npm · x-mcp-ai
X_MCP_AUTH_MODE — Authentication mode: oauth2 (default) or app-only.
X_MCP_CLIENT_ID — OAuth 2.0 client ID (oauth2 mode).
X_MCP_CLIENT_SECRET · secret — OAuth 2.0 client secret (confidential clients only).
X_MCP_BEARER_TOKEN · secret — Application-only bearer token (app-only mode).
X_MCP_TOKEN_FILE — Path to the rotating OAuth 2.0 token store (default: OS-resolved).
X_MCP_TOKEN_KEYCHAIN — Set to 1 to keep OAuth 2.0 tokens in the OS keychain (macOS, Linux) instead of a token file. Mutually exclusive with an explicit X_MCP_TOKEN_FILE.
X_MCP_POLICY — Policy preset: read-only (default), engage, publish, manage, or full.
X_MCP_POLICY_ALLOW — Comma-separated op:domain cells to allow on top of the preset (e.g. read:dm,write:dm).
X_MCP_POLICY_DENY — Comma-separated op:domain cells to deny; deny beats allow beats preset.
X_MCP_HIDE_DENIED — Set to 1 to drop policy-denied tools from registration entirely instead of registering them annotated as denied.
X_MCP_MEDIA_DIR — Directory uploads must resolve inside. Media upload is disabled unless this is set.
X_MCP_AVAILABILITY — Comma-separated specially-provisioned access classes to declare: pilot, premium-user, enterprise. Unset means the conservative default (app+user, user-only).
X_MCP_PROFILES_FILE — Path to a profiles file holding named configuration blocks.
X_MCP_PROFILE — Name of the profile to select from the profiles file.
X_MCP_TIMEOUT_MS — Per-HTTP-request timeout in milliseconds (default 30000).
X_MCP_LOG_LEVEL — Diagnostic verbosity on stderr: silent, error, info (default), or debug.
X_MCP_CREDIT_BUDGET — Session spend cap in USD.
X_MCP_BUDGET_MODE — Budget enforcement: warn (default) or hard.