# uip config

> Syntax and options for `uip config`, which reads, sets, and clears CLI configuration preferences stored in config.json.

`uip config` reads and writes the CLI's local configuration file — defaults like the output format, log level, and the version/update-channel policy that governs `uip update` and `uip tools update`. The file is discovered by walking up from the current directory to `$HOME` looking for `.uipath/config.json`, falling back to `~/.uipath/config.json` if none is found; `--config-file` overrides discovery for any verb.

## Synopsis

```
uip config get [key] [-c <path>]
uip config set <key> <value> [-c <path>]
uip config clear <key> [-c <path>]
```

All `uip config` verbs honor the [global options](./global-options.md) (`--output`, `--output-filter`, `--log-level`, `--log-file`). Exit codes follow the [standard contract](./exit-codes.md).

## Config keys

| Key | Valid values | Writable | Description |
|---|---|---|---|
| `output` | `table`, `json`, `yaml`, `plain`, `markdown` | yes | Default output format for CLI commands. |
| `logLevel` | `error`, `warn`, `info`, `debug` | yes | Default log level. |
| `interactive` | `never`, `auto`, `always` | yes | When the CLI may show interactive prompts. Defaults to `auto`. |
| `updateChannel` | `stable`, `preview` (`dev` is accepted but not advertised) | yes | Release channel used to resolve tool updates. |
| `version` | `major.minor` or `major.minor.patch` (e.g. `1.2` or `1.2.3`) | yes | Version policy: an exact `major.minor.patch` freezes auto-update entirely; a `major.minor` line tracks that line; unset follows the latest release. |
| `clientSecret` | — | **no** | External app client secret used by `uip login`. Read-only from `uip config` — set it via `uip login --client-secret env.NAME` so the secret stays in an environment variable and the auth file, never in `config.json`. |

Two older keys, `autoVersionSync` and `versionSource`, were removed when the version policy was collapsed into `version` + `updateChannel`. Running `uip config set autoVersionSync ...` or `versionSource ...` now fails with `Unknown config key`, and the error message steers you to the `version`/`updateChannel` equivalent.

## uip config get

Get one configuration value, or the full configuration when no key is given.

### Arguments

| Name | Required | Purpose |
|---|---|---|
| `[key]` | no | One of the config keys above. Omit to show the entire config file. |

### Options

- `-c, --config-file <path>` — path to a specific config file, overriding discovery.

### Examples

```bash
uip config get output
```

```bash
# Show everything
uip config get
```

### Data shape (--output json)

Single key:

```json
{
  "Code": "ConfigGet",
  "Data": { "Key": "output", "Value": "table" }
}
```

A key with no value set returns `Value: "-"`. `clientSecret` (and any other secret-bearing key) always returns `<redacted>`, never the real value.

No key — the full file, secrets redacted:

```json
{
  "Code": "ConfigList",
  "Data": {
    "Config": {
      "core": { "output": "table", "logLevel": "info", "updateChannel": "stable" },
      "auth": { "clientId": "client-abc", "clientSecret": "<redacted>" }
    }
  }
}
```

`ConfigGet` and `ConfigList` are distinct `Code` values so a JMESPath consumer sees one stable shape per `Code` rather than a `Data` field that changes shape depending on whether `key` was passed.

## uip config set

Set a configuration value.

### Arguments

| Name | Required | Purpose |
|---|---|---|
| `<key>` | yes | A writable config key (all of the keys above except `clientSecret`). |
| `<value>` | yes | The new value. Validated against the key's allowed values, when it has one. |

### Options

- `-c, --config-file <path>` — path to a specific config file, overriding discovery. The file is created if it doesn't exist.

### Examples

```bash
uip config set output table
```

```bash
uip config set updateChannel preview
```

```bash
# Pin the CLI and tools to the 1.196 line (float — tracks patch releases within it)
uip config set version 1.196

# Freeze on an exact patch (no auto-update at all)
uip config set version 1.196.3
```

### Data shape (--output json)

```json
{
  "Code": "ConfigSet",
  "Data": { "Key": "output", "Value": "table", "Status": "Updated" }
}
```

Attempting to set `clientSecret` fails with `ValidationError` pointing you to `uip login --client-secret env.NAME` instead. An invalid value for an enumerated key (for example `uip config set output csv`) fails with `ValidationError` and lists the valid values.

## uip config clear

Remove a configuration value. A no-op (not an error) if the key was never set.

### Arguments

| Name | Required | Purpose |
|---|---|---|
| `<key>` | yes | A writable config key. |

### Options

- `-c, --config-file <path>` — path to a specific config file, overriding discovery.

### Examples

```bash
# Un-pin the version so the CLI follows the latest release again
uip config clear version
```

```bash
# Clearing a key that was never set is a no-op
uip config clear updateChannel
```

### Data shape (--output json)

```json
{
  "Code": "ConfigClear",
  "Data": { "Key": "version", "Status": "Cleared" }
}
```

`Status` is `"Not set"` instead of `"Cleared"` when the key had no value to remove.

## Related

- [uip update](./uip-update.md) — `config get version` / `config set version` govern which line `uip update` and `uip tools update` resolve against.
- [uip tools](./uip-tools.md) — tool installs/updates read the same `version` and `updateChannel` keys.
- [uip login](./uip-login.md) — sets credentials outside `config.json`; `clientSecret` here is read-only for a reason.

## See also

- [Global options](./global-options.md)
- [Exit codes](./exit-codes.md)
