOKEN` is set, the CLI skips local OAuth storage entirely. You can verify this with `npx githits@latest auth status`, which reports the credential source.

<CodeGroup>
  ```bash Shell export theme={null}
  export GITHITS_API_TOKEN=ghi-your-token-here
  npx githits@latest auth status
  ```

  ```bash Inline (single command) theme={null}
  GITHITS_API_TOKEN=ghi-your-token-here npx githits@latest auth status
  ```

  ```yaml GitHub Actions theme={null}
  - name: Run GitHits
    env:
      GITHITS_API_TOKEN: ${{ secrets.GITHITS_API_TOKEN }}
    run: npx githits@latest example "retry with exponential backoff"
  ```
</CodeGroup>

<Note>
  `GITHITS_API_TOKEN` takes precedence over stored OAuth credentials. If both are present, the environment variable is used.
</Note>

***

## GITHITS\_AUTH\_STORAGE

Override the OAuth credential storage mode for a single process or for all GitHits commands in the current shell session.

* `keychain` (default) — stores OAuth credentials in the system keychain (macOS Keychain, Windows Credential Manager, Linux Secret Service).
* `file` — stores OAuth credentials as JSON files in the GitHits config directory.

Use `file` mode in SSH sessions, CI environments, or when persistent keychain prompts remain even after granting access.

<CodeGroup>
  ```bash Login with file storage (one-off) theme={null}
  GITHITS_AUTH_STORAGE=file npx githits@latest login --force
  ```

  ```bash Set for the current shell session theme={null}
  export GITHITS_AUTH_STORAGE=file
  npx githits@latest login
  ```
</CodeGroup>

<Warning>
  File storage is not encrypted. Any process running as your OS user can read the stored tokens. For CI and automation, use `GITHITS_API_TOKEN` instead.
</Warning>

## GITHITS\_SESSION\_ID

Since `githits` and `@githits/mcp` 0.25.1, set `GITHITS_SESSION_ID` to group requests from a CLI or local MCP run under an explicit identifier. Set it before starting the process. The value is sent unchanged in `x-githits-session-id` and takes precedence over automatic terminal detection.

Use 1–64 ASCII letters, digits, underscores, or hyphens (`[A-Za-z0-9_-]{1,64}`). GitHits does not trim or hash an explicit value. Empty values, whitespace, Unicode, slashes, and longer values are invalid; errors do not echo the supplied value. Unset the variable to restore automatic detection, which hashes a terminal identifier, parent process ID, or fallback UUID.

```bash theme={null}
GITHITS_SESSION_ID=ci_run-42_agent-a npx githits@latest search "routing" --in npm:express
```

Choose an opaque identifier without credentials or personal data because it is transmitted as supplied. This value groups requests; it does not authenticate them or replace a Research `thread_id`. For local MCP, set it in the server process environment. A client-side environment variable does not configure the hosted MCP service.

## GITHITS\_DISABLE\_SKILL\_UPDATE

Set any non-empty value to disable automatic refresh of installed `githits-mcp` skills when the local CLI MCP server starts. Available from 0.26.0. See [skill refresh configuration](/cli/configuration#the-skills-section).

```bash theme={null}
GITHITS_DISABLE_SKILL_UPDATE=1 npx githits@latest mcp start
```

## GITHITS\_TELEMETRY

Set `GITHITS_TELEMETRY` to `1`, `true`, `yes`, or `on` to emit end-of-run timing spans to stderr. Matching is case-insensitive and ignores surrounding whitespace. Other values leave profiling disabled. The output goes to stderr only and does not affect stdout.

```bash theme={null}
GITHITS_TELEMETRY=1 npx githits@latest example "connect to redis"
```

***

## GITHITS\_DISABLE\_UPDATE\_CHECK

When set to any non-empty value, suppresses the npm latest-version check and update notice that the CLI prints when a newer version is available. Useful in CI environments where the notice would pollute log output.

```bash theme={null}
export GITHITS_DISABLE_UPDATE_CHECK=1
```

***

## NO\_COLOR

Set the standard `NO_COLOR` variable to disable ANSI color output. Any present value disables color, including an empty value.

```bash theme={null}
NO_COLOR=1 npx githits@latest pkg upgrade-review npm:zod@4.3.6 --to 4.4.3
```

For one CLI invocation, you can also pass the global `--no-color` option.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.