Approval
Each tool has a default approval level. It decides what happens in the defaultask permission mode:
Other modes change this:
accept-editsalso runswrite,editandnotebook_editwithout asking.reviewhas the session model review each call that would ask, and asks you only if the review doesn’t approve it.autoruns everything except package installs that run install-time scripts.bypassruns everything.planblocks everything that isn’t “Never asks”.
Files
The file tools work inside the project directory and your home directory. They refuse credential locations in your home directory, such as~/.ssh, ~/.aws, ~/.config/gh, ~/.netrc and o4’s own ~/.o4/settings.json. When you pass -C, --add-dir, --sandbox read-only or --sandbox workspace-write, they work only inside the working directory and the added directories, and --sandbox read-only also refuses every write. See Sandbox.
read
read
file_path(required): absolute path to the file.offset: 1-based line to start from.limit: number of lines to read. Default 2000.
write
write
file_path(required): absolute path to the file.content(required): the full new content.
undo or /undo.edit
edit
file_path(required): absolute path to the file.old_string(required): the text to replace. It must match exactly one place in the file unlessreplace_allis set.new_string(required): the replacement.replace_all: replace every occurrence.
notebook_edit
notebook_edit
notebook_path(required): path to the.ipynbfile.new_source(required): the new cell content.cell_id: the cell to edit. Leave it out to insert a new cell.cell_type:codeormarkdown.insert_after: insert the new cell after this cell ID.
Search
glob
glob
pattern(required): the glob pattern.
grep
grep
pattern(required): the regular expression.path: file or folder to search. Defaults to the current directory.glob: only search files matching this pattern, such as*.rs.case_insensitive: ignore case.context: lines of context around each match, up to 100.output_mode:content(the default),files_with_matchesorcount.
.git, node_modules, binary files and files over 1 MB, respects .gitignore, and gives up after 30 seconds. It uses rg (ripgrep) when it’s installed in a standard location such as /opt/homebrew/bin or /usr/bin.ls
ls
path(required): the folder to list.
git_info
git_info
subcommand(required):status,difforlog.ref: a ref or range, such asHEAD~3ormain..feature, fordiffandlog.path: limitdiffto a file or folder.count: number of commits forlog. Default 10.
Shell and code execution
bash
bash
command(required): the command to run.timeout: milliseconds. Default 600,000 (10 minutes), maximum 1,800,000 (30 minutes).0turns the timeout off.working_directory: folder to run the command in.run_in_background: start the command as a background task and return a task ID right away. For dev servers, watchers and other long-running commands.justification: one sentence shown on the approval prompt explaining why the command is needed.
repl
repl
language(required):python(runspython3) ornode.code(required): the code to run.
test_run
test_run
pattern: only run tests whose names match.file: run the tests for one file.timeout: seconds. Default 300, maximum 1,800;0turns it off.impacted_only: run only the tests affected by the current changes, falling back to the full suite when unsure.impact_set: a precomputed set of impacted tests to use withimpacted_only.
Cargo.toml, package.json, pyproject.toml, setup.py or go.mod, and returns each test’s name, status, duration, location and failure message.format
format
file_path(required): the file to format.timeout: milliseconds. Default 120,000.
Web
fetch
fetch
url(required): the URL.
web_fetch
web_fetch
url(required): a public URL.prompt(required): the question to answer about the page.
web_search
web_search
query(required): the search terms.count: number of results. Default 5, maximum 10.
brave key in /config > Providers or set BRAVE_API_KEY, otherwise Tavily with a tavily key or TAVILY_API_KEY, otherwise DuckDuckGo on a best-effort basis. See Environment variables.fetch and web_search follow the sandbox’s host rules, so in the guarded tier a request to a host that isn’t allowed prompts you first. See Sandbox.
Planning and goals
See Plan mode and Goals.
Todos and background tasks
See Todos and background tasks.
