Keeping up with everything coding agents can do is hard.
So we mapped it for you.
Work in progress. Mapped by agents from official docs, so some entries may be wrong.
| Feature | H | |||||
|---|---|---|---|---|---|---|
| Conversation and interaction | ||||||
| Prompt input and editing | ||||||
| Multiline input#Insert line breaks without sending the prompt | ||||||
| Paste multiline text as a single block#Paste multi-line text as one block instead of line by line | ||||||
| Preview large pasted text#Collapse large pastes into a short summary instead of filling the screen | ||||||
| Edit prompts in an external editor#Compose long prompts in your own text editor | ||||||
| Modal input editing#Vim-style modes for editing the prompt | ||||||
| Clear an unsent prompt#Clear what you've typed without closing the session | ||||||
| Suggestions and input history | ||||||
| Command autocompletion#Autocomplete commands as you type them | ||||||
| Accept an input suggestion#Accept a suggested completion with one keypress | ||||||
| Reuse a previous prompt#Pull a past prompt back into the input box | ||||||
| Search prompt history#Search through prompts you've sent before | ||||||
| Control a running agent | ||||||
| Interrupt execution#Stop the agent mid-task | ||||||
| Steer the current turn#Redirect the agent's current task without stopping it | ||||||
| Interrupt and redirect to a new task#Cancel the current task and start a new one right away | ||||||
| Choose how incoming messages affect running work#Decide whether new messages queue, steer, or interrupt ongoing work | ||||||
| Let the agent ask you questions with answer options mid-task#The agent pauses with a multiple-choice question instead of guessing. | ||||||
| Message queues | ||||||
| Queue steering messages for current work#Line up guidance to apply once the current step finishes | ||||||
| Queue follow-up prompts after current work#Line up a prompt to run after the agent finishes everything | ||||||
| Configure steering-message delivery#Choose whether queued guidance sends all at once or one at a time | ||||||
| Configure follow-up delivery#Choose whether queued follow-ups send all at once or one at a time | ||||||
| Return a queued message to the editor#Pull a queued message back out for editing | ||||||
| Restore queued messages after interruption#Get queued messages back after canceling a task | ||||||
| Side interactions | ||||||
| Open a side conversation without interrupting the main one#Branch off a quick question without derailing the main thread | ||||||
| Run a shell command directly from the composer#Run shell commands straight from the prompt box | ||||||
| Copy the last response to the clipboard#Grab the agent's latest answer with one command | ||||||
| Background work | ||||||
| Detach the current session and free the terminal#Send the session to the background and get your terminal back | ||||||
| Start a separate background session without stopping the current one#Kick off a separate task in the background while you keep working | ||||||
| Terminal interface | ||||||
| Stream tool output#Watch tool output live instead of waiting for it to finish | ||||||
| Display model and context status#Show the current model and how much context is left | ||||||
| Customize keyboard shortcuts#Remap keyboard shortcuts to your liking | ||||||
| Switch between regular and fullscreen interfaces#Toggle between a compact view and a fullscreen display | ||||||
| Screen-reader-friendly output#Plain text output designed for screen readers | ||||||
| Start an interactive chat session in the terminal#Open a full-screen conversation with the agent instead of a one-shot run. | ||||||
| Open built-in help and the command list#Show help, flags and available commands without leaving the terminal. | ||||||
| Display and appearance | ||||||
| Show or hide the model's reasoning#Toggle whether thinking blocks appear in the transcript. | ||||||
| Show or hide tool execution details#Collapse or expand the details of each tool call in the transcript. | ||||||
| Show line numbers in displayed code#Toggle line numbers in rendered code blocks. | ||||||
| Show agent status in the terminal window title#The terminal title shows whether the agent is working, waiting or done. | ||||||
| Match the interface to the terminal's light or dark colors#Detects the terminal background and adapts the interface colors. | ||||||
| Switch the interface color theme#Pick a color theme for the terminal interface. | ||||||
| Choose how diffs are displayed#Switch between diff layouts such as split and unified. | ||||||
| Turn mouse support on or off in the terminal#Click and scroll in the interface, or leave the mouse to the terminal. | ||||||
| Play sounds for agent events#Audible cue when the agent finishes or needs attention. | ||||||
| Show a keyboard shortcut guide#An overlay lists the available shortcuts as you type. | ||||||
| Planning, tasks and code review | ||||||
| Planning before making changes | ||||||
| Switch the current session to plan mode#Switch to a mode that plans before touching any code | ||||||
| Use a separate planning primary agent#Delegate planning to a mode that can't make changes | ||||||
| Submit a plan for approval and exit plan mode#Hand off a finished plan for approval before work starts | ||||||
| Work toward a standing goal across turns#Give the agent a goal it keeps pursuing over many turns until done | ||||||
