AI Workbench
Settings
Every AI Workbench setting, its default, and where you can set it.
AI Workbench has 298 settings. Most people never change more than a few, from Settings in the app; this page lists them all, for administrators and for anyone setting them in a file.
Where a setting can be set
A setting can be set in up to four layers. When the same setting is set in more than one, the most specific wins:
| Layer | Where it lives |
|---|---|
| You | Your own settings in the app, for every project on this computer. |
| Machine | One machine you work on (this computer, a WSL distribution, a dev container or an SSH host), so each can hold its own value. |
| Project | One project, for everyone who opens it on this computer. |
| Repository | The repository's own .mojoup/settings.json file, committed with the code. |
The Set in column below lists the layers each setting accepts.
An organisation's policy sits above all four: it can set a default for any setting, or lock a setting so no layer can change it. See Policies.
In files, settings are written without the mjuWorkbench. prefix, for example { "git.mergeStrategy": "ask" }.
General
| Setting | Default | Set in | What it does |
|---|---|---|---|
backgroundNotifications | approvals | You | Notifications shown while the workbench is not the window in front: 'approvals' = permission requests and errors, 'all' = also agent turn completions, 'off' = none. One of: approvals, all, off. |
copilotCliPath | You, Machine, Project | Path to the GitHub Copilot CLI, for agents on the Copilot runtime. Leave empty to use 'copilot' from PATH (or the COPILOT_CLI_PATH environment variable). | |
enableCustomAcpAgents | false | You, Project, Repository | Offer a custom agent command when starting a solo agent: any program that speaks the Agent Client Protocol (ACP), such as "agy_acp_server.par --uid=". |
enableLmStudioAgents | false | You, Project, Repository | Allow spawning agents backed by an LM Studio endpoint. LM Studio does not authenticate by default; if you switched that on under Developer → Server Settings, paste one of its tokens into the key field under Settings → Agent backends. |
enableLoopBreaker | true | You, Project, Repository | Cancel an agent's turn when it repeats the same reasoning verbatim without making progress (shows as "Operation cancelled by user" followed by a corrective prompt). Disable if local models are being cancelled while working. |
enableOllamaAgents | false | You, Project, Repository | Allow spawning agents backed by an Ollama endpoint. |
enableUnslothAgents | false | You, Project | Allow spawning agents backed by Unsloth Desktop on this machine. Unlike Ollama it authenticates every request, so it needs an API key: make one in Unsloth under Settings → API and paste it into the key field under Settings → Agent backends. Agents on it will not start until it is there. |
lmstudioEndpoint | http://127.0.0.1:1234/v1 | You, Machine, Project | Default OpenAI-compatible endpoint for team members using the 'lmstudio' provider. Can be overridden per member in the team config. |
officeLayout | {} | You | The solo office layout (furniture, walls, floors) for ad-hoc agents. Managed by the workbench; team layouts live in .mojoup/teams/<team>.json. |
ollamaEndpoint | http://127.0.0.1:11434/v1 | You, Machine, Project | Default OpenAI-compatible endpoint for team members using the 'ollama' provider. Can be overridden per member in the team config. |
unslothEndpoint | http://127.0.0.1:8000/v1 | You, Machine, Project | Default OpenAI-compatible endpoint for team members using the 'unsloth' provider — the port Unsloth Desktop booted on (8000 by default, 8888 when it was started with -p 8888). Can be overridden per member in the team config. |
Agents
| Setting | Default | Set in | What it does |
|---|---|---|---|
agents.idleStop | automation | You, Project | Which agents are stopped after sitting idle for agents.idleStopMinutes. Members of a running team are never stopped this way; an agent waiting for your approval, or with a task still in progress, is left alone. One of: automation (Stop agents that a routine, the daily review or a task filed for a specialist started, once they sit idle.), all (Stop every idle agent outside a running team as well: chats and specialists you started yourself.), off (Never stop an agent for being idle.). |
agents.idleStopMinutes | 10 | You, Project | How long an agent may sit idle before agents.idleStop stops it. 0 turns it off. From 0 to 1440. |
agents.restart.afterUnansweredNudges | 3 | You, Project, Repository | How many reminders an agent can leave unanswered (status checks, requests to report on its task) before it is treated as stuck and restarted. 0 keeps reminding without restarting. From 0 to 20. |
agents.restart.backoffSeconds | 30 | You, Project, Repository | Seconds to wait before the first restart. Each further restart in the same window waits twice as long. From 0 to 3600. |
agents.restart.maxRestarts | 3 | You, Project, Repository | How many times an agent that crashes or stops responding is started again on its conversation within the time window. After that it is left stopped and you get a note in the inbox. 0 never restarts it. From 0 to 20. |
agents.restart.windowMinutes | 30 | You, Project, Repository | The time window restarts are counted in. An agent that has run cleanly for this long gets its full number of restarts back. From 1 to 1440. |
agents.stuckAfterMinutes | 20 | You, Project, Repository | An agent that sits idle, or waits on you, for this long while it holds a task in progress is shown as Stuck on its card, in Mission Control and on the node's dashboard. 0 never calls an agent stuck. From 0 to 1440. |
Amazon Bedrock
| Setting | Default | Set in | What it does |
|---|---|---|---|
bedrock.endpoint | runtime | You, Machine, Project | Which of Bedrock's two OpenAI-compatible endpoints to use. One of: runtime (bedrock-runtime.<region>.amazonaws.com/openai/v1 — AWS's recommendation. Chat only: the model id is typed (an inference profile such as us.anthropic.claude-…) because this endpoint cannot list models.), mantle (bedrock-mantle.<region>.api.aws/v1 — the compatibility endpoint: lists models, and carries what runtime does not yet.). |
bedrock.region | us-east-1 | You, Machine, Project | AWS region whose Amazon Bedrock endpoint members with provider "bedrock" use, e.g. ap-southeast-2. The key is an Amazon Bedrock API key (Settings → Models), sent as a bearer token — no SigV4 signing. |
Appearance
| Setting | Default | Set in | What it does |
|---|---|---|---|
appearance.reduceEffects | false | You | Turn off the moving background shapes and other decoration that is only there to look nice |
Approvals
| Setting | Default | Set in | What it does |
|---|---|---|---|
approvals.timeoutMinutes.high | 0 | You, Project, Repository | Minutes a high-risk request (running commands or deleting files) waits for an answer before it is denied automatically. It is never allowed without you. 0, the default, waits for you however long it takes. From 0 to 10080. |
approvals.timeoutMinutes.low | 10 | You, Project, Repository | Minutes a low-risk request (reading or searching) waits for an answer before it is allowed once automatically. The decision is recorded in the audit log. 0 waits for you however long it takes. From 0 to 10080. |
approvals.timeoutMinutes.medium | 30 | You, Project, Repository | Minutes a medium-risk request (editing or moving files) waits for an answer before it is denied automatically, so the agent can carry on another way. The decision is recorded in the audit log. 0 waits for you however long it takes. From 0 to 10080. |
Azure
| Setting | Default | Set in | What it does |
|---|---|---|---|
azure.auth | key | You, Project, Repository | How requests to Azure authenticate. One of: key (An API key stored in the operating system’s keychain (Settings → Inference gateways → Azure OpenAI / AI Foundry).), entra (A Microsoft Entra token from VS Code's Microsoft account — nothing to store.). |
azure.endpoint | You, Machine, Project | Azure OpenAI / AI Foundry resource endpoint, e.g. https://<resource>.openai.azure.com (normalised to the v1 surface). Used by members whose provider is "azure". |
Backup
| Setting | Default | Set in | What it does |
|---|---|---|---|
backup.folder | You | Where automatic backups are written. Empty uses the backups folder in the app's own data. A synced folder (OneDrive, Dropbox) keeps them off this computer too. | |
backup.keep | 7 | You | How many automatic backups to keep. Older ones are removed; backups you made yourself are never removed. From 1 to 100. |
backup.organisation | true | You | When you are signed in to an organisation that keeps backups, send it a copy after each backup: your settings, projects and recent chat history (never keys or tokens, at most 16 MB). A new computer can then be restored after you sign in. |
backup.schedule | daily | You | How often the workbench backs itself up on this computer: your settings, your projects and each repository's chat history and runs. Daily by default; the copies go to the backups folder and the oldest are removed after backup.keep. One of: off, daily, weekly. |
backup.transcripts | false | You | Also back up agents' full transcripts (at most 64 MB per repository, newest first). Off: chat history and runs are backed up, transcripts stay on this computer. |
Built-in browser
| Setting | Default | Set in | What it does |
|---|---|---|---|
browser.recordingFormat | webm | You | The container the built-in browser's recordings are written in — from the toolbar's Record button and from an agent's browser_record_start, which can still ask for the other. One of: webm (WebM (VP9). Plays in every browser and in most players; always available.), mp4 (MP4 (H.264). Plays everywhere, including in chat and mail clients that refuse WebM. Encoded by the app's own Chromium; falls back to WebM, and says so, on a build that cannot.). |
browser.recordingFps | 5 | You | Frames per second for recordings. Five is enough to show a feature working; more makes larger files and heavier captures. From 1 to 15. |
Built-in model runner
| Setting | Default | Set in | What it does |
|---|---|---|---|
localRunner.acceleration | auto | You | Compute backend for the local runner. Settings → Local models → Engine shows what was detected and which builds this machine can use; a backend that is not published for this platform falls back to Automatic. One of: auto (Detect the GPU and use the matching build: Vulkan on Linux / Windows with a Vulkan loader, Metal on Apple Silicon, CPU otherwise (and always CPU under WSL2).), gpu (Use the default GPU build even when detection is unsure — Vulkan on Linux / Windows, Metal on any Mac.), cpu (CPU build only.), vulkan (The Vulkan build: NVIDIA, AMD and Intel GPUs through the driver's Vulkan runtime.), rocm (The ROCm (HIP) build for AMD GPUs. Often faster than Vulkan where the card is supported; a large download.), cuda (The CUDA build for NVIDIA GPUs, with the CUDA runtime. Usually the fastest on NVIDIA; a large download.). |
localRunner.allowBuildUpdates | true | You | Let the local runner ask GitHub for llama.cpp builds at all. Off means the build this version of the app was tested with, whatever localRunner.build says — for computers that may not contact GitHub. Every build is verified against the SHA-256 GitHub publishes. |
