npm · brainllm
TRILIUM_BASE_URL (required) — Base URL of the TriliumNext instance, e.g. http://localhost:8080
TRILIUM_ETAPI_TOKEN · secret — ETAPI token. Required unless TRILIUM_PASSWORD is set. Create one in Trilium under Options → ETAPI.
TRILIUM_PASSWORD · secret — Alternative to TRILIUM_ETAPI_TOKEN — BrainLLM mints a token on first start and caches it beside brainllm.json.
BRAINLLM_MODE — core (default) exposes the 45 brain-aware tools; full additionally exposes the 33 raw ETAPI tools.
BRAINLLM_TZ — IANA timezone used to stamp dated notes, e.g. Africa/Johannesburg. Defaults to the host timezone.
BRAINLLM_OWNER_PASSWORD · secret — Enables the OAuth 2.1 / CIMD endpoints required by claude.ai and other hosted Claude surfaces. This is the password entered on the consent screen when authorizing a client.
BRAINLLM_OAUTH_SECRET · secret — Optional 32+ character deployment secret for signing OAuth tokens; rotate it to invalidate old tokens.
BRAINLLM_PUBLIC_URL — Override for the public origin when a proxy rewrites Host. Must exactly match the URL entered in the client.
BRAINLLM_ALLOW_UNAUTHENTICATED_HTTP — Explicit trusted-network-only escape hatch for HTTP mode. Never enable on a public interface.
BRAINLLM_TRUST_PROXY — Trust forwarded host/protocol headers for OAuth discovery only when a trusted reverse proxy sets them.