autofeat docs
Reference

Config reference

Every key in .autofeat/config.yml, with type, default, and notes.

File: .autofeat/config.yml on the default branch. Unknown keys are errors. The pull request branch cannot change the policy that judges that pull request.

autonomy.auto_approve false forces autonomy.merge_mode to stop_before_merge, even if the file says approve_only or auto. Set auto_approve: true before either of those modes will stick. See Merge modes.

Keys

KeyTypeDefaultNotes
versionliteral 11Only version 1.
identityappappOnly value.
runnerstringnixosRecorded on the decision.
autonomy.merge_targetstringmainBase branch name.
autonomy.auto_approveboolfalseWhen false, merge mode is forced to stop_before_merge.
autonomy.merge_modestop_before_merge, approve_only, autostop_before_mergeapprove_only and auto require auto_approve: true.
autonomy.dry_runbooltrueNo push, review, merge, or ready label. Journal, sticky, and checks still write.
autonomy.require_green_checksbooltrueWhen false, an empty check set can count as success. When true, it does not.
entry_actionaction namereviewMust be in policy.allowed_actions.
agents.defaultstringopencodeMust be in agents.allowed.
agents.allowedlist of stringsopencode, claude, codex, grok-buildkimi is recognised for subscription login and is not in this default list.
agents.billingmap of agent to api_key or subscription{}Missing agent means api_key. Keys must be in agents.allowed.
agents.models.<agent>.modelstring or omittedomittedCLI model id, for example sonnet.
agents.models.<agent>.providerstring or omittedomittedRequires model. A provider and model pair is accepted for opencode only.
models.default.providerstringopenrouter
models.default.modelstringdeepseek-v4-proMust appear in models.allowed.
models.allowedlist of {provider, model}the default, when the key is omittedAn explicit [] is invalid. An opencode provider and model pair must equal models.default or sit in this list.
budget.turnsint >= 112Hard ceiling.
budget.usdnumber > 025.0Hard ceiling.
budget.alert_usdnumber >= 010.0Must be <= budget.usd. Warning only.
budget.minutesint >= 1240Hard ceiling.
budget.tokensint >= 12000000Hard ceiling.
subscription.max_concurrentint >= 12Subscription agents.
subscription.max_runs_per_dayint >= 150Alert at 80 percent. Not a stop by itself.
security.allow_same_uidboolfalsetrue requires autonomy.dry_run: true. Hosted launcher refuses it.
security.allow_forksboolfalseWrite actions on a fork are refused. Review can still start.
security.require_signaturebooltrueDirectives must verify.
security.trusted_actorslist of stringsa-x-cGitHub logins trusted to drive the run.
methodsmap of action to method{}Method must be legal for the action and listed in policy.allowed_methods.
orchestrate.max_workersint >= 14Used when method is orchestrate.
labels.gostringautofeat:goAdmit a turn.
labels.stopstringautofeat:stopKill switch.
labels.pausestringautofeat:pausePause. Removing it does not resume.
labels.readystringautofeat:readyAdded when stopping before merge.
checks.required_checkslist of strings[]Names that casefold-start with autofeat/ are refused.
checks.required_producersmap of name to int or string{}App id (int) or slug (string). Same autofeat/ refusal.
checks.allow_missing_checksboolfalseZero checks is a refusal when false.
policy.modereview_only or fullreview_onlyreview_only forbids plan, implement, and test.
policy.allowed_actionslist of actionsderived from modeOmit the key to take the mode default.
policy.allowed_methodsmap of action to list of methodsderivedEach action's list must include that action's default method.
policy.reviewer.providerstring or nullnull
policy.reviewer.modelstring or nullnullMust not appear in must_differ_from.
policy.reviewer.must_differ_fromlist of strings[]Producer model ids the reviewer must not share.
policy.reviewer.severity_thresholdinfo, low, medium, high, criticalhigh

Action names: plan, implement, test, review, gate, merge, halt.

Default method per action:

ActionDefault methodAlso legal
plansingleorchestrate
implementorchestratesingle
testsingleorchestrate
reviewdelegatenative is parseable and refused
gatenativenative only
mergenativenative only
haltnativenative only

Method flow exists in the enum and policy refuses it. Do not set it.

review_only derived actions are review, gate, merge, halt. Derived methods: review is delegate; gate, merge, and halt are native.

Annotated example

This file matches the schema defaults. Comments are not part of the data.

version: 1
identity: app
runner: nixos
autonomy:
  merge_target: main
  auto_approve: false
  # Ignored while auto_approve is false. The loader stores stop_before_merge.
  merge_mode: stop_before_merge
  dry_run: true
  require_green_checks: true
entry_action: review
policy:
  mode: review_only
  reviewer:
    severity_threshold: high
agents:
  default: opencode
  allowed: [opencode, claude, codex, grok-build]
  billing:
    claude: subscription
  # models:
  #   claude: { model: sonnet }
  #   opencode: { provider: openrouter, model: deepseek-v4-pro }
models:
  # Omitted allowed becomes [default]. Explicit [] is invalid.
  default: { provider: openrouter, model: deepseek-v4-pro }
budget:
  turns: 12
  usd: 25.0
  alert_usd: 10.0
  minutes: 240
  tokens: 2000000
subscription:
  max_concurrent: 2
  max_runs_per_day: 50
security:
  allow_same_uid: false
  allow_forks: false
  require_signature: true
  trusted_actors: [a-x-c]
methods: {}
orchestrate:
  max_workers: 4
labels:
  go: "autofeat:go"
  stop: "autofeat:stop"
  pause: "autofeat:pause"
  ready: "autofeat:ready"
checks:
  required_checks: []
  required_producers: {}
  allow_missing_checks: false

To leave dry run, set autonomy.dry_run: false on the default branch after a clean dry run. To let the App approve and then stop, set auto_approve: true and merge_mode: approve_only. To merge, set auto_approve: true and merge_mode: auto. See Budgets and billing.

The deployment-wide API-key ceiling daily_api_key_ceiling_usd (default 25.0) is host config. It is not a key in this file.

On this page