localRunner.autoStart | true | You | Start the local runner when the workbench activates, once its build and model are downloaded. |
localRunner.build | latest | You | Which llama.cpp build runs the local model. latest (the default) follows the newest official build — downloaded from the ggml-org release and checked against the SHA-256 GitHub publishes — so new model families load without waiting for an app update; if a new build will not start, the local model goes back to the tested one. tested stays on the build this version of Mojo Up was tested with. A build number such as b10850 keeps that one build. |
localRunner.contextLength | 0 | You | Context window the local runner starts the model with (0 = the model's own default). Larger costs RAM. A per-model override in Settings → Local models wins over this. From 0 to 1048576. |
localRunner.device | You | Which GPU runs the local model, as llama.cpp names it (llama-server --list-devices: Vulkan0, CUDA1, ROCm0, MTL0). Empty is Automatic: with more than one GPU it picks a discrete card over an integrated one, so a laptop's NVIDIA or Radeon card is used rather than the Intel or AMD graphics built into the processor. all splits the model over every GPU, llama.cpp's own default. A device that is no longer there falls back to Automatic; a --device in localRunner.extraArgs wins. | |
localRunner.enabled | true | You | Allow the bundled local model runner (a llama.cpp server the app downloads into its private storage and supervises). Off stops it and hides it from providers. |
localRunner.extraArgs | You | Extra llama-server flags, space separated, passed verbatim (advanced — e.g. "-ngl 99" to offload to a GPU build you swapped in). | |
localRunner.gpuLayers | 99 | You | Model layers offloaded to the GPU when accelerated (llama-server -ngl); 99 = everything. Lower it if the model does not fit in GPU memory. From 0 to 999. |
localRunner.huggingFace.allowGated | false | You | Allow installing from gated or private Hugging Face repositories using the stored access token. Off refuses them, so a token cannot be spent without asking. |
localRunner.huggingFace.enabled | true | You | Allow searching Hugging Face and downloading GGUF models from it in Settings → Local models. Downloads are pinned to a commit and verified against the hash the Hub reports. Off hides the browser and leaves only the built-in catalogue. |
localRunner.mlxEndpoint | You | Apple silicon only: where mlx_lm.server (the MLX model server from the mlx-lm package) answers, including /v1. Leave empty for its default, http://127.0.0.1:8080/v1. Agents reach it as the mlx provider. | |
localRunner.model | qwen2.5-1.5b-instruct | You | Which model the local runner serves — a catalogue id, or the id of a model you added from Hugging Face or a local file. Changing it downloads the new model on the next start. Settings → Local models lists what is available. |
localRunner.port | 8087 | You | Loopback port the local runner listens on (http://127.0.0.1:<port>/v1). From 1024 to 65535. |
localRunner.serverPath | You | Absolute path to a llama-server you built yourself, used instead of the pinned llama.cpp build. The workbench still supervises it, health-checks it and shows its log. Needed for GGUFs stock llama.cpp cannot load — a new architecture, or an out-of-tree tensor format such as a ROCm FP4 build. Leave empty to use the bundled build. | |
localRunner.startOnRequest | true | You | Start a downloaded model the first time an agent asks for it by name, beside whatever is already running. Off means an agent's request for a model that is not running fails with a message, rather than starting it or being answered by another model. |
localRunner.threads | 0 | You | CPU threads for the local runner (0 = llama.cpp decides). From 0 to 256. |
Chat
| Setting | Default | Set in | What it does |
|---|---|---|---|
chat.autoMerge | true | You, Project, Repository | Replaced by chat.mergeWhen. While chat.mergeWhen is not set, false here still means the work waits until you press Keep it. |
chat.gitIsolation | true | You, Project, Repository | Start chat agents in their own git worktree (their own branch and working copy) instead of the repository's folder. Several can then edit at once safely, and Edit from here can put a turn's files back. Their work is merged into the current branch when chat.mergeWhen says: once the conversation has been idle for a while (the default), when you press Keep it, or after every turn. This is the default for an agent that is not a specialist; a conversation can choose where it runs on its composer (This checkout, Own worktree or Last worktree), and that choice wins. |
chat.mergeIdleMinutes | 10 | You, Project, Repository | With chat.mergeWhen set to idle: how many minutes a conversation sits without a turn before its agent's work is merged. From 1 to 1440. |
chat.mergeWhen | idle | You, Project, Repository | When a chat agent working in its own worktree has its work committed, synced with the same rebase rules as team worktrees, and merged into the repository's current branch. Until then a turn's files can be put back with Edit from here; a turn already merged cannot. Conflicts are reported in the conversation instead of merged. One of: idle (Once the conversation has been idle for chat.mergeIdleMinutes, or when you press Keep it), keep (Only when you press Keep it), every-turn (After every turn (nothing is left for Edit from here to put back)). |
chat.whileRunning | steer | You, Project | What the send button does with a message typed while a turn is running. Ctrl+Enter (⌘+Enter on a Mac) does the other one for that message. One of: steer (Send it to the agent now: Chat interrupts the turn in flight, Team Work hands it to the operations manager.), queue (Hold it in the conversation's queue and send it when the turn finishes.). |
chat.worktreeCleanup | prompt | You, Project, Repository | What to do with a chat/solo agent's isolated git worktree when the agent stops — mirrors the team worktree cleanup options. One of: prompt (Ask what to do with the worktree when the agent stops), auto (Remove the worktree automatically (kept if it still has uncommitted changes)), manual (Keep worktrees, to clean up by hand later). |
Chat approvals
| Setting | Default | Set in | What it does |
|---|---|---|---|
chatApprovals.high | ask | You, Project, Repository | Default approval policy for HIGH-risk tools (delete · execute commands) of chat/solo agents that are not part of a team. Keep on "ask" unless you fully trust the repository. One of: ask, auto. |
chatApprovals.low | ask | You, Project, Repository | Default approval policy for LOW-risk tools (read · search · fetch) of chat/solo agents that are not part of a team. Teams configure their own policy in the team config. One of: ask, auto. |
chatApprovals.medium | ask | You, Project, Repository | Default approval policy for MEDIUM-risk tools (edit · move files) of chat/solo agents that are not part of a team. One of: ask, auto. |
Customisations
| Setting | Default | Set in | What it does |
|---|---|---|---|
customisations.briefAgents | true | You, Project, Repository | Tell every agent the workbench starts what customisations the repository carries — skills, prompts, agents, instructions and MCP servers, one line each with the path — so a CLI that only reads its own folders can still use the others' on request. Items the CLI discovers by itself are left out, so the briefing costs a few lines, not the files. |
Dev containers
| Setting | Default | Set in | What it does |
|---|---|---|---|
devcontainer.autoDetect | true | You | Offer to open a folder in its dev container when it contains a devcontainer.json. |
devcontainer.cliPath | You | Command that runs the Dev Containers CLI (@devcontainers/cli), used to build and start a container. Leave empty to use 'devcontainer' from PATH. | |
devcontainer.dockerPath | You | Path to the Docker CLI used for dev containers. Leave empty to use 'docker' from PATH; 'podman' works too. | |
devcontainer.reopenMode | replace | You | What happens when a repository is opened in its dev container. One of: replace (Opening a repository in its dev container replaces the local copy with the one in the container.), add (The copy in the container is added to the project beside the local one.). |
devcontainer.useNpx | false | You | When the Dev Containers CLI is not installed, fetch and run it with npx. Off by default: it downloads a package from the network each time it is needed. |
Dictation
| Setting | Default | Set in | What it does |
|---|---|---|---|
dictation.enabled | auto | You | Let MojoFlow dictate into Chat and Team Work: a loopback Control API endpoint for companion apps plus a discovery file MojoFlow finds on its own (under WSL also in the Windows profile). Older true/false values still work as on/off. One of: auto (Start the dictation endpoint whenever MojoFlow is installed on this machine (its settings folder exists).), on (Always start the endpoint.), off (Never start it.). |
dictation.port | 7433 | You, Machine, Project | Loopback port for the dictation companion endpoint (0 = random). Must be reachable from Windows when the workbench runs in WSL, which localhost forwarding does by default. |
Docs
| Setting | Default | Set in | What it does |
|---|---|---|---|
docs.defaultFormat | okf | You, Project, Repository | The format a new document is written in. Existing files keep whatever they are; 'Save as OKF' converts a plain one. One of: okf (Typed Markdown: front matter and [kind] section tags, so memory can index sections and the view can check the structure.), markdown (Plain Markdown with no marker or section tags.). |
docs.folders | ["docs"] | You, Project, Repository | Folders, relative to the repository, whose Markdown files the Library lists. READMEs at the top level, agent instruction files, ADR folders, team roles and research notes are always documents. |
docs.templatesFolder | docs/templates | You, Project, Repository | Folder, relative to the repository, whose Markdown files are the templates the Library offers for new documents — each with 'template:' (its name), 'summary:' and 'path:' in its front matter. The Library lists the folder as Templates so they can be edited in place. |
Editor
| Setting | Default | Set in | What it does |
|---|---|---|---|
editor.inlineCompletion | local | You | Whether the built-in editor suggests code as you type, and which model may do it. One of: off (No inline suggestions in the built-in editor.), local (Only ever complete with a local model — the bundled runner, or a local endpoint. Never spends money.), always (Also use the configured chat model, including a hosted one.). |
editor.openFilesIn | built-in | You | Where a file opens when something in the workbench opens one — a doc, a customisation, the workspace policy, a pipeline definition. Files outside the repository always go to the external editor. One of: built-in (Open repository files in the workbench's own editor, in the right pane. The editor's toolbar still offers your external editor for any file.), external (Hand every file to the external editor chosen under Settings → Projects & Editors.). |
Facilitator
