Render Reference

Commands, customization, environment variables, and troubleshooting for the Render template.

The web service is agent-os and the database is agentos-db. Every command in scripts/render/ drives the Render API and needs RENDER_API_KEY in your environment or env file.

Manage

TaskCommand
Deploy code changesPush to your deploy branch. autoDeploy: true in render.yaml rebuilds automatically.
Re-run a build without a commit./scripts/render/redeploy.sh
Sync env variables./scripts/render/env-sync.sh (defaults to .env.production; pass .env to sync that instead)
Tail logsDashboard: agent-os → Logs
Tear down./scripts/render/down.sh (add --yes to skip the confirmation)

./scripts/render/down.sh --yes skips confirmation and deletes both the agent-os web service and the agentos-db Postgres database, including all database data.

Auto-deploy on merge

autoDeploy: true is on in render.yaml, so every push to your deploy branch triggers a build and deploy. Render builds the pushed branch; local uncommitted changes never deploy. ./scripts/render/env-sync.sh is still how you sync env changes.

Production auth

Token-Based Authorization is on by default. Production startup requires JWT_VERIFICATION_KEY or a readable JWKS file at the container path in JWT_JWKS_FILE; otherwise the process exits.

Token-Based Auth gives you three things:

  1. Protected AgentOS routes require a token. The operational and docs routes /, /health, /info, /docs, /redoc, /openapi.json, and /docs/oauth2-redirect remain public.
  2. Per-request identity. Middleware validates the token and exposes its user_id, optional session_id, scopes, and claims to the request.
  3. Scope-based permissions. Token scopes control access to AgentOS routes and resources.

The template already sets AuthorizationConfig(user_isolation=True). Authenticated non-admin REST access is scoped to the principal; local dev mode disables scope enforcement and is open when no credentials are configured. This does not scope Platform Manager’s direct database tools to that REST identity. See User Isolation for the boundaries and admin exceptions.

To disable JWT authentication, set authorization=False in app/main.py, remove JWT_VERIFICATION_KEY and JWT_JWKS_FILE from the Render service, and push. Use this only inside a private VPC behind another auth layer. authorization=False disables AgentOS scope enforcement, while configured JWT environment variables still enable JWT validation. MCP OAuth remains active when MCP_CONNECT_SECRET is set.

Customize

Format, validate, and run evals

Run evals against a dedicated local test platform with no concurrent writers. The starter’s cleanup hooks remove components and learning state created during a case; concurrent application writes can be removed too. The same prerequisite applies to scheduled evals. See eval setup and isolation.

The host scripts require uv. The setup script creates a Python 3.14 venv:

./scripts/venv_setup.sh
source .venv/bin/activate
TaskCommand
Format./scripts/format.sh
Lint and type-check./scripts/validate.sh
Run smoke evalspython -m evals --tag smoke

./scripts/mcp_check.sh runs inside the container, so it needs no venv.

Environment variables

VariableRequiredDefaultDescription
OPENAI_API_KEYYes-Models and embeddings. The Blueprint prompts for it at launch.
RENDER_API_KEYDeploy scripts-Drives the Render API in scripts/render/. The scripts read it from your environment or env file; env-sync.sh never pushes RENDER_* keys to the service.
RUNTIME_ENVNoprddev sets authorization=False, which disables AgentOS scope enforcement. Configured JWT environment variables still enable JWT validation. Compose sets dev locally; keep prd on Render.
JWT_VERIFICATION_KEYProduction-Public key from os.agno.com. Quote the value so the multi-line PEM parses as one variable.
JWT_JWKS_FILEProduction-Path inside the running container to a JWKS JSON file. The scripts set only this path. Commit and push the file into the image build context and let auto-deploy rebuild the service, or configure a platform mount and roll the service.
MCP_CONNECT_SECRETNogenerated by up.shOAuth consent secret (16+ chars) for connecting claude.ai and ChatGPT to /mcp. up.sh generates one on deploy and writes it to .env.production.
AGENTOS_MCP_SIGNING_KEYNogeneratedOptional high-entropy signing-key material (32+ chars) for OAuth tokens. Unset, a strong key is generated and persisted in the database. Rotating it invalidates outstanding tokens.
AGENTOS_URLNohttp://127.0.0.1:8000Scheduler base URL. up.sh sends the generated onrender.com URL when no value exists locally; use env-sync.sh to deliver a preconfigured or custom URL. Loopback reaches the app inside this container; set the public URL for hosted MCP OAuth and the template’s deployment check. When MCP_CONNECT_SECRET is set, OAuth metadata also derives its public origin from this URL.
ENABLE_DEPLOY_CHECKNoTrueDaily deployment-check cron.
EVALS_TAGNosmokeEval tag the run-evals workflow runs.
EVALS_CASE_TIMEOUT_SECONDSNo90Fallback timeout for cases without an explicit timeout.
EVALS_SUITE_TIMEOUT_SECONDSNoderived from selected casesSum of selected case timeouts plus 30 seconds per case, with a 60-second floor. A positive integer overrides this ceiling.
PARALLEL_API_KEYNo-WebSearch uses the Parallel SDK when set, keyless MCP otherwise.
SLACK_BOT_TOKENNo-Set with the signing secret to enable Slack.
SLACK_SIGNING_SECRETNo-Set with the bot token to enable Slack.
DB_HOST / DB_PORT / DB_USER / DB_PASS / DB_DATABASENomatches composePostgres connection. The Blueprint wires them from agentos-db.
DB_DRIVERNopostgresql+psycopgSQLAlchemy driver.
AGNO_DEBUGNoFalseVerbose Agno logs. Compose sets it for dev.
WAIT_FOR_DBNoFalseIf True, the entrypoint blocks on the database before starting. Compose and the Blueprint set it.

Troubleshooting