Allow oncethis request onlyApproves just this one request.
What V3Code Terminal asks before it acts, how to configure permission rules, and exactly what touches the network.
V3Code Terminal does not silently approve every tool. Risky actions stop and ask you first, and the product is local-first by default.
When a guarded action needs approval, you see Permission required, the exact target or command, and three choices:
Allow oncethis request onlyApproves just this one request.
Allow alwaysuntil restartApproves the displayed permission or pattern until V3Code restarts.
RejectstopStops the action. A child agent can also be given written feedback explaining the rejection.
Prompts can protect edits, reads, file listing, glob and grep searches, shell commands, subagent tasks, web fetches, web searches, access to directories outside the project, language servers and skills, and continuation after repeated failures. Unknown plugin tools can request permission by their own tool name.
Permission actions are ask, allow, and deny. A rule can cover a whole tool or just matching patterns.
Project configuration lives in v3code.json, v3code.jsonc, or under .v3code/. User configuration lives under ~/.config/v3code/ on macOS and Linux.
{ "permission": { "edit": "ask", "external_directory": "ask", "webfetch": "ask", "bash": { "*": "ask", "git status*": "allow", "git diff*": "allow", "rm *": "deny", }, },}When several patterns match, the last one wins. So keep the broad fallback first and your specific exceptions after it, exactly as above.
Run /privacy to inspect the policy actually in effect.
Without an opt-in, V3Code Terminal does not:
The built-in model catalog still works from the packaged snapshot or local cache, and anything previously cached stays usable.
Local-first startup also skips the inherited OpenCode account-config refresh, even if an old OpenCode credential is still stored. The upstream account-console and GitHub-bot commands aren’t exposed by the V3Code CLI.
Traffic that directly serves something you asked for:
/share reaches its named service.| Variable | Effect |
|---|---|
V3CODE_ALLOW_BACKGROUND_NETWORK=1 |
Allows background dependency traffic. |
V3CODE_ALLOW_TELEMETRY=1 |
Enables telemetry (separately off by default). |
V3CODE_ALLOW_AUTO_SHARE=1 |
Enables automatic session sharing. |
V3CODE_ALLOW_REMOTE_PARSERS=1 |
Allows remote syntax parsers only. |
Each lane is separate on purpose — enabling background network traffic does not turn on telemetry or sharing.
Setup completes only when a currently available model is selected. Finish Choose a provider and Choose a model. Run /connect to retry authentication, /models to pick a usable model, or v3code providers list outside the interface. A removed model or missing credential deliberately makes setup return.
standaloneOpen V3Code Editor as the same local user and run /bridge again. The discovery file is ~/.v3code/endpoint.json — don’t hand-edit it. Local memory and index features keep working regardless.
/bridge says the index isn’t builtThe structural index is lazy and builds on first use. Ask the agent to run bridge reindex after a large refactor. Semantic search is separate and only covers locations you approved in the Index tab. If Beast says not installed, symbol search still works; only deep trace needs the sidecar.
Local-first mode blocks those downloads. Install what you need locally, or set V3CODE_ALLOW_BACKGROUND_NETWORK=1 deliberately. Run /privacy after restarting to confirm.
v3code debug configv3code debug pathsV3Code reads the V3CODE_* environment prefix first and accepts legacy OPENCODE_* aliases for compatibility.
v3code --pure --print-logs --log-level DEBUGv3code debug startup prints startup timing and v3code debug paths shows the log directory. Remove secrets before sharing logs.
Privacy covers the editor’s policy, and Permissions covers its approval model.