| Setting | Default | Set in | What it does |
|---|---|---|---|
facilitator.chatAccount | You, Machine, Project | Which subscription account the Chat agent sign in as, by the account's name in its short form ("work"), as listed under Settings → Runtimes. Empty = the runtime's default sign-in. Only Claude Code and Codex on their own sign-in, and Antigravity, have accounts. An account this machine does not have stops the agent from starting; it never falls back to the default sign-in. | |
facilitator.chatCredential | You, Project, Repository | Which of the chat provider's keys the Chat agent uses, by the key's name as it appears under Settings → Models → Inference gateways. Empty = the provider's default key. A named key brings its own endpoint unless facilitator.chatEndpoint is set. | |
facilitator.chatEndpoint | You, Machine, Project | OpenAI-compatible endpoint override for the Facilitator chat agent (local runners and inference runtimes only). Empty = the provider's default base URL. | |
facilitator.chatModel | You, Project, Repository | Model for the Facilitator chat agent (empty = provider default). Use Select Facilitator Chat Model to pick from the live model list of the configured chat backend. | |
facilitator.chatProvider | copilot | You, Project, Repository | Backend for the Facilitator chat agent. With chatRuntime set: the hosted provider whose stored API key and base URL the runtime routes through (empty = the runtime's own sign-in or default). With chatRuntime empty (legacy): a runtime id (copilot, ollama, lmstudio, claude-code…) or a hosted provider id. Ollama/LM Studio must be enabled in settings to take effect. One of: "", ollama, lmstudio, llamacpp, vllm, mlx, foundry-local, azure, bedrock, anthropic, gemini, xai, openrouter, kilo-gateway, groq, together, deepinfra, fireworks, deepseek, mistral, openai-compatible, copilot, native, cline, claude-code, codex, opencode, grok, kilo, acp-command. |
facilitator.chatRuntime | You, Project, Repository | Agent runtime for the Facilitator chat agent — the same choice a team member gets in the Team Builder (Copilot, Claude Code, Codex, Google Antigravity, native bridge, local runners…). Runtimes that pick their own model server (openai-compatible, native, cline, claude-code, codex) take a hosted provider and endpoint from mjuWorkbench.facilitator.chatProvider / chatEndpoint; Claude Code with no provider uses the account the claude CLI is signed in to. One of: "" (Not set — read the legacy Provider value (runtime id or hosted provider id)), copilot (GitHub Copilot CLI), ollama (Ollama (local runner)), lmstudio (LM Studio (local runner)), openai-compatible (Copilot CLI in BYOK mode against a hosted provider / gateway), native (Mojo Up native bridge (any OpenAI-compatible server, no Copilot licence)), cline (Cline in ACP mode), claude-code (Claude Code through its ACP adapter), codex (OpenAI Codex through its ACP adapter), gemini (Google Antigravity through its official ACP server), opencode (OpenCode in ACP mode), kilo (Kilo Code in ACP mode), acp-command (Custom ACP agent command (needs mjuWorkbench.enableCustomAcpAgents)). | |
facilitator.opsManagerAccount | You, Machine, Project | Which subscription account the Team Work operations manager sign in as, by the account's name in its short form ("work"), as listed under Settings → Runtimes. Empty = the runtime's default sign-in. Only Claude Code and Codex on their own sign-in, and Antigravity, have accounts. An account this machine does not have stops the agent from starting; it never falls back to the default sign-in. | |
facilitator.opsManagerCredential | You, Project, Repository | Which of the provider's keys the Team Work operations manager uses (its name under Settings → Models → Inference gateways). Empty = the provider's default key. | |
facilitator.opsManagerEndpoint | You, Machine, Project | OpenAI-compatible endpoint override for the ops-mode Operations Manager agent (local runners and inference runtimes only). Empty = the provider's default base URL. | |
facilitator.opsManagerModel | You, Project, Repository | Strong model used by the Operations Manager in ops mode for planning and review (empty = provider default). Use Select Operations Manager Model to pick from the live model list of the configured operations manager backend. | |
facilitator.opsManagerProvider | copilot | You, Project, Repository | Backend for the ops-mode Operations Manager agent. With opsManagerRuntime set: the hosted provider whose stored API key and base URL the runtime routes through (empty = the runtime's own sign-in or default). With opsManagerRuntime empty (legacy): a runtime id (copilot, ollama, lmstudio, claude-code…) or a hosted provider id. Ollama/LM Studio must be enabled in settings to take effect. One of: "", ollama, lmstudio, llamacpp, vllm, mlx, foundry-local, azure, bedrock, anthropic, gemini, xai, openrouter, kilo-gateway, groq, together, deepinfra, fireworks, deepseek, mistral, openai-compatible, copilot, native, cline, claude-code, codex, opencode, grok, kilo, acp-command. |
facilitator.opsManagerRuntime | You, Project, Repository | Agent runtime for the ops-mode Operations Manager agent — the same choice a team member gets in the Team Builder (Copilot, Claude Code, Codex, Google Antigravity, native bridge, local runners…). Runtimes that pick their own model server (openai-compatible, native, cline, claude-code, codex) take a hosted provider and endpoint from mjuWorkbench.facilitator.opsManagerProvider / opsManagerEndpoint; Claude Code with no provider uses the account the claude CLI is signed in to. One of: "" (Not set — read the legacy Provider value (runtime id or hosted provider id)), copilot (GitHub Copilot CLI), ollama (Ollama (local runner)), lmstudio (LM Studio (local runner)), openai-compatible (Copilot CLI in BYOK mode against a hosted provider / gateway), native (Mojo Up native bridge (any OpenAI-compatible server, no Copilot licence)), cline (Cline in ACP mode), claude-code (Claude Code through its ACP adapter), codex (OpenAI Codex through its ACP adapter), gemini (Google Antigravity through its official ACP server), opencode (OpenCode in ACP mode), kilo (Kilo Code in ACP mode), acp-command (Custom ACP agent command (needs mjuWorkbench.enableCustomAcpAgents)). | |
facilitator.workerAccount | You, Machine, Project | Which subscription account Team Work workers sign in as, by the account's name in its short form ("work"), as listed under Settings → Runtimes. Empty = the runtime's default sign-in. Only Claude Code and Codex on their own sign-in, and Antigravity, have accounts. An account this machine does not have stops the agent from starting; it never falls back to the default sign-in. | |
facilitator.workerCount | 2 | You, Project, Repository | Number of worker agents in the facilitator ops team. From 1 to 6. |
facilitator.workerCredential | You, Project, Repository | Which of the provider's keys Team Work workers use (its name under Settings → Models → Inference gateways). Empty = the provider's default key. | |
facilitator.workerEndpoint | You, Machine, Project | OpenAI-compatible endpoint override for the ops-mode worker agents (local runners and inference runtimes only). Empty = the provider's default base URL. | |
facilitator.workerModel | You, Project, Repository | Cheaper/local model used by ops-mode worker agents. Required for Ollama/LM Studio backends — use the Select Facilitator Worker Model command to pick from the server's live model list (you'll also be prompted automatically when ops starts with this empty). | |
facilitator.workerProvider | copilot | You, Project, Repository | Backend for the ops-mode worker agents. With workerRuntime set: the hosted provider whose stored API key and base URL the runtime routes through (empty = the runtime's own sign-in or default). With workerRuntime empty (legacy): a runtime id (copilot, ollama, lmstudio, claude-code…) or a hosted provider id. Ollama/LM Studio must be enabled in settings to take effect. One of: "", ollama, lmstudio, llamacpp, vllm, mlx, foundry-local, azure, bedrock, anthropic, gemini, xai, openrouter, kilo-gateway, groq, together, deepinfra, fireworks, deepseek, mistral, openai-compatible, copilot, native, cline, claude-code, codex, opencode, grok, kilo, acp-command. |
facilitator.workerRuntime | You, Project, Repository | Agent runtime for the ops-mode worker agents — the same choice a team member gets in the Team Builder (Copilot, Claude Code, Codex, Google Antigravity, native bridge, local runners…). Runtimes that pick their own model server (openai-compatible, native, cline, claude-code, codex) take a hosted provider and endpoint from mjuWorkbench.facilitator.workerProvider / workerEndpoint; Claude Code with no provider uses the account the claude CLI is signed in to. One of: "" (Not set — read the legacy Provider value (runtime id or hosted provider id)), copilot (GitHub Copilot CLI), ollama (Ollama (local runner)), lmstudio (LM Studio (local runner)), openai-compatible (Copilot CLI in BYOK mode against a hosted provider / gateway), native (Mojo Up native bridge (any OpenAI-compatible server, no Copilot licence)), cline (Cline in ACP mode), claude-code (Claude Code through its ACP adapter), codex (OpenAI Codex through its ACP adapter), gemini (Google Antigravity through its official ACP server), opencode (OpenCode in ACP mode), kilo (Kilo Code in ACP mode), acp-command (Custom ACP agent command (needs mjuWorkbench.enableCustomAcpAgents)). |
Foundry Local
| Setting | Default | Set in | What it does |
|---|---|---|---|
foundryLocal.endpoint | You, Machine, Project | Foundry Local OpenAI-compatible endpoint (including /v1). Found from the running service; leave empty to use the default port. |
Git
| Setting | Default | Set in | What it does |
|---|---|---|---|
git.autoCleanup | true | You, Project, Repository | Automatically remove Git worktrees when team agents stop. When false, worktrees persist and must be removed manually |
git.autoFetchMinutes | 5 | You, Project | Fetch 'origin' in the background at most this often while Source Control is in use, so ahead/behind counts against the remote are current. 0 turns the automatic fetch off; Source Control's fetch and sync actions still work. From 0 to 1440. |
git.branchNamePattern | feature/{teamId}/{taskId} | You, Project, Repository | Branch name template; supports {teamId}, {taskId}, {agentName} placeholders |
git.branchPrefix | feature/ | You, Project, Repository | Prefix used for feature branch names when featureBranches is enabled |
git.conflictResolver.autoApprove | true | You, Project, Repository | Let the dedicated resolver edit and commit inside the worktree without per-tool approval prompts. Its scope is one in-progress merge in one worktree. |
git.conflictResolver.endpoint | You, Machine, Project | OpenAI-compatible endpoint override for the resolver (empty = the provider's default). | |
git.conflictResolver.mode | in-session | You, Project, Repository | Who resolves merge conflicts when a worktree is merged back and the merge stops on conflicts. One of: in-session (The agent already responsible (operations manager, else the assignee; the chat agent for chat merges) resolves conflicts in its own session.), dedicated (Start a one-shot resolver agent in the worktree on the runtime below (your default runtime unless you pick another); it resolves, commits and is stopped. Falls back to in-session when it cannot start or finish.). |
