Skip to content

mochi trust ​

Manage which workspaces can run tasks without asking

Synopsis ​

Workspace trust decides whether the desktop app asks before running a task, and whether agents connected over MCP may run it at all. A workspace starts out unknown until you trust or restrict it. Rules refine that per task: 'allow' runs matching tasks in a workspace you haven't trusted, 'ask' confirms matching tasks in one you have.

Rule patterns are '[verb ]name-glob', matched against 'name' or 'namespace:name', where '*' matches anything: 'build ', 'deploy ', ':prod-'. Typing a command in a terminal is never blocked by trust.

Options ​

FlagTypeDescription
-h, --helphelp for trust

Options inherited from parent commands ​

FlagTypeDescription
-L, --log-levelstringLog verbosity level (debug, info, fatal) (default "info")
--syncSync flow cache and workspaces

See also ​