> For the complete documentation index, see [llms.txt](https://gotts.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://gotts.gitbook.io/docs/gotts-vaults/vault/11-config.md).

# Configuration

> **Part of**: [Vault PRD](/docs/gotts-vaults/vault.md) | **Last Updated**: 2026-02-13

***

## Configuration

### Wallet Provider Variables

| Variable           | Required           | Default | Description                                                                                           |
| ------------------ | ------------------ | ------- | ----------------------------------------------------------------------------------------------------- |
| `WALLET_PROVIDER`  | No                 | `privy` | Wallet provider: `privy`, `local`                                                                     |
| `PRIVY_APP_ID`     | If Privy           | -       | Privy application ID                                                                                  |
| `PRIVY_APP_SECRET` | If Privy           | -       | Privy application secret                                                                              |
| `AGENT_ID`         | After registration | -       | ERC-8004 agent ID (set after Step 2 of [00-quickstart.md](/docs/gotts-vaults/vault/00-quickstart.md)) |
| `AGENT_HANDLE`     | No                 | -       | Human-readable agent handle                                                                           |

For wallet architecture details and provider selection guidance, see [03-custody.md](/docs/gotts-vaults/vault/03-custody.md).

### Protocol Variables

| Variable                          | Required | Default                                      | Description                                                                                                                                                                                                                                                                                          |
| --------------------------------- | -------- | -------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `GOTTS_UNISWAP_API_KEY`           | No       | -                                            | Uniswap Trading API key. When set, vault rebalancing and LP operations use the Trading API for optimized routing and execution. When not set, uses direct SDK/contract calls. See [mcp-server/11-config.md](/docs/gotts-safe-mcp-server/mcp-server/11-config.md) for full API configuration options. |
| `VAULT_FACTORY_ADDRESS`           | Yes      | -                                            | Deployed AgentVaultFactory contract address                                                                                                                                                                                                                                                          |
| `VAULT_CHAIN`                     | No       | `base`                                       | Primary chain for vault operations                                                                                                                                                                                                                                                                   |
| `IDENTITY_REGISTRY`               | No       | `0x8004A818BFB912233c491871b3d84c89A494BD9e` | ERC-8004 Identity Registry (Ethereum mainnet)                                                                                                                                                                                                                                                        |
| `REPUTATION_REGISTRY`             | No       | `0x8004B663056A597Dffe9eCcC1965A193B7388713` | ERC-8004 Reputation Registry (Ethereum mainnet)                                                                                                                                                                                                                                                      |
| `VAULT_TRUSTED_REVIEWERS`         | No       | `[]`                                         | Comma-separated reviewer addresses for reputation                                                                                                                                                                                                                                                    |
| `VAULT_MAX_DRAWDOWN_BPS`          | No       | `1000`                                       | Default circuit breaker threshold (1000 = 10%)                                                                                                                                                                                                                                                       |
| `VAULT_MAX_REBALANCE_PCT`         | No       | `20`                                         | Default max % of vault assets per rebalance                                                                                                                                                                                                                                                          |
| `VAULT_REBALANCE_INTERVAL`        | No       | `3600`                                       | Minimum seconds between rebalances                                                                                                                                                                                                                                                                   |
| `VAULT_MAX_CCA_EXPOSURE_PCT`      | No       | `50`                                         | Default max % of AUM in CCA positions                                                                                                                                                                                                                                                                |
| `VAULT_MAX_SINGLE_AUCTION_PCT`    | No       | `20`                                         | Default max % of AUM per single CCA auction                                                                                                                                                                                                                                                          |
| `VAULT_MAX_CONCURRENT_AUCTIONS`   | No       | `5`                                          | Default max concurrent CCA auctions                                                                                                                                                                                                                                                                  |
| `VAULT_RESERVE_RATIO_PCT`         | No       | `10`                                         | Default min % idle capital for withdrawals                                                                                                                                                                                                                                                           |
| `VAULT_PARAMETER_TIMELOCK`        | No       | `172800`                                     | Default timelock for parameter changes (48h)                                                                                                                                                                                                                                                         |
| `VAULT_X402_ENABLED`              | No       | `true`                                       | Enable x402 strategy gating                                                                                                                                                                                                                                                                          |
| `VAULT_X402_TREASURY`             | No       | (factory address)                            | x402 payment recipient address                                                                                                                                                                                                                                                                       |
| `PROXY_ENFORCEMENT_ENABLED`       | No       | `true`                                       | Enable role-based proxy enforcement checks                                                                                                                                                                                                                                                           |
| `PROXY_REQUIRED_ROLES`            | No       | `manager,creator,admin`                      | Comma-separated roles that must use proxy for writes                                                                                                                                                                                                                                                 |
| `PROXY_STANDARD_THRESHOLD_USD`    | No       | `10000`                                      | Participant write threshold above which proxy is required                                                                                                                                                                                                                                            |
| `PROXY_FAIL_MODE_REQUIRED`        | No       | `fail_closed`                                | Behavior for required-proxy routes when monitor/cancel is unhealthy (`fail_closed` or `fail_open`)                                                                                                                                                                                                   |
| `PROXY_FAIL_MODE_OPTIONAL`        | No       | `fail_open`                                  | Behavior for optional-proxy routes (`fail_open` or `fail_closed`)                                                                                                                                                                                                                                    |
| `PROXY_MONITOR_MAX_HEARTBEAT_SEC` | No       | `90`                                         | Max allowed monitor heartbeat age before required routes are blocked                                                                                                                                                                                                                                 |
| `PROXY_CANCEL_KEY_PROVIDER`       | No       | `kms`                                        | Cancel authority key provider (`kms`, `hsm`, `local-dev`)                                                                                                                                                                                                                                            |
| `VAULT_TRANSPORT`                 | No       | `stdio`                                      | Transport type: `stdio`, `http`, or `websocket`                                                                                                                                                                                                                                                      |
| `VAULT_HTTP_PORT`                 | No       | `8080`                                       | HTTP+SSE transport port                                                                                                                                                                                                                                                                              |
| `VAULT_WS_PORT`                   | No       | `8081`                                       | WebSocket transport port                                                                                                                                                                                                                                                                             |
| `LOCAL_TESTNET`                   | No       | `false`                                      | If true, connect to Anvil on localhost:8545                                                                                                                                                                                                                                                          |
| `ANVIL_FORK_BLOCK`                | No       | `latest`                                     | Block number for Anvil fork                                                                                                                                                                                                                                                                          |

