pypi · attestari
ATTESTARI_KEK · secret — Base64 32-byte root key. Set it to enable encryption at rest and cryptographic erasure (forget() destroys the subject's key and signs the certificate). Without it, forget() is a logical delete and certificates are left unsigned.
ATTESTARI_DATABASE_URL · secret — Postgres DSN. Set it to use Postgres + pgvector instead of the default local SQLite file (concurrent access, indexed hybrid search).
ATTESTARI_SQLITE_PATH — Where the default SQLite ledger lives.
ATTESTARI_MCP_ALLOW_FORGET — Set to 1 to offer the forget_subject tool (off by default, since erasure is irreversible and an agent can be steered by what it reads). When on, it is flagged destructive and takes two calls: a preview that returns a manifest hash, then a confirmation that passes it back.
ANTHROPIC_API_KEY · secret — Enables Claude-powered fact extraction; falls back to the built-in regex extractor when unset.