Kernl

Where things are

Use these tables to find your token, your data and your settings. Paths marked with an asterisk come from reading Kernl's code and packaging, not from running it on that system.

Linux (deb, rpm and tarball)

What Where
Token command kernl token
Token file ~/.local/share/kernl/data/.kernel-auth-token
Data folder ~/.local/share/kernl/data/ (database kernel.db)
Config file ~/.config/kernl/.env
License file ~/.config/kernl/license.jwt* (does not exist until you add a license)
Dashboard and MCP http://localhost:3086 and http://localhost:3086/mcp
Logs stdout only. With the service: journalctl --user -u kernl -f

Notes:

  • The .env created by a .deb or .rpm has every line commented out, so nothing is active by default. The tarball does not create it. Make the file yourself if you need one.
  • The folder ~/.local/share/kernl/logs/ stays empty on Linux.
  • With the tarball, the program is in ~/.local/opt/kernl.
  • Also in the data folder: .kernel-encryption-key. Kernl encrypts stored secrets with it. Back it up.

macOS

All of this comes from the app's packaging, not from a test run.

What Where
Token command /Applications/Kernl.app/Contents/MacOS/kernl token
Data folder ~/Library/Application Support/Kernl/
Token file ~/Library/Application Support/Kernl/data/.kernel-auth-token
Config file ~/Library/Application Support/Kernl/config/.env
License file ~/.config/kernl/license.jwt
Dashboard and MCP http://localhost:3086 and http://localhost:3086/mcp
Logs ~/Library/Application Support/Kernl/logs/kernl.log

Windows

All of this comes from the app's packaging, not from a test run.

What Where
Token command start.bat token, run from the install folder (C:\Program Files\Kernl for the .msi)
Data folder %LOCALAPPDATA%\Kernl\
Token file %LOCALAPPDATA%\Kernl\data\.kernel-auth-token
Config file %APPDATA%\Kernl\.env
License file %USERPROFILE%\.config\kernl\license.jwt
Dashboard and MCP http://localhost:3086 and http://localhost:3086/mcp
Logs %LOCALAPPDATA%\Kernl\logs\kernl.log

Docker

What Where
Token command docker compose exec kernel cat /app/data/.kernel-auth-token, from the Kernl folder
Data inside the container at /app/data, in a Docker volume
Dashboard and MCP http://localhost:3086 and http://localhost:3086/mcp, published on this computer only
Logs docker compose logs -f kernel (the installer prints this command; not run by us)

Ports and your own token

The dashboard and MCP share port 3086. To change it on Windows, set DASHBOARD_PORT=3088 in %APPDATA%\Kernl\.env.

To pin your own token instead of the generated one, set KERNEL_AUTH_TOKEN in the .env file. To keep Kernl off your network, see reachable from the LAN.