deny rulesallow rulesask rulesbypassPermissions short-circuitallow rulesauto / dontAskdeny always takes precedence over mode.allow / ask rules change the actual behavior of mode.auto only takes over actions that would still end with an ask.dontAsk does not mean "more permissive". Instead, it means "do not prompt and directly deny actions that are not pre-approved".bypassPermissions is not an absolute unconditional pass either: preceding deny / ask rules and interactive dangerous command checks can still block it.Mode | What Can Run Without Prompting | Scenario |
default | Read tools in trusted directories | Default; suitable for sensitive workloads / the onboarding period |
acceptEdits | Read + Edit tools in trusted directories | Review with git diff while making changes. |
auto | Actions that would originally trigger an ask are handed to the classifier to determine allow / deny. | Reduce interruptions while maintaining security boundaries. |
dontAsk | Only pre-approved actions continue to run; all others are denied directly without asking. | Non-interactive automation / fixed allowlist agent |
plan | Delegates to the mode used before plan is entered (default = default); additionally allows writing to the session plan file. | Understand the code before making changes and then decide. |
bypassPermissions | Skip most approvals. | Only for sandbox containers / VMs / offline dev containers |
delegate | Only coordination tools (such as Agent / TaskCreate / SendMessage / team management) are available; implementation tools are blocked. | The main agent only decomposes and dispatches tasks, delegating execution to subagents. |
Mode | When It Occurs |
fullAccess | The IDE client passes it in through the protocol; semantically, it is close to the global allow-all of bypassPermissions. |
work | Passed in by the IDE client. Read is directly allowed without checking trusted directories, Edit always prompts for confirmation, and for Bash, only safe commands are directly allowed while others prompt for confirmation. |
ignore | Effective only in subagent / teammate scenarios. It means to use the main session's mode and not be overridden by the subagent's own frontmatter. Not used by the main session. |
auto, dontAsk, plan, and bypassPermissions can all be specified through the CLI or settings. delegate is mainly switched through Shift+Tab within a session.Shift+TabShift+Tab to cycle through the following modes:default → bypassPermissions → acceptEdits → auto (when available) → plan → delegate → default → ...
auto appears in the cycle only when it is available in the current environment.dontAsk is not in the keyboard cycle and can only be entered through CLI, settings, or SDK / IDE control signals.Shift+Tab and Alt+M can be triggered (Alt+M is a compatibility alias).~/.codebuddy/keybindings.json.Mode | Copy | Description |
default | Not displayed | The default mode does not occupy extra space. |
bypassPermissions | ⏵⏵ bypass permissions on (shift+tab to cycle) | Can switch back to other modes cyclically. |
acceptEdits | ⏵⏵ accept edits on (shift+tab to cycle) | Can switch back to other modes cyclically. |
auto | ⏵⏵ auto mode on (shift+tab to cycle) | Appears only when available. |
dontAsk | ⏵⏵ don't ask on | Not in the cycle chain, so there is no cycle hint. |
plan | ⏸ plan mode on (shift+tab to cycle) | Indicates that the current mode is plan mode. |
plan + preceding mode | ⏸ plan + accept edits (shift+tab to cycle), and so on | Displays the baseline mode inherited before plan mode. |
delegate | ⇢ delegate mode on (shift+tab to cycle) | The main agent only performs coordination. |
--permission-modecodebuddy --permission-mode defaultcodebuddy --permission-mode acceptEditscodebuddy --permission-mode autocodebuddy --permission-mode dontAskcodebuddy --permission-mode plancodebuddy --permission-mode bypassPermissions
--permission-mode officially supports these 6 literal values. Other modes (delegate / work / fullAccess / ignore) cannot be used as standard CLI startup parameters.codebuddy -p --permission-mode dontAsk "Only allow allowlisted actions, and fail all others directly"codebuddy -p --permission-mode auto "Try to automatically fix lint errors first"