| In-session task tracking | ||||||
| Create a task#Add a task to the session's tracked to-do list | ||||||
| List tasks and inspect task details#See all tracked tasks and drill into one | ||||||
| Update task status, dependencies and description#Edit a task's status, dependencies, or description | ||||||
| Targeted code review | ||||||
| Review uncommitted changes#Review changes you haven't committed yet | ||||||
| Review a diff against a base branch#Review everything that changed since a base branch | ||||||
| Review a specific commit#Review the changes in one specific commit | ||||||
| Provide custom instructions for non-interactive review#Tell a one-off review what to focus on | ||||||
| Review pull requests from a CI mention#Mention the agent on a PR or MR to get an automated review | ||||||
| Review the agent's changes in an interactive diff view#Browse every file the agent changed this session and inspect the diffs yourself. | ||||||
| Run a code review with a review agent#A command starts a review pass, e.g. for bugs or security. | ||||||
| Specialized working modes | ||||||
| Switch to a read-only mode that answers without editing files#Ask about the code or discuss options while the agent cannot change anything. | ||||||
| Switch to a dedicated debugging mode#A separate mode for diagnosing bugs, with its own prompts and checks such as confirming reproduction steps. | ||||||
| Git and pull requests | ||||||
| Keep an eye on a pull request and fix failing checks#The agent watches a PR, reads failing checks and review comments, and pushes fixes. | ||||||
| Split a large change into several smaller pull requests#The agent cuts one big diff into reviewable PRs. | ||||||
| Check out a pull request branch and start working on it#Fetch a PR by number and open a session on its branch. | ||||||
| Create branches, commit and push through built-in Git tools#Git operations run as dedicated agent tools rather than raw shell commands. | ||||||
| Post comments on pull requests#The agent writes review or status comments on a PR. | ||||||
| Mark agent-made commits and pull requests as agent-authored#Commits and PRs carry attribution to the agent; can be turned off. | ||||||
| Files, search and code understanding | ||||||
| Read and modify files | ||||||
| Read an entire file or a range#Read a file's contents, in full or a chosen range | ||||||
| Create a file or replace its entire contents#Create a new file or overwrite one completely | ||||||
| Replace an exact text match#Swap out one exact piece of text in a file | ||||||
| Apply a structured patch#Apply a set of file changes as a single patch | ||||||
| Edit individual Jupyter notebook cells#Edit individual cells inside a notebook | ||||||
| Format files automatically after the agent edits them#Runs built-in or custom formatters on every file the agent writes. | ||||||
| Project search | ||||||
| Find files by path pattern#Find files by matching their path or filename | ||||||
| Search file contents using text or regex#Search inside files for text or a pattern | ||||||
| Search code semantically rather than by literal match#Search code by meaning, not just exact wording | ||||||
| Include normally ignored files in project search#Opt specific ignored paths back into file search. | ||||||
| Language intelligence and diagnostics | ||||||
| Find a symbol definition through LSP#Jump straight to where a symbol is defined | ||||||
| Find symbol references through LSP#Find every place a symbol is used | ||||||
| Get symbol hover information#See type and doc info for a symbol on hover | ||||||
| Get a call hierarchy#See what calls a function and what it calls | ||||||
| Receive LSP diagnostics after writing or patching files#Catch type and lint errors right after a file changes | ||||||
| Find symbols across the workspace#Jump to functions or classes by name anywhere in the project | ||||||
| Use built-in language servers and add custom ones#Language servers start automatically for common languages; you can add or disable them. | ||||||
| List the symbols in a file through LSP#Outline of functions, classes and variables in one document. | ||||||
| Workspace folders | ||||||
| Choose the working directory for a run#Point the agent at a project folder without changing into it. | ||||||
| Work across several directories in one session#Add more project folders to the current session. | ||||||
| Save and reopen a named set of directories#Store a multi-folder workspace and load it later in one step. | ||||||
| Shell and process execution | ||||||
| Agent-invoked commands | ||||||
| Execute a shell command through an agent tool#Let the agent run shell commands on your behalf | ||||||
| Select the shell executable#Choose which shell program runs your commands | ||||||
| Prepend a shared prefix to shell commands#Automatically prepend setup text to every command run | ||||||
| Enter a sudo password privately for elevated commands#A masked prompt passes the password to the command without showing it to the model. | ||||||
| Long-running processes | ||||||
| Start a background command with a process or session ID#Launch a long-running command in the background with an ID to track it | ||||||
| List background processes#See every background command currently running | ||||||
| Check background process status#Check whether a background command has finished | ||||||
