o4 command. Run o4 with no command to start an interactive session in the current directory. The subcommands manage sessions, MCP servers, plugins, workspace trust, the daemon, watch mode and evaluations without starting a session.
Every command also accepts -h or --help. o4 help <command> prints the same help as o4 <command> --help.
Global options
These options go before the command, for exampleo4 -m anthropic:claude-sonnet-4-6 or o4 -C ~/code/api watch. Most of them affect how a session starts, so they matter for plain o4, for o4 resume, and for print mode.
Model and prompt
string
The model to start with. Accepts
provider:model (anthropic:claude-sonnet-4-6), provider/model (anthropic/claude-sonnet-4-6), or a bare model ID or name (claude-sonnet-4-6). A model given here must exist: if o4 can’t find it, it exits with a not found error that suggests o4 --list-models. Without -m, o4 uses your saved model. See Choosing a model.string
Runs the prompt once without the interface, prints the reply, and exits. See Print mode and scripting for permissions, exit codes and output.Two prompts print a JSON report instead of calling the model:
o4 -p "/context --json" and o4 -p "/stats --json". See Context and cost.string
Text added to o4’s system prompt for this session. It doesn’t replace the built-in prompt.
string
o4 picks a prompt profile for each model automatically. This option forces one for the session:
modern-minimal, modern-guided, legacy-guided or local-defensive. See Reasoning and prompt profiles.string
The reasoning effort to start with. The help lists
default, low, medium, high and max. o4 also accepts minimal, extra-high (or xhigh) and ultra where the model supports them. default leaves the choice to the provider. Without this option, o4 uses the reasoning value from your settings. An unknown value stops o4 with Unknown reasoning level. See Reasoning and prompt profiles.boolean
Kept for compatibility. A prompt given with
-p is what starts print mode, so o4 --print -p "..." behaves like o4 -p "...", and o4 --print alone starts the normal interface.boolean
Prints the full system prompt o4 would send, followed by a
--- Prompt diagnostics --- block with the prompt profile, how it was selected, a hash, and the size in bytes and estimated tokens. Then it exits. It doesn’t call the model. Combine it with -m, --prompt-profile or -s to see their effect.boolean
Streams the model’s reasoning output as it arrives. It works in print mode, where the reasoning goes to stderr so stdout keeps only the reply. The full-screen interface ignores it.
boolean
Lists every registered model, grouped by provider, with its context window, maximum output tokens, input types and whether it supports reasoning. Then it exits. It doesn’t need an API key.
Interface and setup
boolean
Turns on screen reader output for this session, the same as the screen reader setting. See Themes and display.
boolean
Skips the first-run setup wizard. If no model is configured and you don’t pass
-m, o4 exits with No default model configured and tells you to run without --no-onboarding or to pass -m.Permissions and sandbox
string
Sets how tool calls are approved for this run:
ask, accept-edits, plan, review, auto or bypass. See Permissions. Print mode starts in auto when you don’t set this.string
Fixes the sandbox for shell commands from the model for this run:
With
read-only or workspace-write, o4’s file tools also refuse paths outside those directories. See Sandbox.boolean
Runs enabled hooks even if you haven’t trusted them, for this run only. Use it only in automation that already checks where its hooks come from. See Hooks.
Directories
When you pass-C or --add-dir, o4’s file tools only read and write inside the working root and the added directories. Shell commands are limited to those directories only with --sandbox workspace-write. See Sandbox.
path
Runs o4 as if you started it in this directory. It applies to sessions and to commands such as
o4 -C ~/code/api watch. The directory must exist. o4 refuses directories that overlap protected credential locations such as ~/.ssh. --cwd is a hidden spelling of the same option. When o4 restarts itself to resume a session, it passes the directory you chose with --cwd, so it doesn’t ask again.path
Adds a directory the agent may write to, next to the working root. Repeat it for several directories. A relative path is resolved against the working root. Directories that overlap protected credential locations are refused with
overlaps a protected credential location.Removed flags
Older approval flags now stop o4 with a message that names the replacement:o4 resume
Resume a saved session.