git.conflictResolver.model | You, Project, Repository | Model for the dedicated resolver (empty = the backend's default; the local runner serves one model). | |
git.conflictResolver.provider | You, Project, Repository | Hosted or local provider the resolver's runtime routes through (inference runtimes only). Empty = the runtime's own sign-in. Set it to local-runner to use the bundled local model. | |
git.conflictResolver.runtime | You, Project, Repository | Agent runtime for the dedicated conflict resolver (same choices as a team member). Empty = your default runtime, on its own sign-in. One of: "", copilot, ollama, lmstudio, openai-compatible, native, cline, claude-code, codex, gemini, opencode, kilo, acp-command. | |
git.conflictResolver.timeoutMinutes | 10 | You, Project, Repository | How long the dedicated resolver may take before the in-session fallback runs. From 1 to 120. |
git.defaultBranch | main | You, Project, Repository | Branch name for repositories the workbench initialises. |
git.featureBranches | false | You, Project, Repository | Create a feature branch per task instead of working on the default branch |
git.mergeStrategy | ask | You, Project, Repository | How a feature branch is merged back to the default branch from the app. One of: direct (Merge the feature branch into the default branch locally and push it), pull-request (Push the branch and open a pull request (GitHub CLI, falls back to the compare page)), ask (Ask which of the two to use each time). |
git.pushAfterLanding | false | You, Project, Repository | Push the default branch to 'origin' after integrated work lands on it. Off by default: landing is local, so your branch is ahead of the remote until you push. A failed push is reported and never blocks the landing. |
git.useFeatureBranches | false | You, Project, Repository | Create a feature branch per task instead of working directly on a rebased default branch |
git.worktreeBasePath | You, Machine, Project | Base directory for Git worktrees. When empty, worktrees are created in a sibling '.mojoup-worktrees' folder next to the repository root |
GitHub
| Setting | Default | Set in | What it does |
|---|---|---|---|
github.oauthClientId | You | Client ID of the GitHub OAuth App used for the in-app device-flow sign-in. Empty = sign in through the GitHub CLI (gh) only. |
History
| Setting | Default | Set in | What it does |
|---|---|---|---|
history.autoArchiveIdleDays | 0 | You, Project | Archive a Chat, Research or Team Work conversation once it has been idle this many days. Archived conversations are kept and searchable, and leave the main history list; pinned and running ones are never archived. 0 turns it off. From 0 to 365. |
Identity
| Setting | Default | Set in | What it does |
|---|---|---|---|
identity.email | You | Your email address, kept with your name on the projects this computer keeps. It is how your past work is matched to you when a project is later shared with a team or your organisation. Optional. | |
identity.name | You | Your name, as your work is signed: on a project's roadmap, tasks and activity, and on comments you leave. Empty: your computer's user name. When you join a team or sign in to your organisation, the name they know you by is used there. |
Interface
| Setting | Default | Set in | What it does |
|---|---|---|---|
ui.colorMode | auto | You | Light or dark, or follow the system’s theme. One of: auto (Follow the VS Code colour theme.), light (Always light.), dark (Always dark.). |
ui.designSystem | glass | You | Which Mojo Up theme the workbench uses. One of: glass (Mojo Up (Glass): translucent surfaces over a soft backdrop.), solid (Mojo Up (Solid): the opaque teal-on-mouve system MojoFlow uses.). |
ui.developerViews | false | You | Show the developer-facing Debug view. (Architecture is a view like any other and is always in the sidebar.) |
ui.location | sidebar | You | Not used by the desktop app, which owns its own window; kept so a value from an older settings file is recognised and ignored. One of: sidebar, panel. |
ui.workspaceView | office | You | How the Workspace view shows running agents. One of: office (The pixel-art office: agents at desks, animated by what they do.), cards (Agent cards: who each agent is, their board task, what they are doing now and recently.). |
Language models
| Setting | Default | Set in | What it does |
|---|---|---|---|
llm.costMap.autoRefresh | true | You, Project, Repository | Periodically download the LiteLLM model pricing and context-window map so cost estimates stay current. Cached locally and used offline. Turn off to use only the pricing built into the app. |
llm.costMap.url | https://raw.githubusercontent.com/BerriAI/litellm/main/model_prices_and_context_window.json | You, Project, Repository | Source URL for the model pricing map. Must be HTTPS. Point at a mirror if the default is unreachable from your network. |
llm.currency | You, Project | ISO 4217 code used to display model spend (for example AUD). Leave empty to follow your computer's locale. | |
llm.currencyRate | 0 | You, Project | Pin the USD to display-currency rate. Zero fetches the rate automatically. At least 0. |
llm.currencyRates.autoRefresh | true | You, Project | Refresh exchange rates automatically from the rates URL. |
llm.currencyRates.url | https://api.frankfurter.dev/v1/latest?base=USD | You, Project | Exchange-rate source (Frankfurter-compatible JSON). |
llm.dailyBudget | 0 | You, Project, Repository | Daily spend cap across all agents on paid providers, in the currency your provider's list prices are quoted in. Requests are refused with HTTP 403 once the cap is reached. 0 disables the cap. Local providers are always free and never counted. At least 0. |
llm.mcpToolProxy.allowTools | [] | You, Project, Repository | When non-empty, only these tool names are exposed to agents. The way to give a weak local model five tools instead of forty. |
llm.mcpToolProxy.denyTools | [] | You, Project, Repository | Tool names hidden from agents even when allowed. |
llm.mcpToolProxy.enabled | false | You, Project, Repository | Execute MCP tool calls inside the proxy instead of passing them back to the agent. Useful for weak local models: the tool round trip never reaches the CLI. Agents on a runtime that runs its own tool servers (Claude Code, Codex, Copilot) are unaffected. |
llm.mcpToolProxy.servers | [] | You, Machine, Project | MCP servers the proxy aggregates and exposes to local agents. |
llm.perAgentDailyBudget | 0 | You, Project, Repository | Daily spend cap for each individual agent on paid providers. Stops one runaway agent exhausting the shared budget. 0 disables the per-agent cap. At least 0. |
llm.redactPatterns | [] | You, Project, Repository | Your own redaction rules, applied after the secrets and personal-data patterns to everything bound for a hosted provider: customer or ticket ids, internal hostnames, project codenames — anything a regular expression can name. Built and tried out under Settings → Security → Repository policy. A repository may commit its own, so the rules travel with the code. |
llm.redactPii | true | You, Project, Repository | Redact personal data — email addresses, phone numbers, payment card numbers, IBANs, tax file and social security numbers — from message content before it leaves the machine for a hosted provider, alongside the secrets redaction. Pattern-based, so it needs no classifier; the classifier in .mojoup/policy.json adds names, addresses and sensitivity on top. Local providers are never redacted. |
llm.redactSecrets | true | You, Project, Repository | Redact API keys, tokens and private keys from message content before it leaves the machine for a remote provider. Local providers (Ollama / LM Studio) are never redacted — nothing leaves the machine, and an agent debugging an auth failure needs to see the credential. |
llm.requestsPerMinute | 0 | You, Project, Repository | Maximum proxied requests per minute per agent. Requests over the limit are refused with HTTP 429 so the caller retries rather than gives up. 0 disables rate limiting. At least 0. |
Local context
| Setting | Default | Set in | What it does |
|---|---|---|---|
localContext.autoCompact | true | You, Project, Repository | Automatically compact a local agent's conversation (context reset + task resume prompt) when it nears the model runner's loaded context window. Prevents the truncation/empty-stream failures local models hit when the conversation outgrows num_ctx / the loaded context length. |
localContext.compactThreshold | 0.75 | You, Project, Repository | Fraction of the local model's context window at which auto-compaction triggers (0.75 = compact when 75% full). From 0.4 to 0.95. |
localContext.handoff | true | You, Project, Repository | Before compacting a full context window, ask the agent for a handoff note (kept on the task and in memory) so the fresh context starts from where it stopped. |
Local model
| Setting | Default | Set in | What it does |
|---|---|---|---|
localModel.declined | false | You | You said you don't want a local model on this computer. Nothing is downloaded, the local model service stays off, and the workbench stops suggesting one. Choose a local model in Settings → Setup to change your mind. |
localModel.recoveryAttempts | 3 | You, Project, Repository | How many times the local-model proxy retries a request when the runner itself has fallen over (refused connection, HTML 500) — typically a large model being reloaded into VRAM. Raise it for slow-loading MoE models such as Qwen3; 0 fails the agent's turn on the first refusal. From 0 to 10. |
localModel.recoveryMaxWaitSeconds | 45 | You, Project, Repository | Longest the proxy waits for a crashed or reloading local model to come back, per retry. Waits ramp 5s, 20s, then this ceiling, and end early the moment the runner answers a health probe — so a higher value costs nothing when recovery is fast, and buys a slow model the time it actually needs. From 5 to 600. |
localModel.share | true | You | Let repositories in a WSL distro or container on this computer use the model this computer already serves — on Windows, the GPU-backed runner for every distro, checked for reachability from each one first. A repository whose workbench serves its own model keeps using it. |
localModel.streamIdleTimeoutSeconds | 180 | You, Project, Repository | Silence between streamed chunks that means the local runner died mid-answer. Armed only after the first chunk arrives, so slow prefill is never cut short. Raise it if a model that is genuinely still generating gets cut off. From 30 to 1800. |
Local proxy
| Setting | Default | Set in | What it does |
|---|---|---|---|
localProxy.enabled | true | You, Project, Repository | Route Ollama / LM Studio agents through the built-in compatibility proxy. The proxy repairs message and tool-call formats between the agent's runtime and the local server (array content, missing tool-call ids, namespaced/mangled tool names, wrong finish reasons, reasoning fields, empty streams) and records live metrics for the Inference view. Hosted members (Claude Code, Codex, Cline, Copilot BYOK, the native bridge on a stored key) route through it too, so the provider key stays in the proxy rather than the agent's environment. Disable to connect agents directly to the endpoint, which hands them the key. |