| Wait for a background process to finish#Pause until a background command completes | ||||||
| Read background process output#Read the output a background command has produced so far | ||||||
| Stop a background process#Stop a background command that's still running | ||||||
| Send input to a running process#Send keystrokes to a running background command | ||||||
| Inspect background terminals and recent output#See background terminals and their latest output at a glance | ||||||
| Stream background command output to the agent#Feed a long-running command's output to the agent as it arrives | ||||||
| Execution-policy checks | ||||||
| Test a command against execution-policy rules without running it#Check if a command would be allowed without actually running it | ||||||
| Sessions, history and recovery | ||||||
| Resume work | ||||||
| Resume the latest session#Jump back into your most recent session | ||||||
| Select a saved session from a list#Pick an old session to resume from a list | ||||||
| Resume a session by ID or name#Resume a specific past session by its ID or name | ||||||
| Resume a session in a headless run#Resume a past session when running non-interactively | ||||||
| Branch conversation history | ||||||
| Create a new session from the current conversation#Branch the current conversation into a new session | ||||||
| Create a new session from a selected earlier message#Start a new session from an earlier point in the conversation | ||||||
| Navigate history branches within one session file#Jump between different history branches inside one session | ||||||
| Create a background copy while the original conversation continues#Copy the conversation into a background session while the original keeps going | ||||||
| Fork a saved session into a new one#Branch an older session without continuing it in place | ||||||
| Archive and transfer | ||||||
| Archive a session without deleting its transcript#Tuck a session away without deleting its transcript | ||||||
| Restore an archived session to the active list#Bring an archived session back into your active list | ||||||
| Export a conversation in a human-readable format#Save the conversation as a readable text file | ||||||
| Export a machine-readable session for transfer#Save session data as a file you can move elsewhere | ||||||
| Import a compatible session file#Load a session file exported from elsewhere | ||||||
| Import conversation history from another product#Bring over recent chats from another tool | ||||||
| Back up and restore all local agent data#Save config, sessions and history to one archive and restore them later | ||||||
| Delete a saved session#Permanently remove a past session and its data | ||||||
| Share a conversation through a public link#Publish a session as a web page, revoke the link, or disable sharing entirely. | ||||||
| Restore an earlier state | ||||||
| Rewind the conversation without necessarily restoring files#Jump the conversation back to an earlier point | ||||||
| Restore a filesystem checkpoint#Roll files back to an earlier saved state | ||||||
| Rewind both the conversation and code changes#Roll back both the conversation and the code together | ||||||
| Redo a step you rewound#Bring back the conversation and file changes you just undid. | ||||||
| Start and organize sessions | ||||||
| Start a fresh session#Clear the conversation and start over, or create an empty chat and get its ID. | ||||||
| Rename a session#Give the current or a new session a custom title. | ||||||
| Name sessions automatically#A short title is generated from the conversation. | ||||||
| List saved sessions from the command line#Print sessions as a table or JSON without opening the interface. | ||||||
| Query the local session database from the terminal#Run SQL against stored sessions and messages, output as JSON or TSV. | ||||||
| Context and persistent instructions | ||||||
| Context inputs | ||||||
| Load persistent project instructions#Load standing instructions for a project automatically | ||||||
| Load instructions only for matching paths#Apply instructions only when matching files are touched | ||||||
| Import other files into an instruction file#Pull other files' contents into an instruction file | ||||||
| Append to the default system prompt#Add extra instructions on top of the built-in system prompt | ||||||
| Replace the default system prompt#Swap out the built-in system prompt entirely | ||||||
| Add files or folders to the prompt by mentioning or attaching them#@-mention with fuzzy search, a path in the prompt, or a --file flag adds the contents. | ||||||
| Attach other folders or Git repositories as named references#Declare external code by alias and let the agent browse and mention it. | ||||||
| Context size and compaction | ||||||
| Inspect context-window contents and usage#See what's filling up the context window | ||||||
| Manually compact history with additional instructions#Summarize the conversation on demand, with your own focus | ||||||
| Configure the automatic compaction threshold#Set when automatic history summarization kicks in | ||||||
| Set how much recent history remains uncompacted#Decide how much recent history stays out of the summary | ||||||
| Carry a summary from an abandoned branch into the new branch#Bring a summary of an abandoned branch into the new one | ||||||
