# How to Configure derisk-proxy-aliyun.toml for Secure API Access in OpenRisk

> Secure your API access by configuring derisk-proxy-aliyun.toml. Learn how to set environment variables and start the server for OpenRisk.

- Repository: [derisk-ai/openderisk](https://github.com/derisk-ai/openderisk)
- Tags: how-to-guide
- Published: 2026-02-28

---

**To configure [`derisk-proxy-aliyun.toml`](https://github.com/derisk-ai/openderisk/blob/main/derisk-proxy-aliyun.toml) for API access, copy the template to `~/.openderisk/`, set the required environment variables (`DASHSCOPE_API_KEY_2`, `OSS_ACCESS_KEY_ID`, `OSS_ACCESS_KEY_SECRET`, and `ENCRYPT_KEY`), and start the server with the `--config` flag pointing to your configuration file.**

The [`derisk-proxy-aliyun.toml`](https://github.com/derisk-ai/openderisk/blob/main/derisk-proxy-aliyun.toml) file controls the OpenRisk server's integration with Alibaba Cloud services, including the DashScope LLM API and OSS object storage. According to the derisk-ai/openderisk source code, this TOML configuration uses environment variable substitution to keep sensitive credentials out of version control while maintaining runnable defaults.

## Understanding the Configuration Structure

The configuration file in [`configs/derisk-proxy-aliyun.toml`](https://github.com/derisk-ai/openderisk/blob/main/configs/derisk-proxy-aliyun.toml) contains several distinct sections that define system behavior, network settings, and cloud service authentication.

### System and Web Service Settings

The **`[system]`** section defines global server parameters:

- `language`: UI locale, defaulting to `zh` via `${env:DERISK_LANG:-zh}`
- `log_level`: Logging verbosity (e.g., `"INFO"`)
- `encrypt_key`: Secret key for data encryption, using `${ENCRYPT_KEY:-your_secret_key}` placeholder

The **`[service.web]`** section configures the HTTP endpoint:

- `host` and `port`: Bind address and port (defaults to `"0.0.0.0"` and `7777`)
- `web_url`: Public-facing URL supporting dynamic port substitution via `${env:WEB_SERVER_PORT:-7777}`

The **`[service.web.database]`** subsection specifies SQLite storage at `"pilot/meta_data/derisk.db"` for session persistence.

### LLM Provider Configuration

The **`[[agent.llm.provider]]`** array configures the Alibaba Cloud DashScope endpoint:

- `provider`: Set to `"openai"` for compatibility mode
- `api_base`: Fixed at `"https://dashscope.aliyuncs.com/compatible-mode/v1"`
- `api_key`: Authentication token via `${DASHSCOPE_API_KEY_2:-sk-...}`

The **`[[agent.llm.provider.model]]`** subsections list available model identifiers such as `deepseek-r1` and `qwen-plus`.

### Object Storage Service (OSS) Backend

The **`[[serves.backends]]`** section with `type = "oss"` configures file storage:

- `endpoint`: OSS URL (e.g., `"https://oss-cn-beijing.aliyuncs.com"`)
- `region`: Alibaba region identifier (e.g., `"oss-cn-beijing"`)
- `access_key_id` and `access_key_secret`: Credentials via `${env:OSS_ACCESS_KEY_ID:-xxx}` and `${env:OSS_ACCESS_KEY_SECRET:-xxx}`
- `fixed_bucket`: Default storage bucket (e.g., `"openderisk"`)

The **`[sandbox]`** section duplicates these OSS credentials for the isolated execution environment using the same substitution pattern.

## Environment Variable Substitution

Values wrapped in `${env:VAR_NAME:-default}` resolve at runtime according to the implementation in [`packages/derisk-app/src/derisk_app/app.py`](https://github.com/derisk-ai/openderisk/blob/main/packages/derisk-app/src/derisk_app/app.py). If the environment variable exists, the server uses its value; otherwise, it falls back to the literal default. This design pattern prevents accidental credential commits while allowing immediate execution with placeholder values.

## Step-by-Step Configuration

Follow these steps to prepare the derisk-proxy-aliyun.toml configuration for production use:

1. **Copy the template to your home directory:**

```bash
mkdir -p ~/.openderisk
cp configs/derisk-proxy-aliyun.toml ~/.openderisk/derisk-proxy-aliyun.toml

```

2. **Export required environment variables:**

```bash
export DASHSCOPE_API_KEY_2="sk-your-dashscope-api-key"
export OSS_ACCESS_KEY_ID="your-oss-access-key-id"
export OSS_ACCESS_KEY_SECRET="your-oss-access-key-secret"
export ENCRYPT_KEY="your-32-character-encryption-key"

```

3. **Start the server with the configuration path:**

```bash
uv run python packages/derisk-app/src/derisk_app/derisk_server.py \
    --config ~/.openderisk/derisk-proxy-aliyun.toml

```

The server loads the TOML from [`packages/derisk-app/src/derisk_app/app.py`](https://github.com/derisk-ai/openderisk/blob/main/packages/derisk-app/src/derisk_app/app.py), resolves the environment variables, and establishes connections to DashScope and OSS.