Loop breaker
| Setting | Default | Set in | What it does |
|---|---|---|---|
loopBreaker.repeatThreshold | 6 | You, Project, Repository | How many times the same substantial line must repeat within one turn (with no completed tool call in between) before the loop breaker cancels it. Raise this if agents are being cancelled while legitimately working. From 3 to 20. |
MCP servers
| Setting | Default | Set in | What it does |
|---|---|---|---|
mcp.reportInventory | true | You, Project, Repository | Tell your organisation which tool servers (MCP servers) this repository's agents are given and which tools each one offers, so it can see what is in use and review it. Sent only when this workbench is signed in to an organisation: each server's name, how it is started or reached as the repository writes it, and its tools' names and descriptions — never a credential's value. To read a server's tool list the workbench starts it once in the background. |
mcp.shareRepoServers | true | You, Project, Repository | Attach the repository's MCP servers (.vscode/mcp.json and .mcp.json, minus any disabledServers) to every agent session the workbench starts, whatever CLI runs it — Copilot CLI, Claude Code, Codex, Gemini or OpenCode — so instructions and skills that use an MCP tool work across runtimes. Local models on the lite toolset are excluded. VS Code-style ${env:VAR} and ${workspaceFolder} references are expanded; servers needing ${input:…} prompts are skipped. |
Memory
| Setting | Default | Set in | What it does |
|---|---|---|---|
memory.autoBuild | true | You, Project, Repository | Build the knowledge graph automatically (local AST pass — free, offline) when the repository has none. |
memory.autoInstallGitHooks | true | You, Project, Repository | Install graphify's post-commit/post-checkout rebuild hooks and the graph.json union-merge driver automatically, so the memory graph stays current across the whole git lifecycle. |
memory.autoInstallSkill | false | You, Project, Repository | Retired and ignored. Earlier versions copied the graphify skill into the repository's assistant folders; agents started by the workbench are now given the project's memory directly, and nothing is installed. The key is kept so settings files that carry it stay valid. |
memory.automation | watcher | You, Project, Repository | How the memory graph stays current. One of: watcher (The workbench watches the repository and re-indexes changed files (nothing is written to .git).), hooks (graphify's git hooks and merge driver keep the graph current across commits and checkouts (writes to .git/hooks and .git/info/attributes).), off (Update the graph manually or from the memory tools only.). |
memory.autoProvision | true | You, Project, Repository | Automatically install the Graphify memory engine (PyPI package 'graphifyy') into a private Python environment the workbench manages, when it is not found on PATH. |
memory.enabled | true | You, Project, Repository | Master switch for the graph memory. Off: nothing is provisioned or indexed, agents are not briefed on memory tools and the memory tools answer 'disabled'. Git hooks already installed stay until you remove them from the Memory view. |
memory.graphifyPath | You, Machine, Project | Path to the graphify CLI executable. Leave empty for auto-detection (PATH, then a private environment managed by the app). | |
memory.knowledge.sources | [] | You, Machine, Project | Extra folders whose files belong to knowledge memory wherever they are — an Obsidian project subtree, a notes folder. Absolute paths as the workbench sees them where the repository lives (a repository in WSL needs a WSL path), or paths relative to the repository. Repository docs, ADRs, plans, research, instruction files and every Markdown or text file are knowledge already. |
memory.semanticBackend | default-runtime | You, Machine, Project | Who reads the docs, PDFs and images for the knowledge graph. Code is always mapped on this computer, for free. The default is your default runtime, on its own sign-in; a hosted provider uses the key stored in the workbench (Settings → Models); a local model keeps everything on this computer but needs one set up. One of: default-runtime (Your default runtime reads them, on its own sign-in (Claude Code, Codex, Copilot CLI or Antigravity) — what your agents already use, at the cost you already pay. A runtime that cannot read documents leaves memory to code only and says so.), auto (Automatic: a key in the environment, a local model or local server that is running, then a provider key stored in the workbench, else code only. Can use a local model; the default does not.), env (Only use an API key from the environment (GEMINI_API_KEY, ANTHROPIC_API_KEY, OPENAI_API_KEY, …).), lmstudio (LM Studio server (uses mjuWorkbench.lmstudioEndpoint; first loaded model unless semanticModel is set).), ollama (Ollama server (uses mjuWorkbench.ollamaEndpoint; first available model unless semanticModel is set).), unsloth (Unsloth Desktop server (uses mjuWorkbench.unslothEndpoint and the API key stored in the workbench, which it requires on every request; first available model unless semanticModel is set).), local-runner (The bundled local model runner (llama.cpp) the workbench downloads and serves itself — set up in Settings → Setup. Uses the model it is serving unless semanticModel is set.), claude-code (Claude Code, on its own sign-in (a Pro / Max plan) — no API key. One chunk at a time through the claude CLI; semanticModel optional (e.g. sonnet, haiku).), codex (OpenAI Codex, on its own sign-in — no API key. Each chunk is one turn of the CLI, so it is slower than an API; semanticModel optional.), copilot (GitHub Copilot CLI, on its own sign-in — no API key. Each chunk is one turn of the CLI and spends premium requests; semanticModel optional.), antigravity (Google Antigravity, on its own sign-in — no API key. Each chunk is one turn of the CLI; semanticModel optional.), azure (Azure OpenAI / AI Foundry — needs mjuWorkbench.azure.endpoint and semanticModel.), bedrock (Amazon Bedrock — the region from mjuWorkbench.bedrock.region, a Bedrock API key and semanticModel (a Bedrock model id).), anthropic (Anthropic Claude, using the key stored in the workbench. semanticModel optional.), gemini (Google Gemini, using the key stored in the workbench. semanticModel optional.), xai (xAI (Grok) — an xAI API key and semanticModel.), openrouter (OpenRouter, using the key stored in the workbench. semanticModel required.), groq (Groq, using the key stored in the workbench. semanticModel required.), together (Together AI, using the key stored in the workbench. semanticModel required.), deepinfra (DeepInfra, using the key stored in the workbench. semanticModel required.), fireworks (Fireworks AI, using the key stored in the workbench. semanticModel required.), deepseek (DeepSeek, using the key stored in the workbench. semanticModel required.), mistral (Mistral AI, using the key stored in the workbench. semanticModel required.), openai-compatible (Custom OpenAI-compatible server — needs an endpoint and semanticModel.), off (Never run the semantic pass — index code only (docs/PDFs/images are skipped).). |
memory.semanticModel | You, Machine, Project | Model for the semantic pass. Empty = the first model the local server reports (LM Studio / Ollama), or the backend's own default (Anthropic / Gemini). Every other cloud provider needs this set explicitly. Use Select Memory Semantic Backend & Model to pick from a live model list. | |
memory.semanticSchedule | nightly | You, Project, Repository | When the memory model reads changed documents. Code is always kept current for free; reading documents uses the model chosen for memory and can cost money. One of: nightly (Once a night (between 1 and 6 in the morning, when the workbench is running), documents changed since the last pass are read with the memory model. Agents' updates and the file watcher only refresh code, which costs nothing.), manual (Only when you press Rebuild or Update in the Memory view.). |
memory.shareGraph | false | You, Project, Repository | Share the memory map with the repository: graphify-out/graph.json is committed (nothing else in graphify-out/), and a merge driver in .git/info/attributes joins two people's maps instead of leaving a conflict. Off: the map stays on this computer and no merge driver is installed. |
Model gateway
| Setting | Default | Set in | What it does |
|---|---|---|---|
gateway.externalUrl | You, Machine, Project | External gateway base URL including /v1 (e.g. http://localhost:4000/v1 for LiteLLM). Its API key goes in the "Gateway (OpenAI-compatible)" row under Settings → Inference gateways. | |
gateway.mode | embedded | You, Machine, Project | Where the inference gateway runs. One of: embedded (The inference gateway runs inside the workbench for this repository (stops when it restarts).), sidecar (A supervised gateway process that survives restarts and can serve other tools on this computer (Claude Code, Copilot BYOK, curl).), external (Route hosted providers to an external OpenAI-compatible gateway such as LiteLLM (mjuWorkbench.gateway.externalUrl); local providers stay direct.). |
gateway.port | 7432 | You, Machine, Project | Loopback port for the gateway sidecar (0 = random). |
Node
| Setting | Default | Set in | What it does |
|---|---|---|---|
node.acceptsDispatchFrom | [] | You | Headless node only: whom the node itself accepts work from (project:<id>, group:<name>, user:<id>, tenant). Empty leaves it to the organisation's assignment. A node can narrow its audience here, never widen it. |
node.approvalHoldSeconds | 1800 | You | Headless node only: how long a tool-permission request is held once it has reached the organisation's inbox (the person's phone and console) before the node denies it. Never shorter than the timeout above. From 10 to 3600. |
node.approvalTimeoutSeconds | 300 | You | Headless node only: how long a tool-permission request waits for a remote approval (console, phone, a paired desktop) before the node denies it. Nobody answering means no. From 10 to 3600. |
node.autoUpdate | notify | You | Headless node only: whether the node looks for a new version from where it was installed, and installs it. MOJOUP_DISABLE_AUTO_UPDATE=1 in the node's environment turns this off whatever it says. One of: off (Never look for a new version by itself.), notify (Look every few hours and say so in the node's log and mojoup-node status.), install (Look every few hours and install a new version: it is tried first, and the node stays on the version it has if the new one does not start.). |
node.computer.display | headless | You | Headless node only: how that computer is drawn. One of: headless, xvfb, vnc, native. |
node.computer.kind | off | You | Headless node only: the remote computer use the node offers (role computer): a browser, a whole desktop, or none. One of: off, browser, desktop. |
node.computer.sessions | 0 | You | Headless node only: the most computer-use sessions at once (0 = not stated). At least 0. |
