mochi trust
Manage which workspaces can run tasks without asking
Synopsis
Workspace trust decides whether the desktop app asks before running a task, and whether agents connected over MCP may run it at all. A workspace starts out unknown until you trust or restrict it. Rules refine that per task: 'allow' runs matching tasks in a workspace you haven't trusted, 'ask' confirms matching tasks in one you have.
Rule patterns are '[verb ]name-glob', matched against 'name' or 'namespace:name', where '*' matches anything: 'build ', 'deploy ', ':prod-'. Typing a command in a terminal is never blocked by trust.
Options
| Flag | Type | Description |
|---|---|---|
-h, --help | help for trust |
Options inherited from parent commands
| Flag | Type | Description |
|---|---|---|
-L, --log-level | string | Log verbosity level (debug, info, fatal) (default "info") |
--sync | Sync flow cache and workspaces |
See also
- mochi — Run and organize your development tasks
- mochi trust check — Report whether an executable can run without asking
- mochi trust list — List every workspace's trust
- mochi trust reset — Forget a workspace's trust and rules, so you are asked again
- mochi trust rule — Allow or ask for specific tasks within a workspace
- mochi trust set — Trust or restrict a workspace