bytedance/deer-flow · error · ValueError

mem0 api_key_env must be a non-empty env var name

Error message

mem0 api_key_env must be a non-empty env var name

What it means

Raised by Mem0Config.from_backend_config when memory.backend_config.api_key_env is empty or whitespace-only after str() coercion. api_key_env names the environment variable that holds the mem0 API key (default MEM0_API_KEY) — the key value itself never appears in config.yaml. An empty name cannot resolve to anything, so it is rejected at parse time.

Source

Thrown at backend/packages/harness/deerflow/agents/memory/backends/mem0/config.py:111

            read_policy=str(failure_policy.get("read", "fail_open")),
            write_policy=str(failure_policy.get("write", "log_and_drop")),
        )
        if config.startup_policy not in _STARTUP_POLICIES:
            raise ValueError(f"mem0 startup_policy must be one of {sorted(_STARTUP_POLICIES)}")
        if config.read_policy not in _READ_POLICIES:
            raise ValueError(f"mem0 failure_policy.read must be one of {sorted(_READ_POLICIES)}")
        if config.write_policy not in _WRITE_POLICIES:
            raise ValueError(f"mem0 failure_policy.write must be one of {sorted(_WRITE_POLICIES)}")
        if not 1 <= config.top_k <= 1000:
            raise ValueError("mem0 top_k must be in [1, 1000]")
        if not 0.0 <= config.score_threshold <= 1.0:
            raise ValueError("mem0 score_threshold must be in [0, 1]")
        if config.max_injection_chars <= 0:
            raise ValueError("mem0 max_injection_chars must be positive")
        if config.timeout_seconds <= 0:
            raise ValueError("mem0 timeout_seconds must be positive")
        if not config.api_key_env.strip():
            raise ValueError("mem0 api_key_env must be a non-empty env var name")
        parsed_base_url = urlsplit(config.base_url)
        if parsed_base_url.scheme not in {"http", "https"} or not parsed_base_url.netloc:
            raise ValueError("mem0 base_url must be an absolute http:// or https:// URL")
        if parsed_base_url.scheme == "http" and not config.allow_insecure_http:
            raise ValueError("mem0 base_url must use https:// because it carries the API key; set allow_insecure_http: true only for trusted local development")
        return config

    def resolve_api_key(self) -> str:
        """Read the API key from the configured environment variable."""
        key = os.environ.get(self.api_key_env, "").strip()
        if not key:
            raise ValueError(f"mem0 API key missing: environment variable {self.api_key_env} is unset or empty")
        return key

View on GitHub (pinned to 1dd6ba1acb)

Solutions

  1. Set api_key_env to the real env var name, e.g. api_key_env: MEM0_API_KEY, and export that variable with the key value
  2. Or remove the api_key_env key entirely to use the default MEM0_API_KEY
  3. If config is templated, ensure the template variable for the env var name is set and non-empty

Example fix

# before (config.yaml)
memory:
  backend_config:
    api_key_env: "${MEM0_KEY_ENV_VAR}"   # unset template var -> empty string

# after
memory:
  backend_config:
    api_key_env: MEM0_API_KEY
Defensive patterns

Strategy: validation

Validate before calling

def api_key_env_ok(backend_config: dict) -> bool:
    return str((backend_config or {}).get("api_key_env", "MEM0_API_KEY")).strip() != ""

Type guard

def is_non_empty_env_name(v: object) -> bool:
    return isinstance(v, str) and v.strip() != ""

Prevention

When it happens

Trigger: api_key_env: "" or api_key_env: " " in backend_config; a templating step that renders the key name to an empty string; YAML key present with no value (null coerces to 'None' which passes this check but fails later at resolve_api_key).

Common situations: Env-driven config templating (Helm values, .env substitution) where the variable holding the env-var NAME is unset; deleting the value while leaving the key; misunderstanding the setting as the key itself and blanking it.

Related errors


AI-assisted analysis of bytedance/deer-flow@1dd6ba1acb (2026-08-14). Data as JSON: /api/errors/7dd5b3bb70f1a59c. Report an issue: GitHub.