-y / --dangerously-skip-permissions: equivalent to --permission-mode bypassPermissionspermissions.defaultMode~/.codebuddy/settings.json or project settings:{"permissions": {"defaultMode": "acceptEdits"}}
--permission-modepermissions.defaultModedefaultdefaultMode: "auto" has additional limitations:autodefaultMode: "auto" in .codebuddy/settings.json and .codebuddy/settings.local.json is ignored and falls back to defaultauto is disabled or currently unavailable, it also falls back to defaultplan Remembers the Mode Before It Is Enteredplan, CodeBuddy records the permission mode that was active before CodeBuddy enters plan mode. It is restored after CodeBuddy exits. In other words:acceptEdits to plan, regular Read / Bash / non-plan file Edit operations are still processed according to the acceptEdits baseline during plan mode.plan, you return to the previous mode instead of being forced back to default.Tool Type | Action |
Read | If the path is within a trusted directory (cwd + permissions.additionalDirectories + user-added addDir), allow it; otherwise, prompt for confirmation. |
Edit | Prompt for confirmation |
Bash | Prompt for confirmation |
Others | Prompt for confirmation |
Tool Type | Action |
Read | Allow within trusted directories; prompt outside trusted directories. |
Edit | Allow automatically |
Bash | Prompt for confirmation |
Others | Prompt for confirmation |
EditWriteMultiEditNotebookEditacceptEdits only affects Edit tools and does not affect Bash. Bash always follows a separate security classification.permissions.additionalDirectories + the --add-dir option at startup.deny / ask rule, the rule still takes precedence.git diff.auto does not mean "fully automatic approval." Instead, it hands over actions that would otherwise trigger an ask to the classifier for a second judgment.deny rule.allow rule.ask rule was matched.ask.auto.auto only takes over the "asks that remain unresolved at the end" and does not replace the entire permission system.auto classifier:allow / deny ruleask ruleAskUserQuestionExitPlanModeask rules still mean "mandatory manual approval" under auto.allow or deny, with no intermediate state such as "partial approval".auto and falls back to default.-p / stream-json directly terminate the current run.auto pauses. Interactive sessions fall back to a standard approval dialog, while headless mode terminates the run to avoid repeated idle loops.auto Mode: Notes on allow Rulesauto mode CodeBuddy temporarily ignores allow rules that are "too broad / dangerous" (filtered in memory only for the current decision, without modifying your settings). The main rules that are ignored include:Bash, Bash(*), PowerShell, PowerShell(*)Bash(sudo *), Bash(eval *), PowerShell(iex *)Agent / Task rules: such as Agent(*) — prevents bypassing the classifier through sub-agents.Bash(npm test), Bash(git status), PowerShell(Get-Content foo.txt), Read, and Edit(src/foo.ts).auto mode, the correct approach is to configure autoMode rules (see below) instead of writing broad allow rules.auto Configuration and Self-Test Commandsauto classifier are controlled by top-level autoMode settings (environment / allow / soft_deny / hard_deny). For details, see Settings.codebuddy auto-mode defaults # View built-in default rulescodebuddy auto-mode config # View the currently effective rules (after expanding $defaults)codebuddy auto-mode critique # Have the model check whether your custom rules are vague, redundant, or prone to false positives
bypassPermissions.dontAsk is: do not prompt for any action that would normally require approval, and deny it directly. It is not an alias for bypassPermissions. On the contrary, it is stricter.Tool Type | Baseline Behavior |
Read | Only read-only operations within trusted directories are allowed to continue; reads outside trusted directories are denied. |
Edit | Denied unless pre-approved by an allow rule. |
Bash | Denied unless pre-approved by an allow rule. |
Others | Denied unless pre-approved by an allow rule. |