node.consent.modelDownload | false | You | Headless node only: the answer to "download the llama.cpp build and this model?", which a desktop asks in a dialog. Off declines, so a node never downloads gigabytes nobody agreed to. |
node.consent.organisationPolicy | replace | You | Headless node only: when the organisation publishes a policy for a repository that already has its own .mojoup/policy.json, replace it with the organisation's (the default on a managed node) or keep the repository's. One of: replace, keep. |
node.home | You | Headless node only (mojoup-node): the folder the node clones repositories into and runs agent runtimes from, reported to the organisation as the node's home. Empty uses the node's user home directory. | |
node.maxConcurrentAgents | 0 | You | Headless node only: the most agents the node runs at once, as offered in its manifest (0 = no limit offered; the organisation's assignment quota still applies). At least 0. |
node.name | You | Headless node only: the name the organisation lists this node under (mojoup-node join --name). Empty uses the hostname. | |
node.owner | org | You | Headless node only: who the node is offered as belonging to in its manifest — the organisation (a shared node), the person who joins it (their own box) or one project. The approver decides; this is what the node proposes. One of: org, user, project. |
node.roles | ["teams"] | You | Headless node only: what the node is offered for, beside what it detects. teams is always offered; inference and dlp are added when the local runner serves a model (dlp when it serves the model a repository's DLP classifier names); sandbox and computer are offered only when listed here and configured under node.sandbox.* and node.computer.*. |
node.sandbox.egress | policy | You | Headless node only: sandbox network access — through the node's policy, or none at all. One of: policy, none. |
node.sandbox.engine | off | You | Headless node only: the container engine the node offers agent sandboxes on (role sandbox). Off offers none. One of: off, docker, podman. |
node.sandbox.images | [] | You | Headless node only: the sandbox images the node offers (at most 32). |
node.sandbox.maxConcurrent | 0 | You | Headless node only: the most sandboxes at once (0 = not stated). At least 0. |
node.stateDir | You | Headless node only (mojoup-node): where the node keeps its settings, projects, secrets, key file, mesh state and status.json. Read from /etc/mojoup/node.json (%ProgramData%\MojoUp\node.json on Windows) or the MOJOUP_NODE_STATE_DIR environment variable; empty uses ~/.mojoup/node, or /var/lib/mojoup/node when the node runs as root. | |
node.tags | [] | You | Headless node only: mesh policy tags the node asks for when it joins and runs (tag:gpu, tag:linux). The approver may change them; assignment happens in the organisation's console, never here. |
Notifications
| Setting | Default | Set in | What it does |
|---|---|---|---|
notifications.muted | [] | You | Projects you have muted, by their id on this desktop. A muted project's notifications still arrive in the inbox, but they never raise an operating-system notification and do not count on the bell. |
notifications.os | unfocused | You | When the operating system should tell you about an agent waiting on a permission, an update, a repository's workbench that stopped, or a warning from one, while you were elsewhere. One of: unfocused (Only when the app is not the window you are in — minimised, behind something else, or in the tray.), always (Whenever it happens, even while you are looking at the workbench.), never (Never; everything stays inside the app.). |
notifications.quietDays | [] | You | Whole days that are quiet, such as the weekend. They work like quiet hours all day long: the inbox and the bell still fill, the operating system stays silent, and an approval asked of you by name still reaches you. |
notifications.quietHours | You | Quiet hours, as HH:MM-HH:MM in this computer's local time (22:00-07:00 runs across midnight). Empty means none. During quiet hours anything that needs you still lands in the inbox and counts on the bell, but the operating system stays silent — except for an approval someone asked of you by name, which still reaches you. |
Observability
| Setting | Default | Set in | What it does |
|---|---|---|---|
observability.otlpEndpoint | You | OTLP/HTTP collector base URL (e.g. http://localhost:4318). Every gateway request is exported as a span with tokens, cost, repairs and policy decisions. Empty = off. | |
observability.otlpHeaders | {} | You | Extra headers for the OTLP collector (e.g. an Authorization header). |
Operations
| Setting | Default | Set in | What it does |
|---|---|---|---|
ops.maxDispatchesPerTask | 3 | You, Project, Repository | Maximum times an ops run may (re)dispatch the same task before flagging it needs-human-review. From 1 to 10. |
ops.perTaskTokenBudget | 0 | You, Project, Repository | Tokens a single task may consume before it is stopped and flagged over-budget (0 = off). The inference policy's budgets.perTaskTokens takes precedence when set. At least 0. |
ops.shapeByDefault | false | You, Project, Repository | Start new Team Work conversations with "Shape first" on: the operations manager coaches you through a brief (type, sections, decisions, phases) before anything is planned. The toggle beside the team picker still overrides it per conversation. |
ops.stallTimeoutMinutes | 30 | You, Project, Repository | End an ops run with a timeout result when the task board sees no activity for this many minutes. From 5 to 240. |
ops.testBeforeCommit | advisory | You, Project, Repository | Run the tests that cover a task's changed files when task_done commits its work. Advisory always commits: a failure is reported to the reviewer, not held against the agent. A suite that could not run — no node_modules, no test file for the changed unit, a timeout — is recorded as indeterminate and never counted as a failure. One of: off (Do not run anything; task_done commits as before.), advisory (Run the tests covering the task's changed files, record the result on the task and tell the reviewer — then commit either way.). |
Organisation
| Setting | Default | Set in | What it does |
|---|---|---|---|
organisation.bindTokensToDevice | true | You | When your organisation supports it, bind this computer's sign-in to a key that never leaves it, so a copy of its token is useless anywhere else. Takes effect at the next sign-in or token refresh. Turning it off stops new bindings; a sign-in already bound stays bound until you sign out. |
Pipelines
| Setting | Default | Set in | What it does |
|---|---|---|---|
pipelines.agentRuns | ask | You, Project | Whether agents may start, re-run or cancel GitHub Actions and Azure Pipelines runs. Reading runs and logs is always allowed; approving a deployment is never an agent's call. One of: ask (Ask each time an agent wants to start, re-run or cancel a pipeline run; no answer means no.), allow (Let agents start, re-run and cancel runs without asking (they are still on the audit log).), off (Agents may read pipelines and logs but never start, re-run or cancel a run.). |
pipelines.azureDevOps.organisation | You, Project, Repository | Azure DevOps organisation whose Azure Pipelines build this repository. Empty = derive it from a dev.azure.com origin remote. Set this and the project for a GitHub repository built by Azure Pipelines. | |
pipelines.azureDevOps.project | You, Project, Repository | Azure DevOps project whose Azure Pipelines build this repository. Empty = derive it from a dev.azure.com origin remote. | |
pipelines.notifyOnFinish | true | You, Project | Say when a GitHub Actions or Azure Pipelines run the Pipelines view saw running has finished, or has started waiting for your approval, with a button to open it. |
Plans
| Setting | Default | Set in | What it does |
|---|---|---|---|
plans.unifyWaitHours | 24 | You, Project, Repository | When a plan's work is finished but some of its acceptance criteria are not confirmed, the plan waits this many hours for someone to pass or fail them (or close it anyway) before it closes on its own, recording them as not confirmed. 0 never waits: the plan closes at once and says which criteria were not confirmed. From 0 to 8760. |
Platform
| Setting | Default | Set in | What it does |
|---|---|---|---|
platform.cloudUrl | https://ai.mojoup.com.au | You | Where "Sign in with Mojo Up" finds Mojo Up AI Cloud. Change it only to try a Cloud that is not the public one (a local one while developing it). |
platform.mesh.enabled | true | You | Once signed in to an organisation that offers a mesh, join it: the desktop runs the bundled aioe-mesh agent so the console and your other machines reach this workbench through the encrypted mesh tunnel instead of the relay. Turning it off stops the agent; the platform marks the node offline and falls back to the relay. |
platform.mesh.port | 7434 | You | Loopback port the desktop serves signed remote control on for the mesh agent (0 = any free port). The agent exposes it on the node's overlay address at the same port. |
platform.mesh.proxy | You | The proxy the mesh agent reaches your organisation through. Empty uses the system's proxy for the platform's address (PAC and WPAD included), which is what a network that lets HTTPS out only through its proxy needs; "direct" uses none; or a proxy URL such as http://proxy.corp:8080 or socks5://host:1080. Stored as a plain setting, so do not put a password in it. | |
platform.organisation | You | Display name of the organisation this desktop is signed in to (set by discovery; shown as "Managed by <organisation>" where the platform's policy applies). | |
platform.url | You | Default platform URL offered when onboarding a project (.mojoup/project.json). |
Product
| Setting | Default | Set in | What it does |
|---|---|---|---|
product.features | [] | You | What this workbench is licensed for (nodes, mesh, backups, …), from the device licence its platform issued or the edition's defaults. Worked out by the workbench, like product.tier: a value written here is put back. |
product.tier | free | You | Which edition this workbench runs as, worked out by the workbench from what it is signed in to: Enterprise with an organisation's own platform, Teams with Mojo Up AI Cloud Teams (Mojo Up's SaaS control plane for the AI Workbench) or a team hub on your own network, Free otherwise. It is not a choice: a value written here is put back. One of: free, teams, enterprise. |
Projects
| Setting | Default | Set in | What it does |
|---|---|---|---|
projects.startTeamsForParts | true | You, Project, Repository | When another repository of the project sends this one part of its plan, start the team (or the specialist) the part is given to, so it is worked without anyone pressing Start. The part goes to the team named in the plan, else the team with the same id as the one that planned it, else one whose roles cover the part's role, else the specialist for that role, else this repository's own tasks. Off: the part waits on that team's board until the team is started. |
Pull requests
| Setting | Default | Set in | What it does |
|---|---|---|---|
pullRequests.apiUrl | You, Project, Repository | The web address of a self-managed GitLab, Forgejo or Gitea server (https://git.example.com), when it is not the origin remote's server as written: a different port, or a server under a subpath. Empty = from the origin remote. | |
