Variables
Settings > Environment holds one table of variables and subscriptions. Choose Add variable and enterNAME=value pairs. You can paste a whole .env file into any name field, and known names autocomplete as you type. Adding a name that already exists replaces its value.
Values are encrypted on arrival. A secret is never shown again, only its last four characters, such as ••••7f2a, and a short secret shows none. A plain value, such as a URL, stays readable. Names starting with SPHYNX_ are reserved.
Known names
Sphynx picks these up on its own. You don’t name them anywhere.
A harness gets only its own key. Judge and sandbox keys stay on the server and never enter the agent’s sandbox. Without a sandbox key, trials run on Sphynx’s hosted account.
Subscriptions
Choose Add subscription to run a harness on a plan instead of a key.
Codex uses a ChatGPT subscription over
OPENAI_API_KEY when both are set. A ChatGPT subscription is not an OpenAI API key, so OpenAI judges still need OPENAI_API_KEY.
Your own variables
Any other name is yours. It reaches a run only when the variant’s profile names it:profile.json
From the terminal
set prompts for the value instead of taking it as an argument, since an argument ends up in shell history and the process list. In a script, pipe it in:
Judges and simulated people
A judge that names aharness runs on that harness’s key or subscription. A judge declared with provider: "openai" needs OPENAI_API_KEY.
A case that states a human needs a model to play them. openai, anthropic, google, xai, moonshotai, deepseek, groq and openrouter all serve the same chat-completions API, so the human runs on the first of their keys it finds. Provider judges call OpenAI’s responses API, which the others don’t serve, so a case scored by one needs OPENAI_API_KEY.
On a self-hosted deployment, OPENAI_API_KEY in the server and worker environment works as a fallback.
A missing judge key is not a startup error. The judge that needs it fails when a case reaches it, and names what was missing.
Keep keys out of eval definitions and fixtures. Runs read everything they need from Settings > Environment.