## Configuration Examples

### Using a .env File (Recommended)

Create `~/.openderisk/.env` to store credentials outside the TOML:

```dotenv
DASHSCOPE_API_KEY_2=sk-your-dashscope-key-here
OSS_ACCESS_KEY_ID=LTAI-your-access-key
OSS_ACCESS_KEY_SECRET=your-secret-key-here
ENCRYPT_KEY=super-secure-random-encryption-key

```

Load the variables before starting the server:

```bash
set -a && source ~/.openderisk/.env && set +a
uv run python packages/derisk-app/src/derisk_app/derisk_server.py \
    --config ~/.openderisk/derisk-proxy-aliyun.toml

```

### Hardcoding Credentials (Testing Only)

For local testing without environment variables, edit the TOML directly:

```toml
[[agent.llm.provider]]
provider = "openai"
api_base = "https://dashscope.aliyuncs.com/compatible-mode/v1"
api_key = "sk-your-dashscope-key"

[[serves.backends]]
type = "oss"
endpoint = "https://oss-cn-beijing.aliyuncs.com"
region = "oss-cn-beijing"
access_key_id = "your-oss-access-key-id"
access_key_secret = "your-oss-access-key-secret"
fixed_bucket = "openderisk"

```

**Warning:** Hardcoding credentials exposes secrets to anyone with file system access and increases the risk of accidental commits to version control.

### Verifying Configuration Loading

Use this Python snippet to verify environment substitution works correctly:

```python
from pathlib import Path
import toml
import os

# Ensure env vars are set

os.environ['DASHSCOPE_API_KEY_2'] = 'sk-test-key'

cfg_path = Path.home() / ".openderisk" / "derisk-proxy-aliyun.toml"
config = toml.load(cfg_path)

provider = config["agent"]["llm"]["provider"][0]
print(f"API Base: {provider['api_base']}")
print(f"API Key resolved: {provider['api_key'][:10]}...")

```

## Summary

- The **[`derisk-proxy-aliyun.toml`](https://github.com/derisk-ai/openderisk/blob/main/derisk-proxy-aliyun.toml)** file in `configs/` serves as the template for Alibaba Cloud API integration.
- **Environment variable substitution** using `${env:VAR:-default}` syntax keeps credentials secure and out of the repository.
- **Required variables** include `DASHSCOPE_API_KEY_2` for LLM access, `OSS_ACCESS_KEY_ID` and `OSS_ACCESS_KEY_SECRET` for storage, and `ENCRYPT_KEY` for data security.
- The server loads configuration via [`packages/derisk-app/src/derisk_app/app.py`](https://github.com/derisk-ai/openderisk/blob/main/packages/derisk-app/src/derisk_app/app.py) and starts with the `--config` flag pointing to your TOML file.

## Frequently Asked Questions

### Where is the default derisk-proxy-aliyun.toml template located?

The default template resides in [`configs/derisk-proxy-aliyun.toml`](https://github.com/derisk-ai/openderisk/blob/main/configs/derisk-proxy-aliyun.toml) at the repository root. The [`install.sh`](https://github.com/derisk-ai/openderisk/blob/main/install.sh) script references this file during setup, and the [`README.md`](https://github.com/derisk-ai/openderisk/blob/main/README.md) documentation directs users to copy it to `~/.openderisk/` for customization.

### Can I use hardcoded credentials instead of environment variables?

Yes, but only for local testing. Replace the `${env:VAR:-default}` placeholders with literal strings in the TOML file. However, this exposes secrets in plain text and risks accidental commits. Production deployments should always use environment variables or secret management systems.

### What should I use for the ENCRYPT_KEY value?

Set `ENCRYPT_KEY` to a strong, random string of at least 32 characters. This key encrypts sensitive data stored in the SQLite database. If the key changes after data is encrypted, the server cannot decrypt existing session data, requiring database reset.

### How do I verify that the configuration loaded correctly?

Check the server logs on startup for connection errors to `dashscope.aliyuncs.com` or OSS endpoints. You can also inspect the resolved configuration by examining the `config` object loaded in [`packages/derisk-app/src/derisk_app/app.py`](https://github.com/derisk-ai/openderisk/blob/main/packages/derisk-app/src/derisk_app/app.py), or use the Python verification snippet to confirm environment variables resolve correctly before starting the server.