| Drop old tool output from history to save tokens#Large past tool results are removed from context automatically. | ||||||
| Instruction scope and sources | ||||||
| Apply an instruction file only when you mention it#Rules that load on demand instead of always. | ||||||
| Apply instructions when the agent decides they are relevant#The agent reads a rule's description and loads it only when it fits the task. | ||||||
| Keep personal instructions that apply in every project#User-level rules loaded in all sessions. | ||||||
| Use team-wide instructions that admins distribute and enforce#Organization rules pushed to every member's sessions. | ||||||
| Generate project instructions from the codebase#The agent studies the repository and writes the instructions file for you. | ||||||
| Read instruction and skill files made for other coding agents#Picks up CLAUDE.md, .claude/skills or .codex/skills so existing setups keep working. | ||||||
| Long-term memory | ||||||
| Cross-session memory | ||||||
| Automatically accumulate notes from work#Automatically save useful notes as you work, for next time | ||||||
| Keep separate agent notes and a user profile#Keep notes about you separate from notes about the work | ||||||
| Read memory through an explicit tool#Look up saved memory through a dedicated command | ||||||
| Write a memory note through an explicit tool#Save a note to long-term memory through a dedicated command | ||||||
| Search stored memory#Search everything that's been remembered | ||||||
| Plug in an external memory provider#Store long-term memory in an external service or backend | ||||||
| Memory controls | ||||||
| Control use of existing memory separately from new memory generation#Turn using old memories on or off separately from saving new ones | ||||||
| Require approval for memory writes#Require a sign-off before a memory note gets saved | ||||||
| Review, approve or reject pending memory writes#Approve or reject memory notes waiting for review | ||||||
| Disable memory generation for sessions using external context#Skip saving memories for sessions pulling in outside context | ||||||
| Configure persistent memory for an individual subagent#Give one subagent its own persistent memory | ||||||
| Subagents and agent collaboration | ||||||
| Delegation | ||||||
| Launch a subagent with a separate context#Hand off work to a subagent with its own separate context | ||||||
| Delegate code search and exploration to a separate agent#Send codebase searching to a dedicated helper agent | ||||||
| Run a background subagent without blocking the parent#Run a subagent in the background without waiting on it | ||||||
| Restrict a subagent's available tools#Limit which tools a subagent is allowed to use | ||||||
| Limit concurrent child agents#Cap how many child agents can run at once | ||||||
| Limit delegation depth#Limit how many levels deep agents can delegate to each other | ||||||
| Limit child-agent iterations#Cap how many turns a child agent gets before stopping | ||||||
| Switch between the main session and subagent sessions#Jump into a subagent's own session to watch or steer it, then back | ||||||
| Define custom subagents#Create your own subagents with their own instructions, tools and model | ||||||
| Choose or cycle the primary agent for a session or run#Switch between built-in primary agents (e.g. build and plan) or pick one per run. | ||||||
| Delegate browsing to a built-in browser subagent#A specialist agent drives the browser while the main agent keeps coding. | ||||||
| Research dependency source code in a managed cache#A built-in agent fetches and reads the source of libraries you depend on. | ||||||
| Customize a subagent's color or hide it from autocomplete#Control how custom agents appear in the interface. | ||||||
| Control which subagents an agent may invoke#Allow, ask or deny delegation per subagent. | ||||||
| Collaborative orchestration | ||||||
| Run a team of interacting agents#Run several agents that coordinate with each other on one task | ||||||
| Parallelize large repository changes into work units#Split a large change across a repo into parallel work units | ||||||
| Create child tasks in a managed queue#Spawn child tasks into a shared queue | ||||||
| Block a task until the user responds#Pause a task and wait for a human answer before continuing | ||||||
| Complete a task with a structured handoff#Finish a task and pass along results and follow-ups | ||||||
| Models and providers | ||||||
| Model selection | ||||||
| Switch models in an interactive session#Change which model you're talking to mid-session | ||||||
| List available models#See which models you can use, in the TUI or from the terminal | ||||||
| Limit the model list used for quick switching#Trim which models show up when cycling through them quickly | ||||||
| Set reasoning or thinking effort#Trade speed for deeper reasoning on harder problems | ||||||
| Configure a fallback model chain#Automatically switch models if the current one is unavailable | ||||||
| Define short aliases for models#Refer to models by your own short names | ||||||
| Choose a faster or cheaper serving tier#Trade speed and price by switching the service tier | ||||||
| Run the model with an extended context window#A mode that trades cost for the largest available context. | ||||||
