localhost. When the thing you are changing runs on your machine, --local runs the eval there instead:
Reaching a local service
Variables in.env.local and .env beside the eval file are given to the case, so a verifier can reach a service you are already running:
.env.local wins over .env, and anything already set in your shell wins over both.
What is forwarded
Addresses, and nothing else. A variable is given to a case when its name ends inURL, URI, HOST, PORT, ENDPOINT, ORIGIN, or BASE, and its value is a plain http(s) address, a hostname, or a port.
Both halves matter. DATABASE_URL=postgres://user:password@host/db is named like an address but carries a password inside it, so it is withheld. A local sandbox is a shell on your machine, and a value handed to it reaches the agent’s context and the journal the run writes down.
An agent that needs a model key does not read one from your machine. When you have an API key set, the run leases the credential your organization already connected, for the one harness it names, expiring in fifteen minutes. It is held in memory and never written down, so nothing has to be kept locally.
Sandbox credentials are never leased: a local run opens no cloud sandbox. A lease is only issued for a run you started with --local and are executing yourself.
What a local run is
A local run with an API key set is recorded like any other: it appears in the dashboard with its journal, marked as having run on your machine. What it does not get is a baseline. Its results were produced somewhere nobody else can inspect, so they never become the bar a later run is measured against, and--fail-on regressed has nothing to compare. The exit code reflects the result, so CI can gate on it:
Requirements
The agent runs as you, on your machine, in a temporary workspace with its ownHOME. It is not a container: a case can read and write what you can. Run evals you wrote or trust.
Harnesses install into ~/.anpord/local and are reused, so the first local run of a harness is slower than the rest.