What Is YOLO Mode? How to Enable It in Every Agent
YOLO mode is the setting that lets an AI coding agent act without asking you first. With it off, the agent stops before it edits a file, runs a shell command or calls a tool, and waits for you to approve. With it on, it just does those things, one after another, until the task is done.
The name is the internet's "you only live once": you are accepting that the agent might do something you would have stopped, in exchange for never having to babysit it. Every major coding agent has a version of it. Most of them call it something more careful, and almost all of them put the word "dangerously" somewhere in the flag.
This guide covers what YOLO mode actually turns off, the exact switch in seven agents, and how to get most of the speed without betting the repository on it.
What YOLO Mode Turns Off
Coding agents ship with an approval loop because they run real commands on your real machine. A normal session looks like this: the agent proposes npm install, you approve; it proposes an edit to auth.ts, you approve; it wants to run the tests, you approve. Each prompt is a few seconds of your attention, and a task with fifty tool calls is fifty interruptions.
YOLO mode removes those prompts. Depending on the agent it can also remove a second safety layer, the sandbox that limits which files and network addresses a command can reach. That difference matters, so the table below calls it out.
Most agents also have a halfway setting that approves file edits automatically but still asks before shell commands. If your goal is "stop asking me about every edit", that is usually what you want, not full YOLO.
YOLO Mode in Each Agent at a Glance
| Agent | Full YOLO | Halfway setting | Also turns off the sandbox? |
|---|---|---|---|
| Claude Code | claude --dangerously-skip-permissions |
acceptEdits mode, or auto mode |
No, the Bash sandbox is a separate setting |
| OpenAI Codex CLI | codex --yolo |
codex --approve-for-me |
Yes |
| Google Antigravity | Turbo preset (IDE), agy --dangerously-skip-permissions (CLI) |
Default preset: sandboxed commands run freely | Turbo runs with no isolation |
| Gemini CLI | gemini --yolo or -y, Ctrl+Y in a session |
--approval-mode=auto_edit |
No, the sandbox is separate and off by default |
| GitHub Copilot | copilot --yolo (CLI), Allow all (VS Code) |
--allow-tool for chosen tools |
VS Code keeps its terminal sandbox on |
| Cline | YOLO checkbox in settings, cline --yolo (CLI) |
Per-category auto-approve toggles | No built-in sandbox |
| OpenCode | "permission": "allow" in opencode.json, or --auto |
Per-tool allow, ask, deny rules |
No built-in sandbox |
Flags change quickly. Everything here was checked against each project's documentation or source on October 2, 2026.
How to Turn On YOLO Mode in Claude Code
Start the session with the flag:
That is the same as --permission-mode bypassPermissions. To make it the default, set "permissions": {"defaultMode": "bypassPermissions"} in your user settings (~/.claude/settings.json). Claude Code ignores that key in a project's own .claude/settings.json, so a cloned repository cannot switch it on for you.
A few things worth knowing:
- → Shift+Tab cycles between permission modes inside a session, but it only offers bypass if the session was started with it allowed. Start with
--allow-dangerously-skip-permissionsto add it to the cycle without turning it on. - → It refuses to run as root, and explicit "ask" rules still prompt even in bypass mode.
- → The safer options are
acceptEdits(edits run, commands still ask) and auto mode, where a classifier model reviews each action and only stops you for risky ones. - → Anthropic's advice is to use full bypass only inside a container or VM.
How to Turn On YOLO Mode in OpenAI Codex
--yolo is the short alias for --dangerously-bypass-approvals-and-sandbox, and the long name is accurate: it sets the approval policy to never and the sandbox to danger-full-access. Commands run with no approval and no sandbox.
The same thing in ~/.codex/config.toml:
The old --full-auto flag has been removed. Its replacement is --approve-for-me, which keeps the workspace-write sandbox and lets an automatic reviewer approve requests for you. For most people that is the better default. Inside a session, /permissions changes the mode.
How to Turn On YOLO Mode in Google Antigravity
In the Antigravity IDE on macOS and Linux, open the agent settings and pick the Turbo permission preset. Antigravity describes it as "all commands run without prompting with no isolation". The Default preset is the halfway setting: commands that stay inside the sandbox run freely, and anything outside it asks. On Windows the equivalent is the terminal policy Always Proceed, which only stops for commands on your deny list.
For the agy command-line agent:
Or set "toolPermission": "always-proceed" in ~/.gemini/antigravity-cli/settings.json. Inside a session, /permissions opens the permission panel and Shift+Tab cycles between default, accept-edits and plan.
