Scenario | Recommended Method | How to Obtain Credentials |
Individual developer | CODEBUDDY_API_KEY | |
Enterprise/team (OAuth integration) | apiKeyHelper | |
Existing OAuth token in CI/CD. | CODEBUDDY_AUTH_TOKEN | Use the existing token directly. |
Third-party model service | CODEBUDDY_API_KEY + BASE_URL | Obtain from the third-party service provider. |
Version | Obtaining the Address |
Overseas Edition | |
China Edition |
CODEBUDDY_INTERNET_ENVIRONMENT environment variable!export CODEBUDDY_API_KEY="your-api-key"# No need to set CODEBUDDY_INTERNET_ENVIRONMENT for the overseas edition (default value)
export CODEBUDDY_API_KEY="your-api-key"export CODEBUDDY_INTERNET_ENVIRONMENT=internal
export CODEBUDDY_API_KEY="your-api-key"export CODEBUDDY_INTERNET_ENVIRONMENT=cloudhosted
export CODEBUDDY_API_KEY="your-api-key"export CODEBUDDY_INTERNET_ENVIRONMENT=selfhosted
Version | CODEBUDDY_INTERNET_ENVIRONMENT Value | Description |
Overseas Edition | Not set | Default value. Connects to overseas services. |
China Edition | internal | Connects to services in the China region. |
Dedicated Edition | cloudhosted | Connects to enterprise instances managed by Tencent Ops. |
Private Deployment | selfhosted | Connects to customer self-built enterprise services. |
https://your-company.copilot.qq.com). Setting only the environment variable is not sufficient to direct requests to the enterprise service. When using the CLI, enter the address in "Enterprise Domain Configuration" during the login process, and it will be automatically written to settings.json. When using an API Key, configure it manually. For details, see CODEBUDDY_API_KEY. When using the SDK, pass it through options.endpoint.~/.bashrc, ~/.zshrc, or your shell configuration file to avoid setting them manually each time.# Add to ~/.zshrc or ~/.bashrcecho 'export CODEBUDDY_API_KEY="your-api-key"' >> ~/.zshrcecho 'export CODEBUDDY_INTERNET_ENVIRONMENT=internal' >> ~/.zshrc # China editionsource ~/.zshrc
codebuddy
#!/bin/bash# get-oauth-token.sh - OAuth 2.0 Client Credentials flowCLIENT_ID="${OAUTH_CLIENT_ID}"CLIENT_SECRET="${OAUTH_CLIENT_SECRET}"TOKEN_URL="https://copilot.tencent.com/oauth2/token"response=$(curl -s -X POST "$TOKEN_URL" \\-H "Content-Type: application/x-www-form-urlencoded" \\-d "grant_type=client_credentials" \\-d "client_id=$CLIENT_ID" \\-d "client_secret=$CLIENT_SECRET")echo "$response" | jq -r '.access_token'
~/.codebuddy/settings.json or the project .codebuddy/settings.json:{"apiKeyHelper": "/path/to/get-oauth-token.sh"}
codebuddy command.CODEBUDDY_CODE_API_KEY_HELPER_TTL_MS environment variable (in milliseconds).CODEBUDDY_INTERNET_ENVIRONMENT environment variable because requests are sent directly to the third-party service endpoint.export CODEBUDDY_API_KEY="sk-or-v1-xxx"export CODEBUDDY_BASE_URL="https://openrouter.ai/api/v1"codebuddy --model openai/gpt-4
Feature | Description |
Environment Variable | CODEBUDDY_API_KEY |
Authentication Type | API Key (X-Api-Key request header) |
Scenario | Personal development, third-party model services |
CODEBUDDY_INTERNET_ENVIRONMENT environment variable.Version | Value |
Overseas Edition | Not set (default) |
China Edition | internal |
iOA Edition | ioa |
Dedicated Edition | cloudhosted |
Private Deployment | selfhosted |
# Overseas Editionexport CODEBUDDY_API_KEY="your-api-key"# China Editionexport CODEBUDDY_API_KEY="your-api-key"export CODEBUDDY_INTERNET_ENVIRONMENT=internal# iOA Editionexport CODEBUDDY_API_KEY="your-api-key"export CODEBUDDY_INTERNET_ENVIRONMENT=ioa# Dedicated Edition (The service address is customized by the enterprise and must also be configured in settings.json. See the instructions below.)export CODEBUDDY_API_KEY="your-api-key"export CODEBUDDY_INTERNET_ENVIRONMENT=cloudhosted# Private Deployment (The service address is customized by the enterprise and must also be configured in settings.json. See the instructions below.)export CODEBUDDY_API_KEY="your-api-key"export CODEBUDDY_INTERNET_ENVIRONMENT=selfhosted
settings.jsonCODEBUDDY_INTERNET_ENVIRONMENT variable is not sufficient to direct requests to the enterprise service. You must also add the configuration in ~/.codebuddy/settings.json:{"endpoint": "https://your-company.copilot.qq.com"}
Feature | Description |
Environment Variable | CODEBUDDY_AUTH_TOKEN |
Authentication Type | Bearer Token (Authorization request header) |
Scenario | CI/CD automation and existing OAuth token |
export CODEBUDDY_AUTH_TOKEN="eyJhbGciOiJSUzI1NiIs..."
