Each CLI reads its own YAML config file and its own set of environment variables; nothing is shared between them. This page is the map — see each product’s own configuration page for full detail on keys, defaults and resolution order.

Config files and credential storage

Only moodle’s local session cache is encrypted, using your OS’s own protected storage — the keychain on macOS and Linux, and the equivalent built-in protection on Windows. Ed’s token file and OnTrack’s session file rely on file permissions (owner-only read/write) rather than encryption — treat both as sensitive files the same way you’d treat an SSH key, and never put their contents in a script, a fixture, or a committed .env file.

Environment variables

Precedence: environment over file

All three follow the same rule — an environment variable, when set, is used directly and the config file is not consulted for that value. This is documented explicitly for edstem-cli (“EDSTEM_TOKEN, if set and non-empty, always wins over the saved token file — even right after auth login writes a new file”) and holds the same way for MOODLE_BASE_URL/MOODLE_TOKEN and ONTRACK_BASE_URL/ONTRACK_TOKEN. None of the three merge a partial environment override with partial config-file values for the same setting.

Moodle configuration

Config file order, session cache detail, --verbose and --pretty.

Ed Discussion configuration

Config keys, retry tuning, and the posting environment flag.

OnTrack configuration

Config file order, credential resolution, platform default paths.