Config files and credential storage
Only moodle’s local session cache is encrypted, using your OS’s own protected storage — the keychain on macOS and Linux, and the equivalent built-in protection on Windows. Ed’s token file and OnTrack’s session file rely on file permissions (owner-only read/write) rather than encryption — treat both as sensitive files the same way you’d treat an SSH key, and never put their contents in a script, a fixture, or a committed
.env file.
Environment variables
Precedence: environment over file
All three follow the same rule — an environment variable, when set, is used directly and the config file is not consulted for that value. This is documented explicitly foredstem-cli (“EDSTEM_TOKEN, if set and non-empty, always wins over the saved token file — even right after auth login writes a new file”) and holds the same way for MOODLE_BASE_URL/MOODLE_TOKEN and ONTRACK_BASE_URL/ONTRACK_TOKEN. None of the three merge a partial environment override with partial config-file values for the same setting.
Moodle configuration
Config file order, session cache detail,
--verbose and --pretty.Ed Discussion configuration
Config keys, retry tuning, and the posting environment flag.
OnTrack configuration
Config file order, credential resolution, platform default paths.