What it can do
Each row is backed by a skill, a reusable procedure for one Phoenix workflow that PXI loads on demand.
File GitHub issues. When PXI finds a real defect it can file an issue linking the relevant traces, through GitHub’s MCP server. Add a fine-grained token with Issues read/write under Settings → Assistant → Tools → GitHub, or set
githubPersonalAccessToken in ~/.px/settings.json for the terminal. Issues are filed as you, after approval.
Conversations
Chats are saved on the server, so a conversation survives a reload and is the same session in the panel or thepxi client. The panel header lists past chats to continue, rename, or delete; a temporary chat is never saved. On any message, Rewind drops it and everything after, and Branch forks a new chat from that point.
Retention is set under Settings → Assistant → Chats & data; see agent session retention. Sessions are also exposed under /v1/agent_sessions; see the Agent Sessions API.
The terminal client
The same server-side agent in your terminal, shipped with the Phoenix CLI. Credentials, skills, and permissions come from the server./ are handled locally: /help lists them, /compact summarizes earlier turns. See the CLI reference for every flag and command.
Configuration
Bring your own model
PXI runs on your model provider and your API key. Set credentials for Anthropic, OpenAI, Google, or AWS Bedrock through environment variables or Phoenix secrets, or add a custom provider under Settings → AI Providers.Permissions and approval
Agent assistance is opt-in.- Turn it off per deployment (
PHOENIX_DISABLE_AGENT_ASSISTANT=true), per instance (Settings → Assistant → Permissions), or per browser (Settings → Assistant → General). - State-changing actions wait for you. Saving a prompt, writing dataset examples, or submitting an evaluator arrives as a diff or card you accept. Read-only actions run freely. Bypass Approval applies edits without asking and shows a warning while active.
- Web access is per session, through the globe button in the chat input, and only when an administrator allows it.
Privacy and tracing
PXI runs inside your Phoenix process, on your data, with your model key. Arize is not in the request path.- Bash runs in a sandboxed shell on the server with no network.
PHOENIX_AGENTS_DISABLE_BASH=trueremoves it. - PXI sees whatever you can see, so be deliberate on sensitive data.
- Chats can be recorded as traces in the
assistant_agentproject. Off by default; administrators turn it on under Settings → Assistant. - PXI makes mistakes. Treat its output as suggestions.
Configuration reference
TheDISABLE and FORCE variables take true. The others take a URL, token, or name.