How to Turn On YOLO Mode in Gemini CLI
-y and --approval-mode=yolo do the same thing (don't combine --yolo with --approval-mode). Inside a running session, Ctrl+Y toggles YOLO on and off, and Shift+Tab cycles the other modes.
One difference from the other agents: Gemini CLI does not let you make YOLO the default in settings.json. defaultApprovalMode accepts default, auto_edit and plan only, so YOLO is always a decision you make at launch. The halfway setting is --approval-mode=auto_edit. The sandbox is controlled separately with --sandbox and is off unless you turn it on.
How to Turn On YOLO Mode in GitHub Copilot
In the Copilot CLI:
--yolo and --allow-all both mean allow all tools, all paths and all URLs. Inside a session, /yolo or /allow-all does the same, and /reset-allowed-tools takes it back. For something narrower, --allow-tool and --deny-tool approve or block specific tools, and a deny always wins.
In VS Code, open the permissions menu in the chat input and choose Allow all, or type /yolo in the chat (/disableYolo to turn it off). VS Code keeps its terminal sandbox on even with Allow all selected.
Copilot's Autopilot is a different switch. It is about the agent continuing without stopping to check in, not about tool permissions.
How to Turn On YOLO Mode in Cline
In the VS Code extension, open Cline's settings and find the auto-approve section. It has separate toggles for reading files, editing files, running safe commands, running all commands, the browser and MCP tools, which together are the halfway setting. Below them, the YOLO mode checkbox approves everything, including switching between plan and act.
In the Cline CLI:
-y is the short form. In YOLO mode the CLI also exits when the task is finished, which suits scripts and CI.
How to Turn On YOLO Mode in OpenCode
OpenCode controls permissions in opencode.json. The shortest form allows everything:
Or allow most tools but keep shell commands on a leash:
From the command line, opencode --auto approves every permission that is not explicitly denied. Many of OpenCode's tools are already set to allow by default. Access outside the project directory still asks, and reading .env files is denied.
Is YOLO Mode Safe?
It is as safe as the worst command the agent might run, and you will not see that command before it runs. The real risks are not dramatic. They are an rm aimed at the wrong directory, a migration run against the wrong database, a dependency installed from a typo, or a prompt hidden in a web page or issue that tells the agent to do something you never asked for.
Three rules cover most of it:
- → Contain it. Run YOLO sessions in a container, a VM or a throwaway clone, without production credentials in the environment.
- → Keep git clean. Commit before you start, so any change is one
git resetaway from gone. - → Scope it. Give a YOLO agent one well-defined task, not an open-ended "improve the codebase".
Safe YOLO With AgentRQ Approvals
The trouble with YOLO mode in every agent above is that it is a setting for the whole session. You switch it on for the boring task, forget it is on, and the next task inherits it.
AgentRQ makes it a decision you take for each task. Connect Claude Code or any ACP agent through the ACP Gateway to an AgentRQ workspace, and leave the agent's own approvals on. Every time the agent asks for permission, the request shows up in the task on your phone, the web or Slack, and you answer Allow, Always allow for that tool, or Deny. You approve from wherever you are, so the agent is never left waiting for you to come back to the terminal.
For a task you trust, turn on YOLO mode for that task only. Every tool call in it is approved automatically and the agent never pauses, while every other task in the workspace still asks. When it finishes, the tool call history shows every call it made, including the ones that were auto-approved, so an unattended run is still something you can review.
That is the version of YOLO worth having: fast where you have decided it is safe, supervised everywhere else, and recorded throughout.
FAQ
What does YOLO mode mean? "You only live once." In AI coding agents it means running without approval prompts, so the agent edits files and runs commands on its own.
What is YOLO mode in Claude Code? Starting Claude Code with --dangerously-skip-permissions (bypass permissions mode), which skips every approval prompt for that session.
How do I enable YOLO mode in Antigravity? Choose the Turbo permission preset in the IDE's agent settings (Always Proceed on Windows), or run the agy CLI with --dangerously-skip-permissions.
Is there a YOLO mode in ChatGPT? Not in the ChatGPT app. OpenAI's coding agent, Codex CLI, has one: codex --yolo.
What is the safest way to use YOLO mode? Run it in a container or a clean git checkout, give it one scoped task, and use per-task approvals like AgentRQ's so YOLO never applies to more than the task you chose. See the YOLO mode glossary entry for a short definition.