| Let the tool pick a model for each request automatically#An automatic setting routes each request to a suitable model. | ||||||
| Set a default model for new sessions#The model every new session starts with. | ||||||
| Choose a model for a single run#A flag or provider/model string picks the model for one invocation. | ||||||
| Backend connections | ||||||
| Configure a custom endpoint or provider#Point the CLI at your own API endpoint or provider | ||||||
| Use a local model server#Run models on your own machine instead of the cloud | ||||||
| Register or override a provider through an extension#Add or replace a model provider via a plugin | ||||||
| Control routing across an aggregator's upstream providers#Choose which backend providers handle requests through a routing service | ||||||
| Use your own API key from a model provider#Bill model usage to your own provider account instead of the tool's plan. | ||||||
| Choose from many hosted model providers#Dozens of providers available out of the box. | ||||||
| Allow or block specific model providers#Enable only the providers you want, or deny some by policy. | ||||||
| Refresh the model catalog from its online source#Update the cached list of models and prices. | ||||||
| Model parameters and presets | ||||||
| Tune model parameters such as temperature and verbosity#Set sampling and provider-specific options per agent or model. | ||||||
| Use a separate lightweight model for small tasks#Titles and other minor jobs run on a cheaper model. | ||||||
| Define named variants of the same model#Reusable presets of one model with different options. | ||||||
| Tools and MCP | ||||||
| Connect tool servers | ||||||
| Connect a local MCP server over stdio#Add a tool server that runs as a local process | ||||||
| Connect a remote Streamable HTTP MCP server#Add a tool server reachable over the network | ||||||
| Authenticate an MCP server with OAuth#Sign in to a tool server without leaving the terminal | ||||||
| Disable a server without deleting its configuration#Turn off a tool server temporarily while keeping its settings | ||||||
| List servers and their status#See which tool servers are connected and working | ||||||
| Install MCP servers from a catalog#Browse a catalog of tool servers and install one with a command | ||||||
| Reload MCP servers without restarting the session#Pick up tool-server config changes while the session keeps running | ||||||
| Connect a remote tool server over server-sent events#Legacy SSE transport for remote servers. | ||||||
| Debug a tool server's connection and sign-in#A command diagnoses why a server fails to connect or authenticate. | ||||||
| Sign out of a tool server#Remove stored credentials for a connected server. | ||||||
| Approve project tool servers before they run#Servers defined by a project stay off until you approve them. | ||||||
| Restrict which tool servers members may use#Admins allowlist servers and control user-added ones and their network access. | ||||||
| MCP capabilities | ||||||
| List a server's tools and arguments#See what actions a tool server offers and what inputs they take | ||||||
| Search and load deferred tools on demand#Load extra tools only when they're actually needed | ||||||
| Restrict specific tools from a connected server#Limit which of a tool server's actions the agent can use | ||||||
| List server resources#See what files or data a tool server makes available | ||||||
| Read a resource by URI#Pull a specific file or data item from a tool server | ||||||
| Invoke a server-provided prompt#Run a ready-made prompt supplied by a tool server | ||||||
| Show interactive views returned by tool servers#Tool servers can render UI in the session, not just text. | ||||||
| Let a tool server ask you for missing information#A connected server requests input mid-call and the agent shows the prompt. | ||||||
| Receive and analyze images returned by tool servers#Images from tool results are shown and passed to the model. | ||||||
| Share workspace boundaries with tool servers#Servers learn which folders they may work in. | ||||||
| Skills, commands and extensions | ||||||
| Reusable instructions | ||||||
| Create a user-invoked prompt template#Save a reusable prompt you can trigger by name | ||||||
| Discover skills and load their contents on demand#Load extra instructions automatically only when a task needs them | ||||||
| Explicitly invoke a skill from the conversation#Trigger a specific set of instructions on demand | ||||||
| Run a skill in a separate subagent context#Run a skill's instructions in an isolated background task | ||||||
| Rescan skills without restarting#Pick up new or edited skills without restarting the session | ||||||
| Browse the available skills in a list#An interactive list of skills you can open or run. | ||||||
| Insert file contents and shell output into a prompt template#Templates can reference files and run commands when invoked. | ||||||
| Run a prompt template without the interactive interface#Invoke a saved command from a script or CI. | ||||||
| Run a prompt template in a subagent#A saved command executes in a separate agent context. | ||||||
| Executable customization | ||||||
| Register a custom model-callable tool#Add a new action the model can call for itself | ||||||
| Register a custom user slash command#Add your own shortcut command to the session | ||||||
