Getting started

Authentication

How project credentials work: XOROX_PROJECT_ID, XOROX_TOKEN, and where to store them.

Project credentials

A coding agent connects to a project using a project credential — not your XOROX account login. Create one from the project's Credentials tab in the dashboard.

Creating a credential gives you two values:

ValueWhere it comes from
XOROX_PROJECT_IDThe project's id, visible any time in its Credentials tab.
XOROX_TOKENGenerated once, when the credential is created.

XOROX_TOKEN is shown exactly once, at creation time. There is no way to view it again later — if you lose it, create a new credential.

Storing credentials

Add both values to the .env file in the root of the project you're coding in:

.env
XOROX_PROJECT_ID=your-project-id
XOROX_TOKEN=your-token
  • Don't commit .env. Add it to .gitignore if it isn't already ignored.
  • Values in .env take precedence; if a value is missing there, the agent falls back to your shell environment.
  • Neither value is ever written to a config file on disk by the agent itself — only you manage them, in your own .env.

How it's used

Both the local runtime (for automatic Ruleset context) and the MCP server (for Specifications and Tasks) read XOROX_PROJECT_ID and XOROX_TOKEN from .env and send them to the XOROX backend as a bearer token, scoped to that one project.

Revoking and rotating

There's no in-place rotation. To replace a credential: create a new one, update .env with its token, then revoke the old credential from the Credentials tab. A revoked credential stops working immediately and can't be restored.

Multiple credentials

A project can have more than one credential — for example, one per teammate or machine — so you can revoke one without affecting the others. Each credential has its own name, shown in the Credentials list.

Advanced: custom API base URL

An optional XOROX_API_BASE_URL environment variable overrides the backend the agent talks to (defaults to https://api.xorox.eu). Most projects never need to set this.