# Project Settings: Environments and Auth

> Set base URLs per environment, authentication profiles, default headers, change detection, and AI generation options — the settings that make a project run.

Source: https://totalshiftleft.ai/help-center/product-documentation/project-settings

## Overview

**Project Settings** is where you make a project's tests actually runnable. A project with imported endpoints but no base URL and no credentials can't reach your API — this page is what closes that gap.

Settings here apply to the whole project. For system-wide configuration, see [Administration settings](/help-center/product-documentation/administration-settings).

Save with **Save Project Settings**.

## Project details

| Field | What it does |
|-------|--------------|
| **Project Name** | The project's display name. |
| **Description** | A short summary of purpose and scope. |
| **Build Number** | A version marker for the project, for example `1.0.0`. Useful for tying a run to a release. |

## Base URLs by Environment

**Base URLs by Environment** is the setting most likely to be blocking you if nothing runs.

Each environment gets its own base URL — the host every request in that environment is sent to. An environment with no base URL shows **No base URL configured**, and tests in it can't execute.

To add an environment, use **Add Environment** and give it a name. The placeholder suggests the shape: `SIT`, `UAT`, `Pre-Prod`. The base URL itself is optional at creation time, so it's easy to add an environment and forget the URL — check for **No base URL configured** if a new environment isn't working.

Environments you no longer use can be removed, and **Show archived** reveals ones already archived so you can **Restore environment** if you removed one you still needed. Note that an environment in use may refuse deletion rather than silently breaking whatever depends on it.

## Project Authentication Profiles

**Project Authentication Profiles** hold the credentials tests use to authenticate against your API.

Create a profile per credential set you need, and bind it at the level that matches how your API works — if dev and production take different keys, that's a profile per environment rather than one shared profile.

Verify a profile by running a single test against a known-good endpoint before generating a suite on top of it. An auth profile that's subtly wrong produces a wall of failures that look like API bugs.

See also [Test config](/help-center/product-documentation/test-config) and [Secret managers](/help-center/product-documentation/secret-managers) for pulling credentials from HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault on Enterprise.

## Default headers

Headers defined here are shared across the project's requests, so you set things like `X-API-Version` once rather than on every test. Each entry is a **Header Name** and **Header Value** pair.

## Data for Running Tests

**Data for Running Tests** is where the project's supporting inputs live — the data files and sources that data-driven tests read from.

See [Data-driven testing](/help-center/product-documentation/data-driven-testing), [Data sources](/help-center/product-documentation/data-sources), and [Test data and generation setup](/help-center/product-documentation/test-data-and-generation-setup).

## Change detection

**Enable Change Detection** watches for changes to your API specification and reports what moved — added endpoints, modified request/response models, removed operations.

**Auto-approve non-breaking changes** lets additive changes through without review, so you're only interrupted for changes that could actually break a test. Leave it off if you'd rather see everything.

**Add Monitored URL** registers a spec URL to watch, and **Remove Monitored URL** stops watching one. Monitoring a URL your service publishes is what makes detection automatic rather than something you remember to run.

See [API change detection](/help-center/product-documentation/api-change-detection).

## AI Generation Settings

Project-level controls for AI test generation, overriding the system defaults in [AI settings](/help-center/product-documentation/ai-settings).

| Field | Range | Notes |
|-------|-------|-------|
| **AI test generation timeout (seconds)** | 60–600 | Project-level override. Default is **180**. Raise it if generation on large endpoints times out. |

For what gets generated rather than how long it may take, see [Test generation settings](/help-center/product-documentation/test-generation-settings).

## Deleting a project

**Delete Project** removes the project and its contents. Export anything you need first — this isn't a soft delete, and it takes the endpoints, tests, and history with it.

Restrict this to project owners and administrators. See [Role permissions](/help-center/product-documentation/role-permissions).

## Troubleshooting

- **Tests fail immediately with a connection error** — check **Base URLs by Environment** for the environment you're running in. **No base URL configured** means requests have nowhere to go.
- **Everything fails with 401/403** — the authentication profile is missing, bound to the wrong environment, or holding a stale credential. Verify it against one endpoint before assuming the API is broken.
- **A new environment doesn't work** — the base URL is optional when adding an environment, so it's commonly just missing.
- **An environment won't delete** — something still references it. The dialog names the blocker.
- **You deleted an environment you needed** — turn on **Show archived** and use **Restore environment**.
- **AI generation times out on big endpoints** — raise **AI test generation timeout (seconds)** toward 600.

## Best practices

- Set base URLs and authentication *before* generating tests. Generating against a project that can't connect produces a suite you then have to re-validate.
- Keep one environment per real deployment target, named the way your team already names them.
- Put shared headers in **Default headers** rather than repeating them per test.
- Turn on **Auto-approve non-breaking changes** once you trust detection — otherwise additive spec changes create review noise.

## Related articles

- [Project](/help-center/product-documentation/project)
- [Project operations](/help-center/product-documentation/project-operations)
- [Managing projects](/help-center/product-documentation/managing-projects)
- [Test config](/help-center/product-documentation/test-config)
- [Role permissions](/help-center/product-documentation/role-permissions)
- [Authentication Profiles: Choose and Configure a Method](/help-center/product-documentation/authentication-profiles-and-methods)
- [OAuth 2.0 Sign-In: Browser and Device Code](/help-center/product-documentation/oauth-2-interactive-sign-in)
- [Sign In With Steps](/help-center/product-documentation/sign-in-with-steps)