pullRequests.host | auto | You, Project, Repository | Which service this repository's origin is on, for a self-managed server whose address does not say. Pull requests are read and acted on through that service's API. One of: auto (Tell the service from the origin remote's address (github.com, dev.azure.com, gitlab.com, codeberg.org, gitea.com, bitbucket.org, or a server named gitlab., forgejo. or gitea.)), gitlab (A GitLab server), forgejo (A Forgejo server), gitea (A Gitea server), bitbucket (Bitbucket Cloud). |
pullRequests.settleTasksOnMerge | true | You, Project, Repository | When a pull request joined to a task merges, move the task to done with a comment saying so. Off, the task only gets the comment. A pull request closed without merging never moves its task. |
Remote control
| Setting | Default | Set in | What it does |
|---|---|---|---|
remote.ipc.enabled | false | You, Machine, Project | Serve the Control API on a local IPC endpoint (Unix socket / named pipe, owner-only) for companion apps on this machine. The token is written to the workbench's own storage for the repository (remote/ipc.json there), never into the repository. |
remote.lan.allowPlainHttp | false | You, Machine, Project | Allow the LAN listener without TLS. Only for trusted networks: tokens travel in the clear. |
remote.lan.autoTls | true | You, Machine | When the listener for paired devices is reachable from other machines and no certificate is set, make one for this workbench, so the connection is encrypted. Devices that pair check its fingerprint. |
remote.lan.certPath | You, Machine, Project | PEM certificate for the LAN listener (TLS). | |
remote.lan.enabled | false | You, Machine, Project | Serve the Control API on a network interface for paired devices. Requires a TLS certificate unless plain HTTP is explicitly allowed. |
remote.lan.host | 127.0.0.1 | You, Machine, Project | Interface the LAN listener binds to (0.0.0.0 for every interface). |
remote.lan.interface | You, Machine | Which network the listener for paired devices uses: "tailnet" for your Tailscale network, the name of a network interface, or empty to use the address in remote.lan.host. This is the address other workbenches and nodes use to reach this one. | |
remote.lan.keyPath | You, Machine, Project | PEM private key for the LAN listener (TLS). | |
remote.lan.port | 7431 | You, Machine, Project | Port for the LAN listener (0 = random). |
remote.mirror.allowControl | false | You | Also let a client with the ui:control scope click and type into this window. Off, and worth leaving off unless someone is actively debugging with you — it is full control of the app, and the window shows a warning the whole time it is possible. |
remote.mirror.enabled | false | You | Let a paired client with the ui:view scope watch this window over the Control API, for remote debugging. Off. While anyone is watching, a badge in the title bar says so and will not stop saying so. |
remote.pairing.idleDays | 30 | You | How many days a paired device may go unused before its pairing expires and it has to be paired again. Each use starts the count again. 0 means pairings never expire. At least 0. |
remote.rateLimitPerMinute | 120 | You | Control API requests per minute allowed per remote client. At least 10. |
remote.relay.url | You | Relay / platform URL the workbench dials out to (no inbound ports). Your organisation sets it when you sign in. |
Research
| Setting | Default | Set in | What it does |
|---|---|---|---|
research.artifacts.folder | docs/research | You, Project, Repository | Folder, relative to the repository, that research artifacts are written into. |
research.artifacts.formats | ["okf","md","html"] | You, Project, Repository | How a finished research report is written to disk. 'okf' is the Library's typed Markdown (indexed by memory and read there); 'md' is plain Markdown with notebook-friendly front matter (what Obsidian and Gemini Notebook receive); 'html' is a self-contained page anyone can open in a browser. |
research.critique.enabled | false | You, Project, Repository | Review every research report before it is delivered: a second model critiques the draft and the author revises it (Critique mode). The Research composer can switch this per run. |
research.critique.reviewer | You, Project, Repository | The specialist (its id in Teams) that reviews a research specialist's draft when the specialist names no reviewer of its own. Empty means the specialist reviews its own draft in a fresh frame. | |
research.obsidian.auto | false | You, Machine, Project | Send every finished research report to Obsidian without being asked. |
research.obsidian.enabled | false | You, Machine, Project | Offer to send research reports to an Obsidian vault on this machine. |
research.obsidian.folder | Research | You, Machine, Project | Folder inside the vault that research notes are written into. |
research.obsidian.mirrorDocs | true | You, Machine, Project | Copy the repository's own documents into the vault's Docs/ folder when knowledge memory is written there, so a community note links to something you can read in the vault instead of naming a repository path. They are copies: edit the repository, not the vault. Off for a repository whose docs are too large to want in a vault. |
research.obsidian.openAfterExport | true | You, Machine, Project | Open the note in Obsidian after sending it. |
research.obsidian.projectFolder | You, Machine, Project | The folder inside the vault this project's notes live in — research reports, the knowledge memory's community notes, routers. Empty means 'AI Workbench/<repository folder name>'. The workbench writes nothing outside it, and inside it only the notes it generated; your Inbox/ there is read, never written. | |
research.obsidian.syncKnowledge | false | You, Machine, Project | Write knowledge memory into the vault after every memory update — community notes, routers, lessons and the work log — as well as when you press Sync in the Memory view. |
research.obsidian.vaultName | You, Machine, Project | The vault's name as Obsidian shows it, for the link that opens a note. Empty uses the folder's name. | |
research.obsidian.vaultPath | You, Machine, Project | The Obsidian vault folder, as the workbench sees it where the repository lives (a repository in WSL needs a WSL path). | |
research.reviewTasks | false | You, Project | Hold the tasks a research run files for your review before they are marked done. Off (the default): they go straight to Done and the report is the thing to read. A specialist set to wait for your review still waits. |
Review
| Setting | Default | Set in | What it does |
|---|---|---|---|
review.specialist | You, Project, Repository | The specialist (its id on the Teams page) that writes the daily review when the routine or the Run button names nobody. Empty = the default chat agent, started for the review and stopped after it. |
Routines
| Setting | Default | Set in | What it does |
|---|---|---|---|
routines.defaultSpecialist | You, Project, Repository | The specialist (its id on the Teams page) that runs any routine that names nobody: a prompt routine talks to it in Chat, and the daily review is written by it unless review.specialist names someone else. Empty = the default chat agent from Settings → Models → Chat & Team Work. |
Runtimes
| Setting | Default | Set in | What it does |
|---|---|---|---|
runtimes.claude-code.command | You, Machine, Project | Command (or full path) for the Claude Code ACP adapter. Empty uses "claude-agent-acp" (or the older "claude-code-acp") from PATH, and falls back to "npx -y @agentclientprotocol/claude-agent-acp" when neither is installed but Claude Code is. | |
runtimes.claude-code.enabled | true | You, Machine, Project | Enable the claude-code runtime for new agent sessions, terminal profiles and Usage. Disable to hide it without uninstalling it or stopping active sessions. |
runtimes.cline.command | You, Machine, Project | Command (or full path) for the Cline runtime. Empty uses "cline" from PATH. | |
runtimes.cline.enabled | true | You, Machine, Project | Enable the cline runtime for new agent sessions, terminal profiles and Usage. Disable to hide it without uninstalling it or stopping active sessions. |
runtimes.codex.command | You, Machine, Project | Command (or full path) for the Codex ACP adapter. Empty uses "codex-acp" from PATH, and falls back to "npx -y @agentclientprotocol/codex-acp" when Codex is installed without it. | |
runtimes.codex.enabled | true | You, Machine, Project | Enable the codex runtime for new agent sessions, terminal profiles and Usage. Disable to hide it without uninstalling it or stopping active sessions. |
runtimes.copilot.command | You, Machine, Project | Command (or full path) for the GitHub Copilot CLI runtime. Empty uses "copilot" from PATH. | |
runtimes.copilot.enabled | true | You, Machine, Project | Enable the Copilot runtime for new agent sessions, terminal profiles and Usage. Disable to hide it without uninstalling it or stopping active sessions. |
runtimes.default | copilot | You, Machine, Project | The runtime agents use unless they choose another: new team members and specialists, and the Chat agent, operations manager and ops worker while their own runtime setting is empty. Existing members keep the runtime they were saved with. One of: copilot (GitHub Copilot CLI), claude-code (Claude Code), codex (OpenAI Codex), opencode (OpenCode), kilo (Kilo Code), gemini (Google Antigravity), grok (Grok Build), cline (Cline), native (Mojo Up native bridge, with a local model or a hosted one (runtimes.defaultProvider)). |
runtimes.defaultModel | You, Machine, Project | The model the default runtime asks its provider for (empty = the provider's or runtime's default; the bundled local model serves one model). | |
runtimes.defaultProvider | You, Machine, Project | The local or hosted provider the default runtime's model comes from, for runtimes that take one (the native bridge, Cline, Claude Code, Codex, Kilo Code): "local-runner" for the bundled local model, "ollama", or a hosted provider id such as "openrouter" whose key is stored under Models. Empty = the runtime's own sign-in; the native bridge then uses the bundled local model. | |
runtimes.gemini.command | You, Machine, Project | Command (or full path) for the official Antigravity ACP server. Empty uses the server installed by Settings; legacy Gemini defaults migrate automatically. | |
runtimes.gemini.enabled | true | You, Machine, Project | Enable the Google Antigravity runtime for new agent sessions, terminal profiles and Usage. Disable to hide it without uninstalling it or stopping active sessions. |
runtimes.grok.command | You, Machine, Project | Command (or full path) for the Grok Build runtime. Empty uses "grok" from PATH. | |
runtimes.grok.enabled | true | You, Machine, Project | Enable the Grok Build runtime for new agent sessions, terminal profiles and Usage. Disable to hide it without uninstalling it or stopping active sessions. |
runtimes.kilo.command | You, Machine, Project | Command (or full path) for the Kilo Code runtime. Empty uses "kilo" from PATH. | |