Production policy: `PROXY_CANCEL_KEY_PROVIDER` must be `kms` or `hsm`. `local-dev` is only valid for local and CI test environments.

### Memory & Self-Improvement Variables

These variables are active when `TOOL_PROFILE=vault,learning`. They override the base memory configuration from [mcp-server/11-config.md](/docs/gotts-safe-mcp-server/mcp-server/11-config.md) with vault-specific thresholds.

| Variable                                | Required | Default | Description                                                                                                             |
| --------------------------------------- | -------- | ------- | ----------------------------------------------------------------------------------------------------------------------- |
| `VAULT_MEMORY_ENABLED`                  | No       | `true`  | Enable DeFi Brain memory for vault operations. Inherits from `GOTTS_MEMORY_ENABLED` if not set.                         |
| `VAULT_MEMORY_REBALANCE_MIN_CONFIDENCE` | No       | `0.7`   | Minimum insight confidence for `vault_rebalance` memory augmentation. Higher than default (0.5) due to capital-at-risk. |
| `VAULT_MEMORY_EMERGENCY_MIN_CONFIDENCE` | No       | `0.9`   | Minimum insight confidence for `vault_emergency_exit` memory augmentation. Near-certain insights only.                  |

### Config Schema

```typescript
interface VaultConfig {
  wallet: {
    provider: "privy" | "local";
    privy?: {
      appId: string;
      appSecret: string;
    };
    agentId?: string; // ERC-8004 agent ID (set after registration)
    agentHandle?: string; // Human-readable handle
  };
  factory: {
    address: Address;
    chain: ChainId;
  };
  identity: {
    registryAddress: Address; // ERC-8004 Identity Registry
    reputationAddress: Address; // ERC-8004 Reputation Registry
    trustedReviewers: Address[];
  };
  defaults: {
    // These are defaults for new vaults; each vault can override
    tierLimits: Record<
      AgentTrustTier,
      {
        maxDepositUsd: number;
        maxRebalancesPerDay: number;
        maxDailyAggregateUsd: number;
        maxOpsPerHour: number;
      }
    >;
    circuitBreaker: {
      maxDrawdownBps: number; // default: 1000 (10%)
      maxPositionILBps: number; // default: 2500 (25%)
      maxUtilizationPct: number; // default: 95
    };
    rebalance: {
      minIntervalSeconds: number; // default: 3600
      maxSizePct: number; // default: 20
    };
    cca: {
      maxTotalExposurePct: number; // default: 50
      maxSingleAuctionPct: number; // default: 20
      maxConcurrentAuctions: number; // default: 5
    };
    withdrawal: {
      reserveRatioPct: number; // default: 10
      maxQueueDuration: number; // default: 604800 (7 days)
    };
    parameterTimelock: number; // default: 172800 (48h)
  };
  x402: {
    enabled: boolean;
    treasury: Address;
    pricing: Record<string, string>;
  };
  proxy: {
    enforcementEnabled: boolean;
    requiredRoles: ("manager" | "creator" | "admin")[];
    standardThresholdUsd: number;
    failModeRequired: "fail_closed" | "fail_open";
    failModeOptional: "fail_closed" | "fail_open";
    monitorMaxHeartbeatSec: number;
    cancelKeyProvider: "kms" | "hsm" | "local-dev";
  };
  server: {
    transport: "stdio" | "http" | "websocket";
    httpPort: number;
    wsPort: number;
  };
  testnet: {
    enabled: boolean;
    rpcUrl: string;
    forkBlock: number | "latest";
  };
  memory?: {
    enabled?: boolean; // Default: true (when learning profile active)
    rebalanceMinConfidence?: number; // Default: 0.7
    emergencyMinConfidence?: number; // Default: 0.9
    // Inherits all other memory config from GottsSafeConfig.memory
  };
}

type AgentTrustTier =
  | "unverified"
  | "basic"
  | "verified"
  | "trusted"
  | "sovereign";
```