{"env": {"CODEBUDDY_AUTH_TOKEN": "your-oauth-token"}}
Feature | Description |
Configuration Method | The apiKeyHelper field in settings.json |
Authentication Type | Bearer Token (returned by the script) |
Caching Mechanism | Defaults to 5 minutes and can be configured through CODEBUDDY_CODE_API_KEY_HELPER_TTL_MS. |
Scenario | OAuth Client Credentials, Vault integration, and automatic token refresh |
{"apiKeyHelper": "/path/to/get-token.sh"}
#!/bin/bashvault read -field=api_key secret/codebuddy/api-key
Tool Type | Example | Approval Required | "Yes, Don't Ask Again" Behavior |
Read-Only | File read, LS, Grep | No | N/A |
Bash Command | Shell execution | Yes | Remember permanently by project directory and command |
File Modification | Edit/write files | Yes | Valid until the session ends |
/permissions to view and manage tool permissions for CodeBuddy Code. This UI lists all permission rules and the settings.json files they originate from.Tool or Tool(optional-specifier)Bash to the allow rule list allows CodeBuddy Code to use the Bash tool without user approval.permissions.defaultMode under settings or specified via --permission-mode. The common modes are as follows:Mode | Description |
default | Standard sequential approval mode |
acceptEdits | Automatically approves file edits. Bash still requires approval. |
auto | Use the classifier to automatically determine whether to allow actions that would originally trigger approval prompts. |
dontAsk | Does not display permission prompts. Actions that are not pre-approved are denied directly. |
plan | Plan mode. Primarily read and explore, and generate a plan before writing source code. |
bypassPermissions | Skip all permission prompts (requires a secure environment). |
trustAll / trustedDirectories` are not alternatives to permission modes. These two fields only affect the directory trust authorization prompt at startup (a one-time popup asking whether to trust this directory and allow CodeBuddy to run in it), and are unrelated to whether approval prompts appear during tool execution.permissions.defaultMode or use --permission-mode bypassPermissions / -y / --dangerously-skip-permissions.trustAll: true or add the directory to trustedDirectories only to bypass the directory trust popup.bypassPermissions is enabled, the directory trust popup still appears normally, and vice versa.bypassPermissions + trustAll and nothing else needs to be configured" is inaccurate. The former controls tool approval, while the latter controls directory trust, and they address different confirmation prompts.--add-dir <path> CLI parameter./add-dir slash command.additionalDirectories in the settings file.Bash(npm run build) exactly matches the Bash command npm run buildBash(npm run test:*) matches Bash commands that start with npm run testBash(curl http://site.com/:*) matches curl commands that start with curl http://site.com/:* is valid only at the end of a pattern and matches any subsequent content.Bash(curl http://github.com/:*) can be bypassed in multiple ways:curl -X GET http://github.com/... does not match.curl https://github.com/... does not match.curl -L http://bit.ly/xyz (redirects to github)URL=http://github.com && curl $URL does not match.curl http://github.com does not match.WebFetch(domain:github.com) permission.Edit rule applies to all built-in tools that edit files. CodeBuddy will make every effort to apply the Read rule to all built-in tools that read files, such as Grep, Glob, and LS.Mode | Description | Example | Match |