runtimes.kilo.enabled | true | You, Machine, Project | Enable the Kilo Code runtime for new agent sessions, terminal profiles and Usage. Disable to hide it without uninstalling it or stopping active sessions. |
runtimes.native.enabled | true | You, Machine, Project | Enable the native runtime for new agent sessions, terminal profiles and Usage. Disable to hide it without uninstalling it or stopping active sessions. |
runtimes.opencode.command | You, Machine, Project | Command (or full path) for the OpenCode runtime. Empty uses "opencode" from PATH. | |
runtimes.opencode.enabled | true | You, Machine, Project | Enable the opencode runtime for new agent sessions, terminal profiles and Usage. Disable to hide it without uninstalling it or stopping active sessions. |
Stall nudge
| Setting | Default | Set in | What it does |
|---|---|---|---|
stallNudge.enabled | true | You, Project, Repository | Automatically prompt an agent to continue when it ends a turn describing what it is about to do without actually calling any tools — a common failure mode for local models. |
stallNudge.localOnly | true | You, Project, Repository | Only nudge stalled agents on a local model (Ollama, LM Studio, the built-in runner). Turn off to nudge agents on every runtime. |
stallNudge.maxNudges | 3 | You, Project, Repository | How many times in a row a stalled agent may be nudged to continue before the workbench gives up and leaves it idle. From 1 to 10. |
Targets
| Setting | Default | Set in | What it does |
|---|---|---|---|
targets.ssh | [] | You | SSH machines this workbench can open repositories on, one per ~/.ssh/config alias. Each needs sshd and a POSIX shell; the app installs what it needs there (and Node, on Linux) over ssh. |
Task board
| Setting | Default | Set in | What it does |
|---|---|---|---|
taskBoard.store | auto | You, Project, Repository | Where this repository's task board lives. By default the organisation decides: once a project is an enterprise project (or a personal one is promoted), every member's clone uses its shared board. One of: auto (The organisation decides: an enterprise project's roots use its shared board, a personal project's board stays in .mojoup/taskboard.), local (The board lives in this repository's .mojoup/taskboard.), organisation (The board is the organisation project's shared board in AIOE: every member's workbench sees and changes the same tasks. Needs the repository's .mojoup/project.json to name an organisation project and repository, and this workbench signed in to the organisation.), hub (The board is kept by your team's hub: every workbench and node paired to it sees and changes the same tasks. Needs the project shared with the team on the hub.). |
Tasks
| Setting | Default | Set in | What it does |
|---|---|---|---|
tasks.archiveDoneAfterDays | 14 | You, Project, Repository | Finished tasks leave the board for the archive after this many days in Done, so the Done column stays short. A task something unfinished depends on, one with an open review, one whose work is not merged yet, a part of a project task that is not done, and a task you restored from the archive all stay. 0 keeps finished tasks on the board until you archive them yourself. From 0 to 365. |
tasks.archiveHousekeepingAfterMinutes | 60 | You, Project, Repository | Housekeeping tasks (what a routine or a request to the scribe puts on the board) leave it for the archive this many minutes after they finish successfully. One that failed, or finished with concerns, stays as long as any other task. 0 treats housekeeping like any other task. From 0 to 10080. |
tasks.azureDevOps.organisation | You, Project, Repository | Azure DevOps organisation for the Azure Boards mirror (empty = derive from the origin remote). | |
tasks.azureDevOps.project | You, Project, Repository | Azure DevOps project for the Azure Boards mirror (empty = derive from the origin remote). | |
tasks.azureDevOps.workItemType | Task | You, Project, Repository | Work item type created for a mirrored task (Task, User Story, Issue, Product Backlog Item…). |
tasks.backend | local | You, Project, Repository | Where team/solo tasks are stored. The local board is always the working store; a backend mirrors it. One of: local (Tasks live only in .mojoup/taskboard (this repository).), github (Tasks are mirrored to GitHub Issues (your GitHub sign-in).), azure-boards (Tasks are mirrored to Azure Boards work items (your Azure DevOps sign-in).). |
tasks.githubRepo | You, Project, Repository | GitHub repository for issue sync as "owner/repo" (empty = derive from the origin remote). | |
tasks.wakeAfterMinutes | 10 | You, Project, Repository | How long an agent has to pick up a task handed to it before it is reminded. If it still has not, after tasks.wakeReminders reminders the task goes to the team's operations manager and then to you, this long between each step. Every step is in the activity log and the audit trail. 0 turns reminders off. From 0 to 240. |
tasks.wakeReminders | 2 | You, Project, Repository | How many times an agent is reminded of a task it has not picked up before the task goes to the team's operations manager. A reminder points at the task; it never sends the task again. From 0 to 10. |
Team Work
| Setting | Default | Set in | What it does |
|---|---|---|---|
teamwork.autoStartQueued | true | You, Project, Repository | Start the next queued Team Work session automatically when the team's active session finishes. When off, queued sessions wait for a manual start from the queue. |
Teams
| Setting | Default | Set in | What it does |
|---|---|---|---|
teams.default | You, Project, Repository | The team this project works with by default, by id: the team Home and the team wizard show it first. Set it for the whole project, or for one repository in its committed settings. Empty: no default. | |
teams.definitions | [] | You, Project | Team definitions stored outside the repository: saved for this workbench they are available to every project on this computer; saved for a project, to every repository in it. Managed from the Teams view; a repository's own teams live in .mojoup/teams/. |
teams.hub.enabled | false | You | Make this workbench your team's hub (Teams edition): the other workbenches, nodes and phones of your team pair to it and share its projects, task boards and inbox over your own network. |
teams.hub.fingerprint | You | The fingerprint of your team hub's certificate (sha256:…), checked on every connection so this workbench only ever talks to your own hub. Filled in when you join. | |
teams.hub.name | You | Your team's name, as the hub shows it to the people who join. | |
teams.hub.url | You | The address of your team's hub this workbench has joined. Filled in when you join with an invitation; empty when this workbench is not part of a team hub. |
Terminal
| Setting | Default | Set in | What it does |
|---|---|---|---|
terminal.fontSize | 13 | You | Font size of the integrated terminal, in pixels. From 8 to 32. |
terminal.profiles | [] | You | Your own terminal profiles, beside the shell and the agent CLIs: a name, the command to run and a tab colour. Edited from the new-terminal menu's Manage profiles…. |
terminal.scrollback | 5000 | You | Lines the integrated terminal keeps above the visible screen. From 100 to 100000. |
terminal.shell | You, Machine | The shell the integrated terminal starts: a path or a name on PATH (pwsh.exe, cmd.exe, /usr/bin/fish). Empty uses $SHELL — PowerShell on Windows. A terminal for a repository in WSL runs the distro's own login shell; set this for that distro to change it. |
Turn watchdog
| Setting | Default | Set in | What it does |
|---|---|---|---|
turnWatchdog.enabled | true | You, Project, Repository | Cancel an agent's turn when it has produced no output, tool call or permission request for longer than the idle timeout. Catches agents wedged on a hung model server or a stuck MCP server. |
turnWatchdog.idleTimeoutMinutes | 10 | You, Project, Repository | Minutes of silence inside a turn before the watchdog cancels it. Local models on slow hardware may need a higher value. From 2 to 120. |
turnWatchdog.restartAfterCancel | true | You, Project, Repository | If the cancel is ignored, kill the agent process and restart it, resuming the same conversation. |
Updates
| Setting | Default | Set in | What it does |
|---|---|---|---|
updates.allowUnsigned | false | You | Install an update whose Authenticode signature does not check out. Off, and only worth turning on for unsigned builds from your own update source — every such install is logged as a warning. |
updates.channel | stable | You | Which versions the app updates to. An update must match the channel; the app only installs an older version when you switch channel. MOJOUP_DISABLE_AUTO_UPDATE=1 in the app's environment turns updates off on this machine. One of: stable (Released versions only.), nightly (Nightly builds of what will become the next version, as they come out. Switching back to stable offers the newest release, even when it is older than the nightly you have.). |
updates.checkIntervalHours | 24 | You | How often the app checks for a new version, in hours. 0 turns the periodic check off; the Updates pane can still check on demand. From 0 to 720. |
updates.source | You | Where the app looks for updates. Empty uses the Mojo Up portal. A folder — a share, a synced directory, C:\builds — holding your installers and a latest.json beside them, or an http(s) URL serving the same document. Use this to test a build before it is published. |
Usage
| Setting | Default | Set in | What it does |
|---|---|---|---|
usage.liveLimits | true | You | Ask each signed-in provider for its own usage limits (Claude Code's five-hour and weekly windows, an OpenRouter balance) using the credential that CLI already stores. Turn off to show only what this workbench metered itself. |
Workspace
| Setting | Default | Set in | What it does |
|---|---|---|---|
workspace.activeFolder | You | Not used by the desktop app, which opens one repository per window; kept so a value from an older settings file is recognised and ignored. |
Worktrees
| Setting | Default | Set in | What it does |
|---|---|---|---|
worktrees.linkIgnoredFiles | [] | You, Project, Repository | Files git ignores that a new agent worktree should share with your own checkout, as globs (".env*", "config/local.json"): each match is linked into the worktree. A name without a slash matches at any depth. Files git tracks are never replaced. |
worktrees.setupBlocking | true | You, Project, Repository | Hold an agent's work until its worktree's setup has finished. When setup fails the task offers Start anyway and Retry. Off: the agent starts at once and setup runs beside it. |
worktrees.setupCommands | [] | You, Project, Repository | Commands to run, in order, in every new agent worktree before the agent works in it — installing dependencies, for example ("npm ci"). Each runs in the worktree without a shell unless it uses shell syntax (pipes, &&, variables), which runs through /bin/sh or cmd.exe. Output goes to a log the task links to. They run on your computer, so only commit commands you would run yourself. |
worktrees.setupTimeoutMinutes | 10 | You, Project, Repository | How long one worktree setup command may run before it is stopped and the setup counts as failed. At least 1. |