| Load code plugins from a local directory or package#Extend behavior with installable plugin code | ||||||
| Add a custom TUI component#Build custom on-screen widgets for extensions | ||||||
| Customize tool-call and tool-result rendering#Change how tool calls and their results are displayed | ||||||
| Distribution and marketplaces | ||||||
| Install plugins from an organization-managed marketplace#Admins publish plugins and control who can access them. | ||||||
| Install extensions from a private package registry#Use your company registry for plugins. | ||||||
| Hooks and lifecycle events | ||||||
| Conversation and session | ||||||
| Handle session start or resume#Run custom logic when a session begins or resumes | ||||||
| Handle session termination#Run custom logic when a session ends | ||||||
| Handle user input before the agent processes it#Inspect or modify what you type before the agent sees it | ||||||
| Run a hook when the agent finishes its turn#Run your own check when a turn ends, optionally asking the agent to continue | ||||||
| Run a hook when a workspace opens or its folders change#Set up the environment as soon as a project is opened. | ||||||
| Tools and permission decisions | ||||||
| Intercept and block a tool call before execution#Approve, modify or block an action before it runs | ||||||
| Handle a successful tool result#Run custom logic right after a tool call succeeds | ||||||
| Handle tool failures separately#Run custom logic specifically when a tool call fails | ||||||
| Handle a permission-decision request#Plug custom logic into approval decisions | ||||||
| Run a hook after the agent edits a file#Trigger scripts like linters or formatters on every file change. | ||||||
| Context and branching | ||||||
| Receive an event before context compaction#Get notified before old conversation history is condensed | ||||||
| Cancel compaction or provide a custom summary#Stop history condensing or supply your own summary instead | ||||||
| Intercept and cancel a session fork#Approve or block creating a branched copy of the session | ||||||
| Run a hook after context compaction#Run your own logic right after the conversation was compacted | ||||||
| Intercept and cancel a session switch#Run logic before switching sessions and block it if needed | ||||||
| Working environment | ||||||
| Replace the default worktree-creation mechanism#Swap in custom logic for setting up an isolated working copy | ||||||
| Handle subagent start#Run custom logic when a background subagent is launched | ||||||
| Handle subagent completion#Run custom logic when a background subagent finishes | ||||||
| List and manage configured hooks#See which hooks are active and turn them on or off | ||||||
| Inject environment variables into shell commands#Add environment variables to every command the agent runs | ||||||
| Permissions, trust and isolation | ||||||
| Project trust | ||||||
| Request trust before loading project resources or code#Ask before running any project-specific settings or code | ||||||
| Persist a directory trust decision#Remember whether a folder is trusted for next time | ||||||
| Agent action permissions | ||||||
| Configure allow, ask and deny rules for tools#Set fine-grained rules for what actions run automatically | ||||||
| Allow or deny reads by path or glob#Restrict which files the agent is allowed to read | ||||||
| Allow or deny writes by path or glob#Restrict which files the agent is allowed to modify | ||||||
| Restrict shell commands by pattern#Limit which shell commands are allowed to run | ||||||
| Give deny rules precedence over allow rules#Make explicit blocks always win over explicit allows | ||||||
| Delegate action approval to a classifier#Let an automatic model review actions instead of asking you | ||||||
| Configure inheritable permission profiles#Build permission sets that inherit from a base profile | ||||||
| Auto-approve actions that would otherwise ask#Let the agent proceed without prompts for actions set to ask | ||||||
| Restrict who may talk to the agent#Allowlist the users or chats that can control a gateway agent | ||||||
| Steer automatic action review with written instructions#Plain-language allow and block rules guide the approval classifier. | ||||||
| Switch between named approval modes#Pick a preset such as ask, allowlist or run everything. | ||||||
| Approve an action and similar ones for the rest of the session#One answer covers matching future requests until the session ends. | ||||||
| Stop and ask when the agent repeats the same tool call#Detects loops of identical calls and asks before continuing. | ||||||
| Control access to paths outside the project directory#Ask, allow or deny when a tool touches files beyond the project. | ||||||
| Execution isolation | ||||||
| Run the shell tool in an OS-level sandbox#Contain shell commands in a restricted sandbox | ||||||
| Configure a profile's filesystem access#Set which folders a permission profile can read or write | ||||||
| Restrict network destinations for sandboxed commands#Limit which network addresses sandboxed commands can reach | ||||||
| Run the entire CLI inside an external isolation runtime#Run the whole tool inside a locked-down container or VM | ||||||
| Tell commands whether they run inside the sandbox#Environment variables expose sandbox state and the original user to child processes. | ||||||
| Repository change isolation | ||||||
