You only need the basics that connect the local host to the runtime and a repo path where you want the guardrails installed.
- A `MANDATE_OS_BASE_URL`
- A `MANDATE_OS_AGENT_TOKEN`
- A repo path for the workspace you want to guard
- One host: Codex, Cursor, Claude Code, or OpenClaw
- Optional: `MANDATE_OS_MCP_DEFAULT_MANDATE_ID`