Configure Spectra Resolve
At any time after installing Spectra Resolve, you can access the application settings to configure connections, AI agents, and additional tools. To change these configuration options, select Settings at the bottom of the sidebar, or the File > Application settings menu option.
To configure scan settings, select a project or a repository (folder) in the sidebar. By default, all repositories in a project inherit the project settings, but you can override this for every individual repository.
Application settingsβ
The Settings page contains options to configure:
- Connections - for accessing ReversingLabs APIs
- Agents - for controlling the behavior and token usage of AI runtimes
- Tools - for CLI tools that Spectra Resolve requires or integrates with
Connectionsβ
On the Connections page, you can view currently configured connections, switch between them, remove or modify them, and add a new connection. The API usage quota is displayed for the active connection.
For every new or existing connection, you can configure the options listed in the following table.
| Option | Description |
|---|---|
| Connection name | Provide a custom name for the connection (e.g. default or production). Only letters, digits and underscore are allowed in connection names. |
| API token | Provide the token for your Spectra Assure Community or Portal account. The account type is automatically detected from the token prefix (rlcmm- for Community, rls3c- for Portal). If you don't have an account, use the link in the dialog to create a free Community account. Depending on the detected account type, other options may become available in the dialog. |
| Portal URL | Required only when connecting to the Portal. Name of the Spectra Assure Portal instance associated with your account (example: my.secure.software). |
| Organization | Required only when connecting to the Portal. Name of the Spectra Assure Portal organization. The organization must exist on the specified Portal URL. The user account authenticated with the token must be a member of the specified organization and have the appropriate permissions. Organization names are case-sensitive. |
| Group | Optional, applies only when connecting to the Portal. Name of the Spectra Assure Portal group. The group must exist in the specified Portal organization. Group names are case-sensitive. |
If needed, you can configure a proxy server, port, optional credentials, and a PEM CA bundle for TLS interception. Expand Proxy and CA certificates in the configuration dialog to access these settings.
Agentsβ
The Agents page displays information about token usage and activity for the currently selected runtime (AI agent and model), and lets you choose which runtime to use.
Each runtime can be enabled or disabled, and you can choose the preferred model as well as the model to use for approver actions.
| Runtime | How it works | Model choice |
|---|---|---|
| Codex CLI | Runs your installed codex CLI | Discovered live from the CLI's account |
| Claude Code | Runs your installed claude CLI | The stable aliases opus, sonnet, haiku, fable, or an exact dated model ID |
| Spectra Agent | Built-in harness that interacts with an OpenAI-compatible endpoint you configure | The model is part of the provider connection you select |
Claude Code supports an additional option to Install into CLIβ¦.
Selecting this option in the runtime menu installs the ReversingLabs agent definitions and skills from rl-protect-skills into the Claude Code CLI on your system.
Configure Spectra Agentβ
To use Spectra Agent, first select the Model providers option in the runtime menu to start the setup dialog. In the dialog, select Add provider, and enter required information in the following steps:
-
Endpoint - a display name and a base URL (for example
https://router.huggingface.co/v1orhttp://localhost:11434), and an API key for connecting to the endpoint. Select No API key needed for local gateways -
Model - detect the endpoint's models (OpenAI-compatible
/v1/modelsand Ollama/api/tagsare both recognised), or manually provide a model ID. Set the context window in tokens -
Advanced - configure temperature, maximum reply tokens, requests per minute (to stay inside the provider's rate limit), and whether to stream responses
Token use by stageβ
This section of the Agents page provides statistics on the token usage (total, per runtime, per stage) for the current month and year. Records are kept for 365 days, and you can reset them for each runtime by selecting Reset recorded usage in the runtime menu.
Toolsβ
The Tools page lists all supported command-line tools detected by Spectra Resolve and the location of their executable. Those paths are detected automatically. You can change them manually, but this should only be done when a tool is installed outside your system's configured PATH.
Scan settingsβ
Scan settings are inherited from global to projects, folders, and specific scan runs. This allows you to set a sensible default once, and override it only when needed.
The scanning profile decides which policies the scanner enforces. In addition to built-in profiles, you can create a custom profile that must comply with the rl-profile.json schema.
You can also edit a project's profile from inside the analysis report by selecting the gear icon at the top right. This opens the Scan profile dialog where you can manually choose the profile options or ask AI to help you. In the Threat model tab in the dialog, you can set a prompt for the AI agent to use during triage. The threat model describes the context in which the software you're analyzing is intended to be used, and how to handle different types of threats.
When you save changes to the profile, Resolve will apply the new profile to the plan without a full re-scan when that is sufficient.
You can commit the changes to the scan profile so other people on your team can reproduce the results. The same profile can be applied in CI/CD if you use the rl-protect GitHub Actions integration.