| Start work in a separate Git worktree#Work in an isolated copy of the repo so your main branch stays untouched | ||||||
| Choose the base branch for a new worktree#Pick which branch a new isolated working copy starts from | ||||||
| Organization policies | ||||||
| Enforce organization-managed settings members cannot override#Central or remotely fetched configuration takes precedence over user settings. | ||||||
| Let admins restrict which run and approval modes members may use#Disable headless runs or auto-approval for the whole team. | ||||||
| Enforce organization network allow and deny lists#Admins decide which hosts agent commands can reach. | ||||||
| Web, browser and desktop | ||||||
| Retrieve web information | ||||||
| Search the web with a dedicated tool#Look things up online during a session | ||||||
| Fetch content from a specific URL#Pull the contents of a specific webpage into the conversation | ||||||
| Configure domain-based URL-fetch permissions#Control which websites the agent is allowed to fetch from | ||||||
| Browser control | ||||||
| Connect to a running local Chromium browser through CDP#Attach to a browser already open on your machine | ||||||
| Navigate to a URL in a controlled browser#Open a webpage in an automated browser | ||||||
| Read an accessibility snapshot and element references#Read a page's structure to find clickable elements | ||||||
| Click an element#Click a button or link on a webpage | ||||||
| Type into a field#Fill in a text field on a webpage | ||||||
| Handle a JavaScript dialog#Respond to browser popups like confirm or alert boxes | ||||||
| Read browser console output and page errors#See console logs and errors to debug a webpage | ||||||
| Analyze a page screenshot#Use image analysis to understand a page visually | ||||||
| Inspect browser network requests#See the requests and responses a controlled browser makes | ||||||
| Use persistent browser profiles for logged-in sites#Keep browser logins so the agent can use authenticated web apps | ||||||
| Scroll a page in the controlled browser#The agent scrolls to reach content below the fold. | ||||||
| Desktop control | ||||||
| Control applications, pointer, input and screen from a CLI session#Let the agent click, type and see the screen like a person would | ||||||
| Control the desktop in the background through a separate driver#Control apps and input in the background without touching your cursor | ||||||
| Images, video and voice | ||||||
| Input media | ||||||
| Attach image files to a CLI prompt#Include image files alongside your prompt | ||||||
| Paste a clipboard image into an interactive prompt#Paste a screenshot straight into the prompt | ||||||
| Analyze video from a file or URL#Get descriptions and timestamps from a video | ||||||
| Downscale attached images to fit provider limits#Oversized images are resized or rejected before sending. | ||||||
| Generation and voice interaction | ||||||
| Generate or edit images#Create or modify images from a text description | ||||||
| Dictate a text prompt#Speak your prompt instead of typing it | ||||||
| Hold a voice conversation with speech recognition and synthesis#Talk back and forth with the agent by voice | ||||||
| Generate or edit video#Create or modify video clips from a prompt | ||||||
| Schedules, events and messaging | ||||||
| Time-based execution | ||||||
| Repeat a prompt while the current session remains open#Rerun a prompt on a timer while you keep working in the session | ||||||
| Schedule a one-shot or recurring task within a session#Schedule a prompt to run later or on a repeating schedule | ||||||
| List in-session scheduled tasks#See what's currently scheduled in this session | ||||||
| Cancel an in-session scheduled task#Remove a scheduled task before it runs | ||||||
| Manage persistent jobs in a separate scheduler runtime#Manage scheduled jobs that keep running outside any single session | ||||||
| Create a cloud-executed routine#Set up a recurring task that runs in the cloud, not on your machine | ||||||
| Run the agent on a GitHub Actions cron schedule#Trigger the agent automatically on a CI schedule | ||||||
| External event triggers | ||||||
| Activate the agent through a webhook subscription#Trigger the agent automatically when an external event fires | ||||||
| Receive MCP channel push events in the current session#Let a connected tool server push messages into the live session | ||||||
| Communicate outside the terminal | ||||||
| Maintain durable conversations through messaging adapters#Keep an ongoing conversation going through a chat app | ||||||
| Communicate through Telegram#Chat with the agent from a messaging app | ||||||
| Reject a pending dangerous action through a messaging command#Deny a risky pending action from a chat app | ||||||
| Send a desktop notification#Get a desktop alert when a long task finishes | ||||||
| Send a phone push notification#Get a phone alert when a long task finishes | ||||||
| Batch processing | ||||||
| Run many independent prompts with a parallel batch runner#Run large batches of prompts in parallel | ||||||
| Resume an unfinished batch from a checkpoint#Pick a large batch run back up where it left off | ||||||
| Cloud and CI execution | ||||||
| Hand the current task off to a cloud agent#Continue work remotely and pick it up later from the web. | ||||||