dontAsk only rewrites the final ask result. Actions that are already allow / deny are not affected.ask rules do not trigger a prompt under dontAsk. Instead, they are directly converted to deny.AskUserQuestion and ExitPlanMode are also denied under dontAsk (no prompt is shown / plan approval is not entered). This is because the intent of dontAsk is to "never interrupt the user", so even these interactive tools are no exception.allowedTools / permissions.allow together with dontAsk to create a "fixed allowlist proxy".plan mode is to first explore, then draft a plan, and then seek confirmation, rather than immediately applying changes to the source code.plan is not an independent "fully read-only mode". Instead, it is delegated to the mode that was active before plan is entered:plan from default, regular Edit / Bash operations still trigger a prompt.plan from acceptEdits, edits to non-plan files are still automatically allowed according to the acceptEdits baseline.plan truly allows additionally is "writes to the current session's plan files".Shift+Tab or EnterPlanModeShift+Tab again or use ExitPlanModecodebuddy --permission-mode plan
bypassPermissions skips most normal approval processes and is suitable for isolated containers / VMs / dev containers, sandboxes without public network access, or scripted scenarios where you fully understand the consequences.deny / ask rules are still evaluated first.permissions.disableBypassPermissionsMode: "disable", this mode falls back to the default baseline.ask rules become invalid.codebuddy --permission-mode bypassPermissions# Equivalentcodebuddy -ycodebuddy --dangerously-skip-permissions
{"permissions": {"disableBypassPermissionsMode": "disable"}}
delegate mode, the main agent only handles coordination and does not directly execute implementation tools.Agent, TaskCreate, and SendMessage.Read, Write, Edit, and Bash, are not exposed to the main agent.work is only passed in through the IDE-side protocol and is generally not used directly by CLI users.Tool Type | Action |
Read | Allow directly without checking trusted directories. |
Edit | Prompt for confirmation |
Bash | Allow safe commands directly; prompt for other commands. |
Others | Allow |
bypassPermissions.ignore is used only for subagent configuration and indicates:acceptEdits / bypassPermissions:.git, .gitconfig, .gitmodules.bashrc / .bash_profile / .zshrc / .zprofile / .envrc, and so on.npmrc / .yarnrc / .pnpmfile.cjs / bunfig.toml, and so on.vscode / .idea / .husky / .devcontainer / .cargo / .yarn / .mvn.codebuddy (except .codebuddy/worktrees).mcp.json / .codebuddy.json{"permissions": {"subagentPermissionMode": "bypassPermissions"}}
auto / dontAsk, the subagent mode is resolved in the following order:mode explicitly passed in during an Agent tool callpermissionMode in the subagent frontmatter / product config (when set to ignore, the parent session mode is inherited)--subagent-permission-modeCODEBUDDY_SUBAGENT_PERMISSION_MODEpermissions.subagentPermissionModedelegate → subagent default changes to defaultauto / dontAskauto or dontAsk, a permission ceiling is triggered first:mode, it will not take effect.auto / dontAsk, these short-circuits are disabled, and the normal permission check flow must be followed.-p, stream-json, or background agents, it is recommended to understand the modes as follows:Mode | Typical Result in Non-Interactive Mode |
default / acceptEdits / plan | Any action that still requires ask in the end will be rejected. |
auto | Actions that would originally trigger an ask are routed to the classifier; when the classifier is unavailable, fail-closed is applied; when the transcript is too long, the run is aborted. |
dontAsk | Actions that are not pre-approved are denied directly without waiting for manual confirmation. |
bypassPermissions | Most actions proceed directly. |
dontAsk + allow rules.auto.bypassPermissions.allow / ask / deny define exceptions{"permissions": {"defaultMode": "default","allow": ["Bash(npm test)", "Read(/etc/hosts)"],"ask": ["WebFetch"],"deny": ["Bash(rm -rf *)", "Edit(.git/**)"]}}
{"permissions": {"defaultMode": "dontAsk","allow": ["Read","Grep","Glob","Bash(npm test:*)"],"deny": ["Bash(git push:*)"]}}
Read / Grep / Glob are automatically approved.npm test ... is automatically approved.git push ... is always denied.dontAsk.defaultMode, disableAutoMode, autoMode, and subagentPermissionMode--permission-mode, --subagent-permission-mode, and codebuddy auto-mode.delegate modePreToolUse / PermissionRequest / PermissionDenied.-p flowWas this page helpful?
You can also Contact sales or Submit a Ticket for help.
Help us improve! Rate your documentation experience in 5 mins.
Feedback