Skip to main content
Everything beyond the PXI quickstart: what each skill does, conversations, the terminal client, and how to configure and lock down the agent.

What it can do

Each row is backed by a skill, a reusable procedure for one Phoenix workflow that PXI loads on demand. File GitHub issues. When PXI finds a real defect it can file an issue linking the relevant traces, through GitHub’s MCP server. Add a fine-grained token with Issues read/write under Settings → Assistant → Tools → GitHub, or set githubPersonalAccessToken in ~/.px/settings.json for the terminal. Issues are filed as you, after approval.

Conversations

Chats are saved on the server, so a conversation survives a reload and is the same session in the panel or the pxi client. The panel header lists past chats to continue, rename, or delete; a temporary chat is never saved. On any message, Rewind drops it and everything after, and Branch forks a new chat from that point. Retention is set under Settings → Assistant → Chats & data; see agent session retention. Sessions are also exposed under /v1/agent_sessions; see the Agent Sessions API.

The terminal client

The same server-side agent in your terminal, shipped with the Phoenix CLI. Credentials, skills, and permissions come from the server.
Requires Phoenix 20.0.0 or newer and a configured model provider. Lines beginning with / are handled locally: /help lists them, /compact summarizes earlier turns. See the CLI reference for every flag and command.

Configuration

Bring your own model

PXI runs on your model provider and your API key. Set credentials for Anthropic, OpenAI, Google, or AWS Bedrock through environment variables or Phoenix secrets, or add a custom provider under Settings → AI Providers.

Permissions and approval

Agent assistance is opt-in.
  • Turn it off per deployment (PHOENIX_DISABLE_AGENT_ASSISTANT=true), per instance (Settings → Assistant → Permissions), or per browser (Settings → Assistant → General).
  • State-changing actions wait for you. Saving a prompt, writing dataset examples, or submitting an evaluator arrives as a diff or card you accept. Read-only actions run freely. Bypass Approval applies edits without asking and shows a warning while active.
  • Web access is per session, through the globe button in the chat input, and only when an administrator allows it.

Privacy and tracing

PXI runs inside your Phoenix process, on your data, with your model key. Arize is not in the request path.
  • Bash runs in a sandboxed shell on the server with no network. PHOENIX_AGENTS_DISABLE_BASH=true removes it.
  • PXI sees whatever you can see, so be deliberate on sensitive data.
  • Chats can be recorded as traces in the assistant_agent project. Off by default; administrators turn it on under Settings → Assistant.
  • PXI makes mistakes. Treat its output as suggestions.

Configuration reference

The DISABLE and FORCE variables take true. The others take a URL, token, or name.

Feedback

PXI is in beta. Open an issue or start a discussion on GitHub.