Where things are
Use these tables to find your token, your data and your settings. Paths marked with an asterisk come from reading Kernl's code and packaging, not from running it on that system.
Linux (deb, rpm and tarball)
| What | Where |
|---|---|
| Token command | kernl token |
| Token file | ~/.local/share/kernl/data/.kernel-auth-token |
| Data folder | ~/.local/share/kernl/data/ (database kernel.db) |
| Config file | ~/.config/kernl/.env |
| License file | ~/.config/kernl/license.jwt* (does not exist until you add a license) |
| Dashboard and MCP | http://localhost:3086 and http://localhost:3086/mcp |
| Logs | stdout only. With the service: journalctl --user -u kernl -f |
Notes:
- The
.envcreated by a .deb or .rpm has every line commented out, so nothing is active by default. The tarball does not create it. Make the file yourself if you need one. - The folder
~/.local/share/kernl/logs/stays empty on Linux. - With the tarball, the program is in
~/.local/opt/kernl. - Also in the data folder:
.kernel-encryption-key. Kernl encrypts stored secrets with it. Back it up.
macOS
All of this comes from the app's packaging, not from a test run.
| What | Where |
|---|---|
| Token command | /Applications/Kernl.app/Contents/MacOS/kernl token |
| Data folder | ~/Library/Application Support/Kernl/ |
| Token file | ~/Library/Application Support/Kernl/data/.kernel-auth-token |
| Config file | ~/Library/Application Support/Kernl/config/.env |
| License file | ~/.config/kernl/license.jwt |
| Dashboard and MCP | http://localhost:3086 and http://localhost:3086/mcp |
| Logs | ~/Library/Application Support/Kernl/logs/kernl.log |
Windows
All of this comes from the app's packaging, not from a test run.
| What | Where |
|---|---|
| Token command | start.bat token, run from the install folder (C:\Program Files\Kernl for the .msi) |
| Data folder | %LOCALAPPDATA%\Kernl\ |
| Token file | %LOCALAPPDATA%\Kernl\data\.kernel-auth-token |
| Config file | %APPDATA%\Kernl\.env |
| License file | %USERPROFILE%\.config\kernl\license.jwt |
| Dashboard and MCP | http://localhost:3086 and http://localhost:3086/mcp |
| Logs | %LOCALAPPDATA%\Kernl\logs\kernl.log |
Docker
| What | Where |
|---|---|
| Token command | docker compose exec kernel cat /app/data/.kernel-auth-token, from the Kernl folder |
| Data | inside the container at /app/data, in a Docker volume |
| Dashboard and MCP | http://localhost:3086 and http://localhost:3086/mcp, published on this computer only |
| Logs | docker compose logs -f kernel (the installer prints this command; not run by us) |
Ports and your own token
The dashboard and MCP share port 3086. To change it on Windows, set DASHBOARD_PORT=3088 in %APPDATA%\Kernl\.env.
To pin your own token instead of the generated one, set KERNEL_AUTH_TOKEN in the .env file. To keep Kernl off your network, see reachable from the LAN.