Configuration

keygrant has no config file. Its behaviour is set by a few environment variables, read by whichever process runs it: the MCP server for agent requests, the CLI for your own commands.

Environment variables

VariableDefaultEffect
KEYGRANT_APPROVAL_TIMEOUT_MS60000How long the local approval dialog waits before treating silence as no answer.
KEYGRANT_APIhttps://api.keygrant.appCloud API endpoint, for testing against your own deployment.
KEYGRANT_REQUESTERset by the serverLabel identifying the requesting session on the phone approver and in the audit trail. The MCP server sets it per process; you don’t normally set it yourself.
XDG_CONFIG_HOME~/.configmacOS and Linux only: where the keygrant folder lives.

Set a variable for the MCP server in your client’s server config, for example in .mcp.json:

{
  "mcpServers": {
    "keygrant": {
      "command": "keygrant-mcp",
      "env": { "KEYGRANT_APPROVAL_TIMEOUT_MS": "120000" }
    }
  }
}

Files

See Storage and platforms for where keygrant keeps its files on each platform and what each one contains.