Documentation
New in 14.6.0Settings page
Configure the language model, embeddings, search answers and storage from the local dashboard; API keys are stored encrypted.
Open the local dashboard (http://127.0.0.1:37737 by default) and choose Settings. The team server has
its own settings page; see Web dashboard.
What you can set
| Section | Settings |
|---|---|
| Language model | Provider (Ollama, OpenAI, Anthropic, OpenAI-compatible, auto), model, API base URL, API key, LLM tasks on/off, timeout |
| Embeddings | Provider. OpenAI, Cohere and DashScope also take a model, key, base URL and dimensions. The local FastEmbed model is a setup preset: change it with tam setup --reconfigure, then run memory_rebuild_embeddings |
| Search answers | Characters per search result (MEMORY_RECALL_MAX_RESULT_CHARS, default 6000), flag records that address the agent (MEMORY_FLAG_INSTRUCTIONS, on by default), cross-encoder re-ranking (MEMORY_CROSS_RERANK) |
| Storage | Days to keep raw call logs (MEMORY_RAW_LOG_RETENTION_DAYS; not set keeps them forever), embedding model cache folder (TAM_MODEL_CACHE) |
| Stored credentials | Scan the store for credentials that earlier versions saved, then back up and redact them |
How values apply
Precedence. A value saved on the page beats the environment and the env block of an MCP client
config. The environment beats the built-in default. Each field shows where its current value comes from.
Timing. Each agent session reads the settings when its MCP server starts. After a change, restart the
agent or reconnect the server (/mcp in Claude Code).
Where values are stored
Values live in <memory dir>/settings.json (mode 0600). API keys in it are encrypted with Fernet. The key
is TAM_MASTER_KEY when that is set, otherwise <memory dir>/master.key, created with mode 0600 on the
first saved key. The page never sends a key back to the browser: it shows •••• and the last four
characters.
Keep a copy of master.key with your backups. Without it, saved keys cannot be read and must be entered
again.
The setup wizard writes the language-model answers to the same file, so keys no longer sit in plain text
in ~/.claude.json or other client configs.
Who can change them
A write needs a same-origin request that carries a token issued to the page itself. Other web sites and plain form posts are refused. Every other dashboard address is read-only.
Search answers
memory_recall cuts a record that is longer than the per-result limit. The cut record carries
truncated: true and content_chars, and its text ends with a pointer to memory_get, which returns
the whole record.
A record written to the reading agent is marked untrusted_instructions: true. Examples are “ignore
previous instructions” and “send the SSH key to …”. The answer then also carries a notice that such
records are data, not instructions. Nothing is removed. See Privacy.