How Qwen Code Approval Mode Works and What the --yolo Flag Does

The approval mode in Qwen Code controls whether tool executions require user confirmation, and the --yolo flag automatically approves all actions by setting the mode to ApprovalMode.YOLO.

Qwen Code is an AI-powered coding assistant that executes tools like file edits, shell commands, and web fetches on your behalf. To balance automation with safety, it implements a configurable approval mode system that determines when the system must pause for user consent. This article explains how the approval subsystem works and specifically what happens when you use the --yolo command-line flag.

The Four Approval Modes Explained

The approval mode is stored in ServerConfig.approvalMode and defined in packages/core/src/config/config.ts as the ApprovalMode enum. Each mode represents a different trust level between the user and the AI agent:

Mode Behavior Best For
default Every mutable tool prompts for explicit approval. Interactive sessions requiring full control.
plan Only read-only tools execute; mutable operations are rejected automatically. Dry-run planning without side effects.
auto-edit File edit tools (write, diff) auto-approve; other tools still prompt. Fast editing when you trust the model's file modifications.
yolo All tools auto-approve without user prompts. CI pipelines, unattended runs, or maximum automation.

Where Approval Mode is Defined

The canonical definition lives in packages/core/src/config/config.ts:

export enum ApprovalMode {
  PLAN = 'plan',
  DEFAULT = 'default',
  AUTO_EDIT = 'auto-edit',
  YOLO = 'yolo',
}

This file also exports APPROVAL_MODE_INFO, which provides human-readable labels and descriptions for UI rendering. The ServerConfig class maintains the current state and exposes getApprovalMode() and setApprovalMode() methods for runtime changes.

How to Set Approval Mode

Using the --yolo CLI Flag

The --yolo flag (alias -y) is defined in packages/cli/src/config/config.ts:

.option('yolo', {
  alias: 'y',
  type: 'boolean',
  description:
    'Automatically accept all actions (aka YOLO mode, see https://www.youtube.com/watch?v=xvFZjo5PgG0 for more details)?',
  default: false,
})

Important: The flag is mutually exclusive with --approval-mode. The CLI enforces this conflict at lines 538-540:

if (argv['yolo'] && argv['approvalMode']) {
  return 'Cannot use both --yolo (-y) and --approval-mode together. Use --approval-mode=yolo instead.';
}

When --yolo is passed, the CLI translates it to approvalMode: 'yolo' (handled around line 745), effectively bypassing all confirmation prompts.

Runtime Configuration via UI

You can change modes mid-session using the VSCode companion or web UI. The command /approval-mode <mode> routes through packages/vscode-ide-companion/src/services/qwenAgentManager.ts, which calls Config.setApprovalMode(mode). This allows dynamic switching between cautious and permissive behaviors without restarting the agent.

Programmatic Configuration

When using the SDK directly:

import { ServerConfig, ApprovalMode } from '@qwen/code-sdk';

const cfg = await ServerConfig.load(...);
cfg.setApprovalMode(ApprovalMode.YOLO); // All future tool calls bypass approval

How Approval Mode Affects Tool Execution

Core Scheduler Logic

The central gatekeeper is CoreToolScheduler.scheduleToolCalls in packages/core/src/core/coreToolScheduler.ts. It checks the current mode before deciding whether to prompt:

if (this.config.getApprovalMode() === ApprovalMode.YOLO ||
    doesToolInvocationMatch(toolCall.tool, invocation, allowedTools)) {
  // auto‑approve
  this.setToolCallOutcome(reqInfo.callId, ToolConfirmationOutcome.ProceedAlways);
  this.setStatusInternal(reqInfo.callId, 'scheduled');
}

When ApprovalMode.YOLO is active, the scheduler immediately sets the outcome to ProceedAlways, skipping the confirmation UI entirely.

Tool-Specific Implementations

Individual tools also perform early-exit checks to optimize performance:

Practical Usage Examples

Unattended Automation with --yolo

For CI pipelines or batch processing where no human is present to confirm actions:

qwen-code --yolo "Refactor all utility functions to use async/await"

This executes file edits, shell commands, and web fetches without interruption.

Safe Planning Mode

To preview what the agent would do without risking your codebase:

qwen-code --approval-mode plan "Add TypeScript types to the database layer"

The agent will analyze files but reject any actual write operations.

Dynamic Mode Switching

Start cautiously, then enable faster editing once you trust the session:


/approval-mode default   # Initial safe mode

... (review a few edits) ...
/approval-mode auto-edit # Now speed up file modifications

Summary

  • Approval mode is a global safety setting stored in ServerConfig that determines whether Qwen Code must prompt for user consent before executing tools.
  • Four modes exist: default (confirm all), plan (read-only), auto-edit (confirm only non-edit tools), and yolo (confirm nothing).
  • The --yolo CLI flag (alias -y) sets the mode to ApprovalMode.YOLO, enabling fully unattended execution where all tools auto-approve.
  • The flag is mutually exclusive with --approval-mode; use --approval-mode=yolo if you need to specify the mode explicitly.
  • Internally, CoreToolScheduler and individual tool implementations check config.getApprovalMode() to decide whether to render confirmation UI or proceed immediately.

Frequently Asked Questions

What happens if I use --yolo and --approval-mode together?

The CLI will reject the command with an error message: "Cannot use both --yolo (-y) and --approval-mode together. Use --approval-mode=yolo instead." This conflict check is enforced in packages/cli/src/config/config.ts at lines 538-540 to prevent ambiguous configuration.

Is YOLO mode safe for production CI environments?

YOLO mode is designed specifically for unattended automation, making it suitable for CI pipelines where no human operator is available to confirm actions. However, because it auto-approves all tools—including shell commands and file deletions—you should only use it in isolated environments or with highly trusted prompts. For safer automation, consider auto-edit mode which only bypasses confirmation for file modifications.

How do I switch approval modes during an active session?

You can change modes at runtime using the /approval-mode <mode> command in the VSCode companion or web UI. This command routes through packages/vscode-ide-companion/src/services/qwenAgentManager.ts and calls Config.setApprovalMode(), immediately affecting subsequent tool calls without requiring a restart.

What is the difference between auto-edit and yolo mode?

Auto-edit mode (ApprovalMode.AUTO_EDIT) automatically approves only file modification tools (writes, diffs, edits) while still prompting for shell commands, web fetches, and other potentially dangerous operations. YOLO mode (ApprovalMode.YOLO) removes all restrictions, auto-approving every tool including shell execution and network requests. Use auto-edit for faster coding with safety guardrails; use yolo only when you need complete hands-off automation.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →