Getting started
Authentication
How project credentials work: XOROX_PROJECT_ID, XOROX_TOKEN, and where to store them.
Project credentials
A coding agent connects to a project using a project credential — not your XOROX account login. Create one from the project's Credentials tab in the dashboard.
Creating a credential gives you two values:
| Value | Where it comes from |
|---|---|
XOROX_PROJECT_ID | The project's id, visible any time in its Credentials tab. |
XOROX_TOKEN | Generated once, when the credential is created. |
XOROX_TOKEN is shown exactly once, at creation time. There is no way to view it again later — if you lose it, create a new credential.
Storing credentials
Add both values to the .env file in the root of the project you're coding in:
XOROX_PROJECT_ID=your-project-id
XOROX_TOKEN=your-token- Don't commit
.env. Add it to.gitignoreif it isn't already ignored. - Values in
.envtake precedence; if a value is missing there, the agent falls back to your shell environment. - Neither value is ever written to a config file on disk by the agent itself — only you manage them, in your own
.env.
How it's used
Both the local runtime (for automatic Ruleset context) and the MCP server (for Specifications and Tasks) read XOROX_PROJECT_ID and XOROX_TOKEN from .env and send them to the XOROX backend as a bearer token, scoped to that one project.
Revoking and rotating
There's no in-place rotation. To replace a credential: create a new one, update .env with its token, then revoke the old credential from the Credentials tab. A revoked credential stops working immediately and can't be restored.
Multiple credentials
A project can have more than one credential — for example, one per teammate or machine — so you can revoke one without affecting the others. Each credential has its own name, shown in the Credentials list.
Advanced: custom API base URL
An optional XOROX_API_BASE_URL environment variable overrides the backend the agent talks to (defaults to https://api.xorox.eu). Most projects never need to set this.