Configuration

nitpik is configured through a layered system — CLI flags, environment variables, config files, and built-in defaults. Each layer overrides the one below it.


Configuration Priority

From highest to lowest priority:

  1. CLI flags — always win
  2. Environment variables — override config files
  3. .nitpik.toml in repo root — project-level defaults
  4. ~/.config/nitpik/config.toml — global user defaults
  5. Built-in defaults — fallback values

Project Config (.nitpik.toml)

Drop this in your repository root to set defaults for your team:

[provider]
name = "anthropic"
model = "claude-sonnet-4-20250514"
# base_url = "https://custom-endpoint.example.com/v1"  # for openai-compatible

[review]
default_profiles = ["backend", "security"]
fail_on = "warning"

[review.agentic]
enabled = false
max_turns = 10
max_tool_calls = 10

[review.context]
max_file_lines = 1000
surrounding_lines = 100

[secrets]
enabled = false
severity = "warning"

[threats]
enabled = false

[telemetry]
enabled = true

Global Config (~/.config/nitpik/config.toml)

Same format as .nitpik.toml. Use this for personal defaults that apply across all repositories — like your preferred provider and model.

The project config overrides the global config, so teams can set project-level standards that take precedence over individual preferences.

Config Sections Reference

[provider]

KeyTypeDefaultDescription
namestring"anthropic"LLM provider. One of: anthropic, openai, gemini, cohere, deepseek, xai, groq, perplexity, openai-compatible.
modelstring(per-provider)Model identifier passed to the provider. If omitted, nitpik uses a sensible default for each provider.
base_urlstring(none)Custom API endpoint. Required for openai-compatible, optional for others.
api_keystring(none)API key. Prefer env vars over config files for secrets.

[review]

KeyTypeDefaultDescription
default_profilesarray["auto"]Profiles used when --profile is not specified on the CLI. The CLI default is auto (heuristic selection); set explicit names here to opt out.
fail_onstring"error"Fail-on severity threshold. One of: error, warning, info. nitpik exits non-zero if any finding meets this threshold. Use --no-fail on the CLI to disable.
audit_logstring(none)Path to write the per-run JSON audit log. When set, nitpik captures per-task status, tool calls, retries, token usage, critic decisions, and final findings. CLI flag --audit-log and env var NITPIK_AUDIT_LOG take precedence.

[review.agentic]

KeyTypeDefaultDescription
enabledboolfalseEnable agentic mode by default. Equivalent to always passing --agent.
max_turnsinteger10Max LLM round-trips per file×agent task. Higher values allow deeper exploration but increase cost.
max_tool_callsinteger10Max tool invocations per file×agent task. Caps total tool calls regardless of turns.

[review.context]

KeyTypeDefaultDescription
max_file_linesinteger1000Files with more lines than this get hunk excerpts instead of full content. Larger values give the LLM more context but increase token cost.
surrounding_linesinteger100Number of context lines around each diff hunk for large files. Only applies when the file exceeds max_file_lines.

[secrets]

KeyTypeDefaultDescription
enabledboolfalseEnable secret scanning by default. Equivalent to always passing --scan-secrets. Adds ~3-5s startup time.
severitystring"warning"Severity level for detected secrets. One of: error, warning, info. Set error to block merges; set info for legacy codebases. CLI flag: --secrets-severity.

[threats]

KeyTypeDefaultDescription
enabledboolfalseEnable threat scanning by default. Equivalent to always passing --scan-threats.
additional_rulesstring(none)Path to additional threat rules TOML file. Loaded alongside the 44 built-in rules.

[license]

KeyTypeDefaultDescription
keystring(none)Commercial license key. Set by nitpik license activate. Can also use NITPIK_LICENSE_KEY env var.

[telemetry]

KeyTypeDefaultDescription
enabledbooltrueEnable anonymous usage telemetry. Set false to disable. Can also use NITPIK_TELEMETRY=false env var or --no-telemetry flag.

Environment Variables

Provider & Model

VariableDescription
NITPIK_PROVIDERLLM provider name (overrides [provider].name)
NITPIK_MODELModel identifier (overrides [provider].model)
NITPIK_API_KEYUniversal API key fallback — used when no provider-specific key is set
NITPIK_BASE_URLCustom API endpoint (overrides [provider].base_url)

Provider-Specific API Keys

nitpik checks for a provider-specific key first, then falls back to NITPIK_API_KEY:

VariableProvider
ANTHROPIC_API_KEYAnthropic
OPENAI_API_KEYOpenAI and openai-compatible
GEMINI_API_KEYGoogle Gemini
COHERE_API_KEYCohere
DEEPSEEK_API_KEYDeepSeek
XAI_API_KEYxAI (Grok)
GROQ_API_KEYGroq
PERPLEXITY_API_KEYPerplexity

CI Platform Tokens

VariablePurpose
BITBUCKET_TOKENBitbucket access token for --format bitbucket (optional inside Bitbucket Pipelines)
FORGEJO_TOKENForgejo/Gitea API token for --format forgejo

Other

VariableDescription
NITPIK_LICENSE_KEYCommercial license key
NITPIK_TELEMETRYSet false to disable telemetry
NITPIK_AUDIT_LOGPath to write a per-run JSON audit log (equivalent to --audit-log)

Contact Us

Have a question or feedback? Send us a message and we'll get back to you.