Default Settings for Kimi-CLI: A Complete Guide to Configuration Values
The default settings for kimi-cli include a web server port of 5494, 50,000-character tool output limits, 32,000 fallback tokens for LLM context budgeting, and telemetry enabled by default, all of which can be overridden via environment variables or TOML configuration files.
The MoonshotAI/kimi-cli repository defines its out-of-the-box behavior through a centralized configuration system located in src/kimi_cli/config.py. These defaults govern everything from logging verbosity to token safety margins, ensuring the CLI operates securely and efficiently without requiring immediate user configuration.
Core Configuration File Locations
Before examining specific values, it is essential to understand where kimi-cli expects to find its settings. According to src/kimi_cli/config.py, the tool uses the XDG Base Directory specification with a fallback to the home directory.
# From src/kimi_cli/config.py
DEFAULT_CONFIG_DIR: Final[Path] = Path(os.getenv("XDG_CONFIG_HOME", Path.home() / ".config")) / "kimi"
DEFAULT_CONFIG_FILE: Final[Path] = DEFAULT_CONFIG_DIR / "config.toml"
DEFAULT_SECRETS_FILE: Final[Path] = DEFAULT_CONFIG_DIR / "secrets.toml"
ENV_KIMI_CONFIG_DIR: Final[str] = "KIMI_CONFIG_DIR"
The KIMI_CONFIG_DIR environment variable overrides the default directory, allowing users to relocate their configuration to custom paths.
General Runtime Defaults
The Config class in src/kimi_cli/config.py defines the primary runtime behavior using Pydantic models with sensible fallbacks.
Logging and Telemetry
By default, kimi-cli operates with transparency and basic analytics:
log_level: Set to"INFO"by default, controlling console verbosity for debugging and operational feedback.telemetry: Enabled (True) by default, collecting anonymous usage data to improve the tool.
Web Interface Port
The default port for the FastAPI-based web server is defined consistently across the codebase:
default_port:5494(defined insrc/kimi_cli/config.pyand mirrored insrc/kimi_cli/web/app.pyasDEFAULT_PORT)
A separate visualization server uses port 5495 as defined in src/kimi_cli/vis/app.py.
LLM Token Budgeting Defaults
Token management is critical for preventing context window overflows. The defaults in src/kimi_cli/config.py and src/kimi_cli/llm.py provide conservative safety margins:
# From src/kimi_cli/config.py
unknown_context_completion_tokens: int = Field(default=32_000)
completion_token_safety_margin: int = Field(default=1_024)
unknown_context_completion_tokens:32_000tokens serve as the fallback budget when the underlying LLM provider does not report its context size.completion_token_safety_margin:1_024tokens are reserved as a buffer, subtracted from the model's maximum token limit to prevent truncation errors.
These values are duplicated in src/kimi_cli/llm.py as DEFAULT_UNKNOWN_CONTEXT_COMPLETION_TOKENS and DEFAULT_COMPLETION_TOKEN_SAFETY_MARGIN, and enforced within the core agent loop in src/kimi_cli/soul/kimisoul.py.
Execution Flow Limits
To prevent runaway agent behavior, kimi-cli implements hard limits on execution steps:
max_flow_moves:1_000(defined insrc/kimi_cli/config.pyandsrc/kimi_cli/soul/kimisoul.pyasDEFAULT_MAX_FLOW_MOVES)
This setting caps the number of tool invocations within a single agent flow, protecting against infinite loops.
Security and CORS Defaults
The web server implements strict security defaults in src/kimi_cli/web/auth.py:
DEFAULT_ALLOWED_ORIGIN_REGEX: Final[re.Pattern] = re.compile(
r"^https?://(localhost|127\.0\.1)(:\d+)?$"
)
This regular expression restricts Cross-Origin Resource Sharing (CORS) to localhost origins only (http://localhost, http://127.0.0.1), mitigating CSRF attacks when running the server locally.
