Skip to content

Configuration ​

Providers and clients use the same production API, https://api.hashiro.ai/api/. Configure one profile for your organization. Your token determines your identity, organization, license, and permissions; a profile name does not grant provider access.

Create the configuration file ​

Generate an API token in My Account in the Hashiro console. Create the following file:

SystemFile
macOS / Linux~/.config/galileo/config.toml
Windows%USERPROFILE%\.config\galileo\config.toml

On macOS or Linux:

bash
mkdir -p ~/.config/galileo
$EDITOR ~/.config/galileo/config.toml
chmod 600 ~/.config/galileo/config.toml

On Windows PowerShell:

powershell
New-Item -ItemType Directory -Force "$env:USERPROFILE\.config\galileo"
notepad "$env:USERPROFILE\.config\galileo\config.toml"

Paste this configuration and replace the token placeholder:

toml
current_project = ""
no_update = false
no_skills_update = true

[[profiles]]
name = "hashiro"
default = true
api_address = "https://api.hashiro.ai/api/"
api_key = "REPLACE_WITH_YOUR_API_TOKEN"

Field reference ​

FieldMeaning
current_projectDefault project identifier. Empty until you select a project.
no_updateSet to true to disable automatic binary updates. Default is false.
no_skills_updateSet to true to disable automatic refresh of installed Claude Code command files.
[[profiles]]A TOML array entry. Use this syntax even with one profile.
nameLocal label for the connection.
defaulttrue selects this profile by default.
api_addressAlways use https://api.hashiro.ai/api/. Galileo normalizes the API suffix.
api_keyAPI token generated by your user.
proxyOptional HTTP proxy URL. Omit when not needed.
default_projectOptional project identifier inside a profile; it seeds the current project when the profile loads.

Do not use [profiles.default], url, token, or current_program; those are not the current configuration format.

Provider and client access ​

A provider token can reach the provider's own data and linked clients where the endpoint permits it. A client token is confined to its own organization. Use the same API address for both. Project membership and project ownership still determine which operations are allowed.

Verify the connection ​

bash
galileo config profile list
galileo config profile default
galileo projects list

The profile list marks the default with *. Project listing is a read operation and shows only authorized projects.

Select a default project ​

bash
galileo projects default my-project
galileo projects default
galileo assets list
galileo assets list --project another-project
galileo projects default --unset

--project selects a project for a single command. Keep current_project at the top level if you want the default-project command to control it; a profile's default_project can seed it again when configuration loads.

Proxy ​

bash
galileo config proxy set http://127.0.0.1:8080
galileo config proxy unset

These commands modify the default profile. The proxy is optional and does not change the API instance or your access rights.

Configuration management ​

galileo config set ./config.toml copies an existing TOML file to the standard path. It is not a key/value setter. Create the standard file before the first invocation because Galileo loads configuration before executing commands.

With one profile, no profile switching is needed. If you later add another identity on the same instance, galileo config profile default NAME sets the default and --profile NAME overrides it for one invocation.

Updates and troubleshooting ​

Use galileo --no-update projects list to skip the automatic binary update for one invocation. galileo update explicitly checks for updates even when automatic updates are disabled.

ProblemCheck
No config file foundCreate the file at the system-specific path above.
TOML parsing errorUse [[profiles]], quote string values, and keep global settings before the profile.
Authentication failureReplace the placeholder with a valid token; a newly generated token invalidates the previous one.
Permission deniedCheck your role, license, project membership, and organization relationship.
Wrong projectPass --project explicitly or review the saved default.

The config file contains a credential. Keep it private and outside version control.

Hashiro. Continuous Threat Exposure Management.