Anton Gladkov · 2026-04-14 · 06-tools · source ↗
mcp_servers.<id>.http_headers: static headers for MCP HTTP servers. mcp_servers.
mcp_servers.<id>.http_headers: static headers for MCP HTTP servers.
mcp_servers.<id>.env_http_headers: headers sourced from env vars.
mcp_servers.<id>.enabled: disable a configured MCP server without deleting it.
mcp_servers.<id>.required: fail startup/resume if that server is unavailable.
mcp_servers.<id>.startup_timeout_ms: millisecond alias of startup timeout.
mcp_servers.<id>.tool_timeout_sec: per-tool MCP timeout.
mcp_servers.<id>.enabled_tools: allowlist exposed MCP tools.
mcp_servers.<id>.disabled_tools: denylist exposed MCP tools.
mcp_servers.<id>.scopes: OAuth scopes to request.
mcp_servers.<id>.oauth_resource: optional OAuth resource parameter.
agents.max_threads: maximum concurrent agent threads.
agents.max_depth: maximum nested agent depth.
agents.job_max_runtime_seconds: default worker runtime for agent jobs.
agents.<name>.description: role guidance for a named agent type.
agents.<name>.config_file: TOML overlay file for that agent role.
agents.<name>.nickname_candidates: display nicknames for that role.
approval_policy.granular.sandbox_approval: allow sandbox escalation prompts.
approval_policy.granular.rules: allow prompts triggered by execpolicy rules.
approval_policy.granular.mcp_elicitations: allow MCP elicitation prompts.
approval_policy.granular.request_permissions: allow request_permissions prompts.
approval_policy.granular.skill_approval: allow skill-script approval prompts.
allow_login_shell: allow login-shell semantics for shell tools.
default_permissions: choose a named permissions profile by default.
permissions.<name>.filesystem: define filesystem permissions profile.
permissions.<name>.filesystem.<path>: read/write/none for a specific path.
permissions.<name>.filesystem.":project_roots".<subpath>: scoped access relative to project roots.
permissions.<name>.network.enabled: enable network in that profile.
permissions.<name>.network.mode: limited | full.
permissions.<name>.network.proxy_url: HTTP proxy.
permissions.<name>.network.socks_url: SOCKS proxy.
permissions.<name>.network.enable_socks5: expose SOCKS5 listener.
permissions.<name>.network.enable_socks5_udp: allow UDP via SOCKS5.
permissions.<name>.network.allow_upstream_proxy: allow chained proxying.
permissions.<name>.network.allowed_domains: network allowlist.
permissions.<name>.network.denied_domains: network denylist.
permissions.<name>.network.allow_unix_sockets: allow specific Unix sockets.
permissions.<name>.network.allow_local_binding: allow local bind/listen.
permissions.<name>.network.dangerously_allow_non_loopback_proxy: allow non-loopback proxy listener.
permissions.<name>.network.dangerously_allow_all_unix_sockets: allow arbitrary Unix sockets.
sandbox_workspace_write.writable_roots: extra writable roots in workspace-write mode.
sandbox_workspace_write.network_access: network access inside workspace-write mode.
sandbox_workspace_write.exclude_tmpdir_env_var: remove $TMPDIR from writable roots.
sandbox_workspace_write.exclude_slash_tmp: remove /tmp from writable roots.
profile: default named profile at startup.
profiles.<name>.*: profile-scoped overrides.
profiles.<name>.service_tier: per-profile tier.
profiles.<name>.plan_mode_reasoning_effort: per-profile plan reasoning.
profiles.<name>.web_search: per-profile search mode.
profiles.<name>.personality: per-profile personality.
profiles.<name>.model_catalog_json: per-profile model catalog.
profiles.<name>.model_instructions_file: per-profile instruction file.
profiles.<name>.experimental_use_unified_exec_tool: legacy unified-exec alias per profile.
profiles.<name>.oss_provider: per-profile OSS provider.
profiles.<name>.tools_view_image: per-profile image tool toggle.
profiles.<name>.analytics.enabled: per-profile analytics.
profiles.<name>.windows.sandbox: per-profile Windows sandbox.
plan_mode_reasoning_effort: dedicated reasoning setting for Plan mode.
model_providers.<id>.name: custom provider display name.
model_providers.<id>.base_url: custom provider base URL.