Configuration and environment

Environment variables

Variable Effect
CURIOSITY_SERVER Workspace address, when --server is not given.
CURIOSITY_TOKEN A session token to use instead of a stored sign-in. Nothing is stored. For CI.
CURIO_SESSION Session id or name, when --session is not given.
CURIO_TRANSPORT sse forces the server-sent events fallback for the live connection.
CURIO_NO_INTRO 1 skips Sudo's opening run in the two-panel interface.
CURIO_SCREENSAVER_SECONDS Seconds without a key before Sudo's screensaver (default 120). 0 turns it off.

Files

Path Contents
~/.curiosity/curio/config.json The workspaces you signed in to, which one is current, and the last session used on each.
~/.curiosity/curio/credentials.json The refresh token, when it is not in the keyring. Readable only by you, with the tokens encrypted.
.claude/skills/curio/SKILL.md Written by curio skills install, with a .curio-skills.json manifest that lets a later install tell its own files from your edits.

With a keyring available, the token lives there instead of in credentials.json: Windows Credential Manager, the macOS Keychain, or the Secret Service (libsecret) on Linux.

The live connection

curio keeps a WebSocket open to the session (/api/admin-agent/sessions/{id}/ws). Commands go out over it, and every change to the session comes back over it: Sudo editing files in the dock, a commit being staged, an approval in the browser. The header of the two-panel interface says live.

When a proxy does not let a WebSocket through, curio falls back to server-sent events for the changes and plain HTTP for the commands, and the header says live (sse). CURIO_TRANSPORT=sse forces the fallback.

Referenced by

© 2026 Curiosity. All rights reserved.