//path | An absolute path from the file system root directory | Read(//Users/alice/secrets/**) | /Users/alice/secrets/** |
~/path | A path from the home directory | Read(~/Documents/*.pdf) | /Users/alice/Documents/*.pdf |
/path | A path relative to the settings file | Edit(/src/**/*.ts) | <settings file path>/src/**/*.ts |
path or ./path | A path relative to the current directory | Read(*.env) | <cwd>/*.env |
/Users/alice/file is not an absolute path - it is relative to your settings file. Use //Users/alice/file to indicate an absolute path.Edit(/docs/**) - Edit in <project>/docs/ (not /docs/!).Read(~/.zshrc) - Read the .zshrc in the home directory.Edit(//tmp/scratch.txt) - Edit the absolute path /tmp/scratch.txtRead(src/**) - Read from <current directory>/src/WebFetch(domain:example.com) matches fetch requests to example.com.mcp__puppeteer matches any tool provided by the puppeteer server (the name configured in CodeBuddy Code).mcp__puppeteer__* is wildcard syntax that also matches all tools provided by the puppeteer server.mcp__puppeteer__puppeteer_navigate matches the puppeteer_navigate tool provided by the puppeteer server.mcp__github (approve all GitHub tools).mcp__github__* (approve all GitHub tools, equivalent to the previous one).mcp__github__get_issuemcp__github__list_issues{"permissions": {"allow": ["Read","Edit","Bash(git:*)","Bash(npm:*)"],"ask": ["WebFetch","Bash(docker:*)"],"deny": ["Bash(rm:*)","Bash(sudo:*)","Edit(**/*.env)","Read(~/.ssh/**)"]}}
{"permissions": {"allow": ["Read","Edit(src/**)","Bash(git:status,git:diff)"],"deny": ["Edit(**/*.env)","Edit(**/*.key)","Edit(**/*.pem)","Bash(wget:*)","Bash(curl:*)","Read(/etc/**)","Read(~/.ssh/**)","Read(~/.aws/**)"],"defaultMode": "default"}}
.codebuddy/settings.local.json).codebuddy/settings.json)~/.codebuddy/settings.json)Platform | Storage Location |
macOS | Encrypted macOS Keychain |
Linux | System keyring (GNOME Keyring, KWallet) |
Windows | Windows Credential Manager |
apiKeyHelper to configure a custom script to obtain tokens dynamically. For details, see the apiKeyHelper configuration.{"permissions": {"allow": ["Read","Edit(src/**/*.ts)","Bash(npm:test,npm:build)"],"deny": ["Edit(**/*.env)","Bash(rm:*)","Bash(sudo:*)"]}}
{"permissions": {"deny": ["Read(.env)","Read(.env.*)","Read(secrets/**)","Read(~/.ssh/**)","Read(~/.aws/**)","Edit(**/*.key)","Edit(**/*.pem)"]}}
{"sandbox": {"enabled": true,"autoAllowBashIfSandboxed": true,"excludedCommands": ["docker"]}}
# Create a team shared configuration.codebuddy/settings.json# Add to .gitignore.codebuddy/settings.local.json
CODEBUDDY_INTERNET_ENVIRONMENT environment variable is not configured or is configured incorrectly.# Check the current configurationecho $CODEBUDDY_API_KEYecho $CODEBUDDY_INTERNET_ENVIRONMENT
Version | CODEBUDDY_INTERNET_ENVIRONMENT |
Overseas Edition | Not set |
China Edition | internal |
iOA Edition | ioa |
Dedicated Edition | cloudhosted |
Private Deployment | selfhosted |
CODEBUDDY_INTERNET_ENVIRONMENT=internalinternal instead of ioaoptions.endpoint in the SDK), causing requests to still be sent to the default public network address.--permission-mode bypassPermissions flag:codebuddy --permission-mode bypassPermissions
.codebuddy/settings.json in the project root directory:{"permissions": {"allow": ["Project-specific permissions"]}}
/permissions command to view all effective permission rules and their sources.Was this page helpful?
You can also Contact sales or Submit a Ticket for help.
Help us improve! Rate your documentation experience in 5 mins.
Feedback