The “Settings” window collects what can be changed without touching the server: the interface language, the font size, signing out, the leak report retention. It opens from the gear icon in the header — right away, without intermediate lists.
Appearance
The “General” group has an “Appearance” card: here the interface language (“English” or “Russian”) and the font size are chosen. Both choices apply at once and are saved, so they survive a page reload.
Theme
The theme is switched only by the button in the header — light or dark. The choice is saved and applied before the page renders, so there is no light-on-dark flash. If “follow the system” was chosen earlier, that choice keeps working, but there is no such switch in the “Settings” window any more.
Account
The “Account” group has a “Logout” card: it ends the session and returns you to the login form.
The license line
At the bottom of the window sits a quiet line with the license state (there is none elsewhere in the interface). Clicking it opens the “License Information” window: who it was issued to, the type, the scope, the validity term and the state. The line refreshes once a minute while the window is open, so a key whose term has passed stops being valid without reloading the page. The license itself is not entered here — it is set with an environment variable on the server. Exactly how — in the Licensing section.
The proxy service
The Settings window no longer manages the proxy service: it is configured on every channel separately — in the “HTTP proxies” section, in the “Inbound listener” block. Where to set the port and how to enable key sign-in — in the Tunnel Service section.
Secret hiding and reports
The secret-hiding master switch and the leak report retention (90 days by default) also live here. The switch itself is off by default — that is described in the Anonymization section.
Service buttons
- Test connection — checks whether the service answers and whether external addresses are reachable.
- Backfill ClickHouse Stats — re-sends the missed days, when statistics are delivered to an external store. The button appears only when that store is configured.
What applies at once, and what after a restart
- At once, or nearly so — the language, the font size, the secret-hiding settings, and a channel’s sign-in conditions and port: the listener applies changes in about 15 seconds, and editing the configuration file in about 300 ms. Editing the
.envfile also applies on the fly, but only for variables that are read at use time: secret references, the management key, the administrator sign-in and external programs. - Only after restarting the container — the chat connection to an external Xedant Agent, the ClickHouse address, the license, the configuration folder and the data folder. These values are read once at startup, from the environment or from the
.envfile — there is no difference.
Where the settings live
Settings from the interface are stored not in the database but in the settings.yml file in the configuration folder (by default /project/apps/proxy). The model, channel, access key and secret-hiding rule files sit next to it. It is the single source of truth: you can edit the file, the interface, or through management over the API — the result is the same.
Hand edits are picked up in about 300 ms, no restart needed. The folder is convenient to keep under version control: moving it to another server moves the whole configuration. And secret fields can be written as an environment-variable reference like $VARIABLE_NAME — then the secret itself never lies in the file.
Secrets are conveniently kept in one .env file next to the project (by default /project/.env; the path is changed with the PROXYAGENT_ENV_FILE variable): the product mixes it into the environment at startup and re-reads it on the fly, while the configuration files keep only the $VARIABLE_NAME references. The file belongs in the version-control ignore list — it holds secrets.
More about that — in the File Configuration section.
The administrator password
The administrator password is changed not in the interface but with environment variables on the server. The reason is simple: it is stored not as text but as its irreversible hash (SHA-256, written lowercase), and there is nowhere to paste it in the interface. The built-in generator in the login form produces the ready string — type the password you want, copy the hash and put it into the environment variable.
The variables are read on every sign-in, so the login and password can be changed without restarting the container.
Next: what the AI agent chat inside the product gives you — in the Chat with the AI Agent section.