Session API Path Depth
The session management API enforces directory traversal protection:
DEFAULT_MAX_PUBLIC_PATH_DEPTH:6(fromsrc/kimi_cli/web/api/sessions.py)
This limits how many path components can be exposed through the public API, preventing access to deeply nested system directories.
Tool Output Constraints
Tool outputs are truncated to prevent console flooding and token overflow, as defined in src/kimi_cli/tools/utils.py:
DEFAULT_MAX_CHARS:50_000characters (global output limit)DEFAULT_MAX_LINE_LENGTH:2_000characters (per-line limit)
The truncate_output() function applies the line-length limit first, then enforces the global character cap, appending an ellipsis (…) when truncation occurs.
Agent Specification Defaults
Kimi-cli uses YAML-based agent specifications with built-in fallbacks in src/kimi_cli/agentspec.py:
DEFAULT_AGENT_SPEC_VERSION:"1"DEFAULT_AGENT_FILE:src/kimi_cli/agents/default/agent.yamlOKABE_AGENT_FILE:src/kimi_cli/agents/okabe/agent.yaml(legacy compatibility)
When users do not specify a custom --agent-file, the system loads the default agent specification from the package directory.
LLM Provider Configuration
The abstraction layer in src/kimi_cli/llm.py defaults to OpenAI-compatible endpoints:
- Provider:
"openai" - Model:
"gpt-4o-mini" - Environment override:
KIMI_LLM_PROVIDERcan change the default provider without modifying configuration files.
Overriding Default Settings
Users can customize these defaults through multiple mechanisms. The configuration loader in src/kimi_cli/config.py uses the following precedence:
- Environment variables (e.g.,
KIMI_CONFIG_DIR,KIMI_LLM_PROVIDER) - Configuration file (
~/.config/kimi/config.tomlor$KIMI_CONFIG_DIR/config.toml) - Hard-coded defaults (as detailed above)
Example config.toml to override key defaults:
log_level = "DEBUG"
telemetry = false
default_port = 8080
max_flow_moves = 500
unknown_context_completion_tokens = 16_000
Summary
- Configuration files default to
~/.config/kimi/(or$XDG_CONFIG_HOME/kimi/), withKIMI_CONFIG_DIRavailable for relocation. - Web server defaults to port
5494with strict localhost-only CORS policies and a maximum public path depth of6. - Token budgeting uses a
32,000token fallback budget and a1,024token safety margin to prevent context overflow. - Tool outputs are limited to
50,000characters total and2,000characters per line. - Agent flows are capped at
1,000moves to prevent infinite execution loops. - LLM defaults target OpenAI's
gpt-4o-minibut can be overridden viaKIMI_LLM_PROVIDER.
Frequently Asked Questions
How do I change the default port for the kimi-cli web server?
The default port is 5494, defined in src/kimi_cli/config.py as default_port and in src/kimi_cli/web/app.py as DEFAULT_PORT. You can override this by setting default_port = 8080 in your config.toml file, or by passing the --port flag when running kimi server.
Where does kimi-cli store its configuration files by default?
According to src/kimi_cli/config.py, kimi-cli stores configuration in DEFAULT_CONFIG_DIR, which resolves to $XDG_CONFIG_HOME/kimi/ or ~/.config/kimi/ on most systems. The main configuration file is config.toml, and sensitive values belong in secrets.toml. You can relocate these by setting the KIMI_CONFIG_DIR environment variable.
What are the default token limits for LLM interactions in kimi-cli?
The defaults are defined in both src/kimi_cli/config.py and src/kimi_cli/llm.py. The unknown_context_completion_tokens default is 32,000, used when the model does not report its context size. Additionally, completion_token_safety_margin defaults to 1,024 tokens, which is subtracted from the model's maximum capacity to create a safety buffer against overflow.
Is telemetry enabled by default in kimi-cli?
Yes. The telemetry field in the Config class (src/kimi_cli/config.py) defaults to True, enabling anonymous usage collection. You can disable this by setting telemetry = false in your config.toml file.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →