pypi · grafomem-cgr
GRAFOMEM_CGR_TENANT_KEY (required) · secret — Your GRAFOMEM Cloud tenant API key (X-API-Key). Needs decisions:read for the durability guard.
GRAFOMEM_CGR_TENANT (required) — The tenant id you expect that key to resolve to. If the key resolves to any other tenant, every write is refused.
GRAFOMEM_CGR_ROLE_KEYS_JSON — Role handles to public agent_key (64-hex Ed25519), inline as JSON. Example: {"cc-builder@acme":"<64-hex>"}. Use this or GRAFOMEM_CGR_ROLE_KEYS.
GRAFOMEM_CGR_ROLE_KEYS — Path to a JSON file with the same role-handle to public agent_key mapping. Use this or GRAFOMEM_CGR_ROLE_KEYS_JSON.
GRAFOMEM_CGR_FORBIDDEN_TENANTS — Comma-separated tenant ids to always refuse, even if pinned by mistake. Put your production tenant here.
GRAFOMEM_API — GRAFOMEM Cloud base URL. Defaults to https://api.grafomem.com.