Without an ID,
o4 resume opens the session picker. When no terminal is attached, it prints the list of sessions from every directory instead. With an ID, it resumes that session directly. If the session started in a different directory, o4 asks which directory to use, unless you chose an “always” answer before or pass -C. See Resuming in a different directory. Global options such as -m still apply. The resumed session runs on the model you pass with -m, or on your default model, not on the model it last used; see Sessions.
o4 sessions
Manage sessions. A subcommand is required.o4 sessions list
List recent sessions from the current checkout, with ID, model, title, directory and last update.o4 sessions list --all.
o4 sessions delete
Delete a session.Deleted session <id> even when no session has that ID. See Sessions for what deleting removes.
o4 mcp
Manage MCP servers. With no subcommand,o4 mcp runs o4 mcp list. See MCP servers.
o4 mcp add
Add an MCP server from the MCP registry.
Without
--global, o4 adds the server to the project’s .o4/.mcp.json, which needs a trusted workspace. In an untrusted workspace the command stops and asks you to run o4 trust or pass --global. With --global, the server goes into ~/.o4/.mcp.json. If the server needs environment variables, o4 lists them after adding it.
o4 mcp remove
Remove an MCP server.
o4 removes the server from the project config if it’s there, otherwise from the global config.
o4 mcp list
List configured MCP servers with their transport. It only reads the config files and doesn’t start the servers, so theStatus column always shows stopped and Tools shows ?.
o4 mcp search
Search the MCP registry atregistry.modelcontextprotocol.io. Shows up to 20 results, each with its name, a short description and its transport.
o4 mcp restart
Restart MCP servers.
Servers only run inside a session, so this command fails from the shell with
Server restart is only available within an interactive session. Use /mcp restart [name] in a session instead.
o4 plugin
Manage plugins and marketplaces.o4 plugins works too. With no subcommand, o4 plugin runs o4 plugin list. See Plugins and marketplaces.
o4 plugin install
Install a plugin.
Global plugins go into
~/.o4/plugins, and project plugins into the project’s .o4/plugins. Installing a project plugin needs a trusted workspace.
o4 plugin remove
Remove an installed plugin.o4 plugin list
List installed plugins with their version, scope (global or project) and description. It warns about project plugins it ignored because the workspace isn’t trusted.
o4 plugin marketplace
Manage plugin marketplaces. With no subcommand, it runso4 plugin marketplace list. Marketplaces are stored under ~/.o4/marketplaces.
o4 watch
Watch the workspace and run its configured check after each change. When the check fails, o4 offers to fix it. See Watch mode.
Without
-c, o4 uses command from the [watch] section of the project’s .o4/config.toml (only in a trusted workspace). If that isn’t set, it picks a command from the project files:
o4 trust
Trust the current workspace. This enables its project hooks and MCP servers, and the rest of the project configuration covered in Workspace trust. Trust also covers the directories inside it.o4 untrust
Revoke trust for the current workspace.o4 update
Update o4 to the latest release. o4 downloads the release archive for your platform, checks it against the published checksum, and replaces the binary you ran. See Update o4.
Without
--version, o4 never replaces a build that is newer than the latest release. If the binary is in a Homebrew Cellar, o4 doesn’t replace it and tells you to run brew upgrade open4rena/tap/o4. Open sessions keep using the old binary until you restart them.
o4 daemon
Manage the o4 daemon, a long-running background process that hosts sessions for clients connecting over a Unix socket. A subcommand is required. The daemon is available on macOS and Linux. See The o4 daemon.status exits with 0 when the daemon is running and 3 when it isn’t, so scripts can check it without parsing the output. stop also exits with 3 if the daemon wasn’t running. start waits up to 5 seconds for the daemon to answer; if it doesn’t, the error points to the daemon log at ~/.o4/daemon/daemon.log. A hidden serve subcommand runs the daemon in the foreground; see Run in the foreground.
o4 eval
Run and report coding-agent evaluations. A subcommand is required. o4 reads the task corpus from theevals directory in the current directory and records runs in .o4/evals.db, so run these commands from the repository that holds the corpus. See Evaluations.
o4 eval run
Run selected corpus tasks against one or more models.
o4 skips a model reference it can’t resolve, with a warning, and runs the rest. If nothing matches your selection, it stops with
no tasks matched the requested eval selection.
o4 eval paired
Run an automatic control arm and amodern-minimal candidate arm, to compare the automatic prompt profile with modern-minimal.
o4 eval report
Render a recorded eval run.o4 eval summary
Summarize autonomy results by o4 version: tasks attempted and completed, how many finished without intervention, and the rates.o4 eval list
List eval corpus tasks.Exit codes
Commands exit with0 on success and 1 on an error, printing Error: ... to standard error. An unknown flag, an invalid value or a missing subcommand exits with 2. o4 daemon status and o4 daemon stop use 3 for “not running”. See Print mode and scripting for print mode.