config.toml (policy and behavior), settings.json (preferences) and display.json (display options /config saves). For where the files live, which one wins, and how /config edits them, see Configuration files.
All keys are optional. Anything you leave out uses the default shown.
config.toml
config.toml can live in four places. From lowest to highest precedence:
~/.o4/config.toml, your user file..o4/config.tomlin the project..o4/config.local.tomlin the project.~/.o4/managed/config.toml, the managed file for policy an organization sets.
o4 ignores keys it doesn’t know. If a file isn’t valid TOML, or a known key has the wrong type, o4 stops at startup with an error that names the file.
Top-level keys
string
The default model, as a model reference such as
anthropic:claude-opus-5. model in settings.json takes priority when both are set, and -m overrides both. See Choosing a model.boolean
default:"false"
When o4 restores a plan at startup, keep it without asking Continue or Abandon. o4 restores the linked plan of a session you resume, and on a new session a plan marked
approved or executing. See Plan mode. On if any config file turns it on.permissions
Permission rules allow, ask about, or deny tool calls by pattern. Rules from every file are combined. See Permissions for the pattern syntax and precedence.sandbox
Settings for the sandbox around shell commands. List values are combined across files.hooks
Hooks run a shell command or send an HTTP request at points in a session. Each[[hooks]] entry is one hook. Hooks from every file are combined and run in this order: ~/.o4/managed/config.toml, .o4/config.local.toml, .o4/config.toml, ~/.o4/config.toml, then any hooks block in the project’s .o4.md. The first hook that blocks stops the rest. See Hooks for the events and what hooks can return.
keybindings
Remaps TUI shortcuts. Each key is an action name and each value is a key:alt-<key>, shift-tab, f1 to f12, or ctrl-t. Other Ctrl combinations are reserved. The new key replaces the action’s default key. An unknown action or key shows a warning at startup and is skipped. When two files set the same action, the higher-precedence file wins.
cycle_reasoning, steer_current_task, edit_last_queued, resume_queue, cycle_approval, toggle_plan_mode, new_tab, close_tab, next_tab, prev_tab, cycle_model, undo_last_change, toggle_diff_pane, toggle_radar_pane, toggle_task_board, toggle_todo_list, open_transcript_reader, toggle_time_machine, cycle_sandbox_tier, repeat_with_correction, panic_pause, approve_pending and deny_pending. See Keyboard shortcuts for each action’s default key.
watch
string
The check command
o4 watch runs after files change, for example cargo test. o4 watch --command overrides it. When unset, o4 picks a command from the project type. Read only from the project’s .o4/config.toml, and only in a trusted workspace.scout
/scout suggests which tools, MCP servers and skills a project needs, and applying its suggestions writes this section to the project’s .o4/config.toml. See Code intelligence. You can also edit it by hand. The interactive UI applies it; print mode (-p) ignores it.
/scout also writes first_run, profile_hash and last_run here. Nothing reads them in 0.2.74. The section is taken whole from the highest-precedence file that has one; [scout] tables from different files aren’t combined.
router
The model router keeps a session on one model and switches to a fallback after a provider error it can retry./router setup --yes writes this section for you in ~/.o4/config.toml, or in the project’s .o4/config.toml with --project; without --yes it only shows what it would write. It won’t write when a higher-precedence file already has a [router] section. /router disable sets enabled = false. On the Providers tab of /config, Router setup shows the same preview as /router setup without writing anything, Router disable (shown instead while the router is on) runs /router disable, and Router status runs /router status. o4 reads this section when a session starts, so changes take effect in the next session. Model router and fallback explains how the router picks and switches models.
o4 checks these values when it loads the config and writes a warning to
~/.o4/o4.log for each problem. An out-of-range context_safety_ratio or max_fallback_attempts is replaced with the default. Unknown fallback_on entries are dropped, and a list with none left means all four. A capacity entry below 1 is dropped. Each key is taken from the highest-precedence file that sets it; capacity entries are combined by provider.
daemon
Settings for the o4 daemon. Read only from~/.o4/config.toml and ~/.o4/managed/config.toml, and a key in the managed file wins; o4 ignores this section in project files. enabled and idle_unload_secs are accepted but have no effect (see Keys that have no effect).
resume
string
Which directory a resumed session runs in when you resume it from a different directory:
session (the session’s own directory) or current (where you are now). o4 saves this when you pick one of the “Always use…” choices in the resume prompt. When unset, o4 asks. Read only from ~/.o4/config.toml. See Sessions.codemode
CodeMode is experimental and off by default. It gives the model anexec tool that runs JavaScript, in which o4’s other tools are available as functions. Each call from inside a program goes through the same permission checks as a direct tool call. Read only from ~/.o4/config.toml and ~/.o4/managed/config.toml, and a key in the managed file wins; o4 ignores this section in project files, with a warning in the log. See CodeMode for how it works and which providers support it.
A limit set to
0 or above its maximum is replaced with the default, with a warning in the log.
Keys that have no effect
o4 0.2.74 accepts theseconfig.toml keys without an error, but nothing uses them. Setting them changes nothing:
settings.json
~/.o4/settings.json holds your preferences. /config and the setup wizard write it, and you can edit it by hand. In a trusted workspace, a project’s .o4/settings.json overrides it value by value (see Configuration files); api_keys, lsp_servers and formatters are combined by name instead, with the project’s entry winning. There is no managed settings.json. If a file isn’t valid JSON, or a value has the wrong type (such as "yes" for a boolean) or an unknown choice, o4 ignores that whole file and uses the defaults. /config always saves to ~/.o4/settings.json.
The last column says whether a row in /config changes the key.
General
Providers and API keys
Older versions stored keys in
anthropic_api_key, openai_api_key, google_api_key, xai_api_key, deepseek_api_key and ollama_api_key. o4 still reads them when api_keys has no key for that provider, but new keys go in api_keys. Clearing a key with the API key row also removes the old field. See Providers and API keys.
Appearance
Notifications
Context and background work
No/config row changes these keys. The setup wizard sets auto_compact_enabled. The three auto_compact_* keys apply in the interactive UI only.
Tools
The LSP servers and Formatters rows on the Tools tab of/config show these keys but can’t change them; edit settings.json by hand. A trusted project’s .o4/settings.json can add entries to both, and a project entry replaces a user entry with the same name.
object
Language servers for code intelligence, keyed by a name you choose. Each entry has
command (required), args (a list) and extensions (a list of file extensions without the dot, such as ["rs"]). An entry with an empty command or no extensions is ignored. Once the map has any entry, even an ignored one, it replaces the built-in servers (rust-analyzer, typescript-language-server, pyright-langserver and gopls). See Language servers and formatters.object
Formatters the model can run with its
format tool, keyed by a name you choose. Each entry has command (required), args and extensions, like lsp_servers. o4 runs command, then args, then the file’s path.Written by o4
o4 writes these keys itself. You don’t need to set them.settings.json keys with no effect
o4 0.2.74 reads these keys but they change nothing:display.json
~/.o4/display.json holds display preferences that /config saves separately from settings.json. It exists only in your home folder; there is no project or managed display.json. Each time you change one of these rows, /config writes all four keys.
If you write the file by hand, include show_timestamps, show_thinking and animations. If one of them is missing, or the file isn’t valid JSON, o4 ignores the whole file and uses the defaults. screen_reader may be left out.