Install
openclaw skills install @eohmig/update-cli-configView and modify Codex CLI configuration settings in ~/.cursor/cli-config.json. Use when the user wants to change CLI settings, configure permissions, switch approval mode, enable vim mode, toggle display options, configure sandbox, or manage any CLI preferences.
openclaw skills install @eohmig/update-cli-configThis skill explains how to view and modify Codex CLI settings stored in ~/.cursor/cli-config.json.
The config file is ~/.cursor/cli-config.json.
Projects can layer overrides via .cursor/cli.json files. The CLI walks from the git root to the current working directory and merges each .cursor/cli.json it finds (deeper files take precedence). Project overrides only affect the current session; they are not written back to the home config.
Read ~/.cursor/cli-config.json, apply changes, and write it back. The file is standard JSON. Changes take effect after restarting the CLI.
permissions (required)Tool permission rules. Each entry is a string pattern.
allow: string[] — patterns for allowed tool calls (e.g. "Shell(**)", "Mcp(server-name, tool-name)")deny: string[] — patterns for denied tool callseditorvimMode: boolean — enable vim keybindings in the CLI inputdefaultBehavior: "ide" | "agent" — default behavior modedisplay (optional)showLineNumbers: boolean (default: false) — show line numbers in code outputshowThinkingBlocks: boolean (default: false) — show model thinking/reasoning blocksshowStatusIndicators: boolean (default: false) — show status indicators in the UIchannel (optional)Release channel: "prod" | "lab" | "static"
maxMode (optional)boolean (default: false) — enable max mode for higher-quality model responses
subagentModels (optional)Per-subagent model settings.
explore: "default" | "inherit" | "disabled" or { "modelId": string, "parameters"?: [{ "id": string, "value": string }], "maxMode"?: boolean } — use Codex's default Explore model, inherit the parent agent's model, disable the Explore subagent, or pin a specific model. When parameters is omitted, saved per-model parameter preferences apply; when maxMode is omitted, the parent conversation's max mode applies.exploreSubagentModel (optional, legacy)"default" | "inherit" (default: "default") — legacy Explore model setting. subagentModels.explore wins when both are set; keep this in sync ("inherit" when explore inherits, otherwise "default") so older CLI versions reading the same config behave sensibly.
approvalMode (optional)Controls tool approval behavior:
"allowlist" (default) — require approval for tools not in the allow list--force / --yolo; set approval mode to the non-allowlist value)sandbox (optional)Sandbox execution environment settings:
mode: "disabled" | "enabled" (default: "disabled")networkAccess: "user_config_only" | "user_config_with_defaults" | "allow_all" — controls network access from sandboxnetworkAllowlist: string[] — domains the sandbox is allowed to reachnetwork (optional)useHttp1ForAgent: boolean (default: false) — use HTTP/1.1 instead of HTTP/2 for agent connections (enables SSE-based streaming)bedrock (optional)AWS Bedrock integration settings:
enabled: boolean (default: false)mode: "access-key" | "team-role" (default: "access-key")region: string — AWS regiontestModel: string — model to use for testingteamRoleArn: string — IAM role ARN for team modeteamExternalId: string — external ID for STS assume-roleattribution (optional)Controls how agent work is attributed in git:
attributeCommitsToAgent: boolean (default: true) — attribute commits to the agentattributePRsToAgent: boolean (default: true) — attribute PRs to the agentwebFetchDomainAllowlist (optional)string[] — domains the web fetch tool is allowed to access (e.g. "docs.github.com", "*.example.com", "*")
These are internal/cached state and should not be edited manually:
version — config schema versionmodel / selectedModel / modelParameters / hasChangedDefaultModel — managed by the model pickerprivacyCache — cached privacy mode stateauthInfo — cached authentication infoshowSandboxIntro — one-time UI flagconversationClassificationScoredConversations — internal cache