Skip to content

Settings

Open Hydron Settings from the chat pane toolbar. It opens as an editor tab rather than a modal, so you can keep it beside your code while you work.

Auto-Approve

Auto-Approve defines how tools are allowed to run. Most tools default to Allow. doom_loop and external_directory default to Ask.

Each capability has one default covering every target, plus a list of exceptions. Set the default to Ask and allow the specific paths or commands you trust. That way an unfamiliar path or command prompts you, rather than running because nobody thought to block it.

Each row is set to Allow or Ask. Exceptions are glob patterns, so git log * matches any git log invocation and /tmp/* matches anything under /tmp.

External Directory

Access files outside the workspace. Triggered when the agent reaches outside the current project directory.

The default, All paths (*), is set to Ask. Use + Add path to allow specific locations:

/tmp/*
/opt/qcom/*

Keep the default at Ask. This is the setting that stops the agent reading SSH keys, cloud credentials, and shell configuration from your home directory while it works on your firmware. A broad exception such as /home/* gives that away in one line.

Allow the toolchain and SDK paths your build genuinely needs, and nothing above them.

Bash

Run terminal commands. Allows execution of shell commands, for example git status.

The default, All commands (*), is set to Ask. Add exceptions for the commands you want running unattended:

git log *
git diff *
git show *
ls *

Read-only inspection commands are the safe category. They let the agent orient itself without a prompt on every step, which is where most of the friction is.

Leave build, flash, and anything destructive at Ask. On a machine wired to hardware this matters more than on a laptop: an approved flash command is a real action on a real board.

doom_loop

Fires when the agent issues the same tool call with identical input three times in a row. Defaults to Ask.

It is a circuit breaker, not a permission. When it triggers, the agent is stuck repeating itself, and the useful response is usually to interrupt and rephrase rather than approve another attempt.

Capabilities

The permission model covers read, write, edit, patch, list, glob, grep, bash, webfetch, task, todo, external_directory, and doom_loop.

Most default to Allow, because a firmware task that prompts on every file read is slower than doing the work by hand. The two that reach outside the project, bash and external_directory, are the ones worth spending attention on.

Checkpoints

Enable checkpoints to save a snapshot of your workspace before each file edit.

With it on, every edit the agent makes is preceded by a restore point. If a change goes the wrong way, roll back to the checkpoint instead of unwinding the edits by hand or reaching for git checkout and losing your other uncommitted work.

This matters most in the cases where you would not notice immediately: a multi-file change where the second file's edit invalidates the first, or a refactor that compiles cleanly and breaks on the bench.

Checkpoints are local to your machine and are not a substitute for committing. Anything you want to keep still belongs in a commit.

Marketplace

Browse and install plugins without leaving the editor.

Search the Marketplace, pick a scope from the dropdown on the install button, and click Install. Installed plugins appear under Installed, where you can enable, disable, update, or remove them.

Scope is the decision worth pausing on: Global makes a plugin available in every project on your machine, This project keeps it to the current workspace. Start with This project for anything you are still evaluating.

See Plugins.

Practices

  • Narrow the two defaults, widen the exceptions. Ask on *, Allow on the specific paths and commands you use daily.
  • Allow what you would read anyway. If you would skim a command's output without thinking, it belongs on the list.
  • Review the list when your toolchain changes. An exception for an SDK path you no longer build against is access nobody is using or watching.
  • Keep hardware-facing commands on Ask. Flashing and resets are cheap to approve and expensive to undo.

Next

  • Agent modes for what each mode is allowed to do.
  • Plugins for managing plugins from either surface.