| Run the agent in GitLab CI and from GitLab comments#Mention the agent in an issue or MR, or run it as a pipeline job. | ||||||
| Run the agent in GitHub Actions from comments or manual triggers#Set up a workflow; the agent answers issue and PR comments or runs on dispatch. | ||||||
| Headless, APIs, SDKs and external clients | ||||||
| Single non-interactive runs | ||||||
| Submit a prompt and receive a result without a TUI#Run a single prompt from a script and get the answer back | ||||||
| Return the final result as JSON#Get the final answer as structured JSON for scripts | ||||||
| Stream JSON events during execution#Stream step-by-step JSON events as the agent works | ||||||
| Specify a JSON Schema for the final response#Force the final answer to match a schema you define | ||||||
| Write the final response to a file#Save the final answer straight to a file | ||||||
| Stop a print-mode run at an API spending limit#Cap how much a scripted run can spend before it stops | ||||||
| Limit agentic turns in a print-mode run#Cap how many steps a scripted run can take before it stops | ||||||
| Limit tool-calling iterations within one conversation turn#Cap how many tool calls happen within a single reply | ||||||
| Long-running programmatic interfaces | ||||||
| Control the agent through a custom bidirectional stdio RPC protocol#Drive the agent programmatically from another app | ||||||
| Run a headless HTTP API server#Expose the agent as an HTTP API for other tools to call | ||||||
| Connect a client to an app server over WebSocket#Connect a client to the agent over a persistent network link | ||||||
| Expose an ACP interface to an external editor or client#Let external editors control the agent through a standard protocol | ||||||
| Protect a local agent server with a password and allowed origins#Require a password and restrict which browser origins may connect. | ||||||
| Get a machine-readable API specification for the server#An OpenAPI document describes the server's HTTP API. | ||||||
| Answer the agent's questions from an external client#An editor or app connected to the agent can reply to its blocking questions. | ||||||
| SDKs and remote control | ||||||
| Embed the agent loop through an official SDK package#Embed the agent directly into your own application code | ||||||
| Control a locally running session from a web or mobile client#Control a session on your computer from your phone or browser | ||||||
| Attach a terminal UI to a running agent server#Open the TUI against an agent that is already running elsewhere | ||||||
| Use the agent through a local browser UI#Work with the agent in a web page served from your machine | ||||||
| Work with a running agent server through a desktop app#A native app connects to the same server as the terminal. | ||||||
| Make the agent server discoverable on the local network#Other devices find the running server automatically. | ||||||
| Self-hosted workers | ||||||
| Run cloud agents on your own machines as workers#Register a machine or pool that executes cloud agent runs. | ||||||
| Monitor a self-hosted worker through health and metrics endpoints#Readiness, health and metrics for running workers. | ||||||
| Configuration, diagnostics and observability | ||||||
| Configure and recover the environment | ||||||
| Reload resources and extensions without ending the process#Pick up config and extension changes without restarting | ||||||
| Start without user customizations for troubleshooting#Start with a clean slate to isolate a config problem | ||||||
| Diagnose installation and configuration issues#Check the setup for common problems automatically | ||||||
| Start and stop the runtime as a service#Run the tool in the background as a managed service | ||||||
| Update the CLI from within the CLI#Check for and install a new version with a built-in command | ||||||
| Copy the conversation and request IDs#Put identifiers on the clipboard for support or debugging. | ||||||
| Edit settings in an interactive editor inside the CLI#Change configuration without opening files. | ||||||
| Find and view diagnostic logs#Locate log files, print logs to the terminal and set their verbosity. | ||||||
| Show version, system and account details#Print the CLI version and environment info for support. | ||||||
| Update the CLI automatically in the background#Installs new versions without asking, or notifies you. | ||||||
| Usage and operational signals | ||||||
| Inspect session spending, usage and limits#See how much this session has cost and how much you have left | ||||||
| Aggregate usage and cost by session, model and project#See usage and cost totals broken down across sessions and projects | ||||||
| Export metrics, logs and traces through OpenTelemetry#Feed usage and performance data into your own monitoring stack | ||||||
| See remaining plan or subscription quota#Check how much of your plan allowance is left | ||||||
| Generate a report about recent sessions#Get a summary of how you used the agent across recent sessions | ||||||
| Privacy and export | ||||||
| Disable installation telemetry and attribution headers#Turn off anonymous install and usage reporting | ||||||
| Export a session with sensitive data redacted#Export a session transcript with sensitive details stripped out | ||||||
| Enable PII redaction within the documented scope#Automatically mask personal identifiers before they reach the model | ||||||