Agents and teams
agent
agent
prompt(required): the task for the subagent.agent: the agent definition to use, such asExplore,Plan,Generalor one of your own. Leave it out to fork the current conversation.description: a short label for the display.model: aprovider:modelreference to use instead of the current model.background: run it in the background and return a task ID right away.name: a name other agents can use to reach it withsend_message.isolation:worktreeruns it in its own git worktree.structured_output_schema: a JSON Schema. The subagent then gets aStructuredOutputtool and must call it once with a result that matches.contract: a task contract withtask,context,done_when(a shell command and the result that proves the work is done),touch_only(the files it may change) andon_failure. Whentouch_onlynames more than one file, o4 checksdone_whenitself by default.verify: a shell command that replaces that check, orfalseto turn it off. A failing check goes back to the subagent, up to 2 retries.
campaign
campaign
description(required): the overall goal.workers(required): the workers, each with arole(the agent to use) and atask, and optionally amodel.strategy:parallel(the default),sequential,map_reduceorcollaborative.timeout_secs: a time limit per worker. No limit if left out.auto_approve: accepted, but o4 0.2.74 doesn’t use it.
brief
brief
summary(required): the report, up to 100,000 characters.files: paths to attach, up to 1 MB each and 5 MB in total.
Code intelligence
codebase_query takes an operation (such as callers_of, find_symbol or changed_together) and a target. The index lives in .o4/index/codebase.db and is built in the background when a session starts. lsp takes an operation, a filePath, and a 1-based line and character. It needs a language server for that file type installed; by default o4 looks for rust-analyzer, typescript-language-server, pyright-langserver and gopls. In 0.2.74 o4 doesn’t send the server the initialize request, so standard servers such as rust-analyzer answer with an LSP error -32002. See Code intelligence and Language servers and formatters.
Memory
Each memory tool takes a
scope: project (the default, stored in .o4/memory/memory.db) or global (stored in ~/.o4/memory/global.db). The global store is available only in a trusted workspace. See Memory.
Skills
See Skills.
MCP
If your built-in and MCP tools add up to more than 64, o4 doesn’t send the MCP tools to the model up front. It adds
tool_search instead, and the model loads MCP tools as it needs them. See MCP servers.
Worktrees
Other tools
CodeMode
See CodeMode.
Where each tool is available
Not every tool is offered in every kind of session:- Plan mode. The model can only use
read,glob,grep,ls,fetch,task_create,task_update,task_list,enter_plan_modeandexit_plan_mode. Other tools are hidden from it, and a call to one is blocked. See Plan mode. - Print mode (
o4 -p). There’s no one to ask, soask_user_questionisn’t offered, and neither areundo,todo_write, thetask_*tools, theplan_*,checkpoint_*and goal tools,lsp,format,list_mcp_resources,read_mcp_resourceandtool_search. MCP server tools are still offered. See Print mode and scripting. - Subagents. A subagent gets
read,glob,grep,ls,write,edit,bash,fetch,web_search,git_infoand your MCP server tools, narrowed by its agent definition, plusagentwhen its definition allows it, andStructuredOutputwhen it was started with astructured_output_schema. Inside a subagent, MCP server tools ask every time. A subagent started without anagenttype, a fork, gets the same tools as the session that started it. See Subagents. - Daemon runs. When a client of the o4 daemon starts a run with an output schema, the model also gets a
structured_outputtool whose input is that schema. A call that doesn’t match the schema returns an error to the model, and a run that ends without a valid call fails withmodel did not produce valid structured output. - Configuration.
formatneeds at least one formatter, andtool_searchappears only when MCP tools were held back.
Plugin tools and turning tools off
Installed plugins can add their own tools. Plugin tools ask for approval every time, and a plugin tool with the same name as a built-in tool isn’t added. To leave tools out of the model’s tool set in a project, built-in or MCP, list their names underdisabled_tools in the [scout] section of .o4/config.toml; /scout can write this for you. This applies to the interactive interface. See the configuration reference.