Reference · Rules and settings
Settings
Every field on every Settings tab, its values and its default.
The tabs, in the order they appear: General, Services, Accounts, Auto-Sync, Google Drive, Claude, Codex, Gemini, DeepSeek. Output style and turn reminder are drawn the same way on the Claude, Codex, Gemini and DeepSeek tabs. The fragment below names both once, rather than once per tab.
No tab draws a paragraph explaining a setting. The ⓘ beside a setting's name opens what it does and how to use it, and a click elsewhere or Escape closes it. The text a tab does draw reports state: a value, a status, an error, or a step of a flow that is running.
| Tab | Field | What it does |
|---|---|---|
| General | Base folder | Where Turret finds GitHub repositories and clones new ones. |
| General | External editor | What the conversation header's editor button opens a session's folder in. |
| General | MCP servers | The MCP servers from the Claude Code configuration that a new session starts with switched on. |
| General | Show thinking | Whether a conversation in this app draws the model's thinking. |
| General | Show debug cards | Whether a conversation draws debug cards about the session behind it. |
| General | Offer Coding v2 | Whether the new-session screen offers the experimental Coding v2 mode. |
| General | Mute sounds | Whether this machine plays the preset sounds a session asks for. |
| General | Map tiles | The map style every map viewer draws its base map from. |
| General | Map tile cache | How much disk the map tiles Turret has fetched may take up on this machine. |
| General | Full Disk Access | Whether Turret holds Full Disk Access, drawn on macOS alone. |
| General | Computer use | Whether sessions on this computer may look at its screen and click and type on it, for macOS, Windows and Linux. |
| General | Updates | The version and channel running now, and the control that checks for and installs the next one. |
| General | Game engine | The game engine running now, where it came from, and the controls that update it or point it at a local build. |
| Services | Peer Discovery | Whether other Turret installs on this network can find and pair with this one. |
| Services | Paired peers | The machines paired with this one, with their connection state and an Unpair button. |
| Services | Sudo | The sudo password sessions on this machine use when they ask for sudo. Drawn only where sudo exists. |
| Accounts | Tailscale | Reaches your other machines running Turret from any network. |
| Accounts, General | GitHub | The GitHub account Turret clones private repositories and lists repositories with. |
| Accounts | Telegram | The Telegram bot sessions send messages, photos and files through. |
| Accounts | Bot | The bot token sessions send through. |
| Accounts | Chats | The named chats a session may send to. |
| Accounts | Channels | People you allow can talk to sessions on this computer through the bot. |
| Accounts | Slack | The Slack app people start and steer sessions on this computer from. |
| Accounts | Slack app | The two tokens Turret answers your Slack app with. |
| Accounts | Who can approve | The people besides you who may approve a Slack session’s tool calls. |
| Accounts | Channels | The Slack channels Turret is in, and what a mention starts in each. |
| Accounts | Google Photos | The Google account the composer attaches Google Photos pictures from. |
| Accounts | Google Drive | The Google account folders sync with Google Drive through. |
| Claude, Codex, Gemini, DeepSeek | Output style | How the model writes, appended to the system prompt when a session of that engine starts. |
| Claude, Codex, Gemini, DeepSeek | Output style editor | One output style: its name, list description, system prompt section and turn reminder. |
| Claude, Codex, Gemini, DeepSeek | Turn reminder | A line from the chosen style, put in front of every message sent. |
| Claude | Personal skills | The skills in this machine's Claude Code personal skills directory, and the way to add or teleport one. |
| Claude | Permissions | Every permission rule this app has stored, your own settings-file rules, and what it always refuses. |
| Claude | How asks are answered | The permission mode every Claude session this app starts runs under. |
| Claude | Allow List | The rules this app has stored, grouped by project, and a form for writing one by hand. |
| Claude | Add a rule | A form that stores an allow, ask or deny rule for a tool, in one project or every project. |
| Claude | Your own settings files | The permission rules in your Claude settings files, read from disk for display. |
| Claude | Deny List | What Claude sessions refuse in every project, in every mode. |
| Claude | Always asks a person | What is put to you rather than answered from a rule, on every session. |
| Claude | Tools | The built-in tools every Claude session in this app is given. |
| Codex | Permissions | Everything a Codex session is allowed: its sandbox mode, network access and extra writable directories. |
| Codex | Sandbox mode | How far a Codex session may write: nowhere, its working directory, or anywhere. |
| Codex | Allow network access | Whether a sandboxed Codex session may use the network. Off by default. |
| Codex | Extra writable directories | Directories a Codex session may write to beyond its own working directory. |
| Gemini | API key | The Google API key the Gemini process takes. It is set here and never shown back. |
| Gemini | Permissions | Everything a Gemini session is allowed: its permission mode and the tools that are always refused. |
| Gemini | Permission mode | Read only, or Full — unsandboxed. Read only by default. |
| Gemini | Always refused | Tool names a Gemini session refuses in either mode. |
| DeepSeek | API key | The API key the DeepSeek process takes. It is set here and never shown back. |
| DeepSeek | Permissions | Everything a DeepSeek session is allowed: its permission mode and the tools that are always refused. |
| DeepSeek | Permission mode | Read only, or Full — unsandboxed. Read only by default. |
| DeepSeek | Always refused | Tool names a DeepSeek session refuses in either mode. |
General
General draws each setting as a row in a group: Workspace, MCP servers, Conversation or This machine.
Base folder
In the Workspace group. The folder Turret clones GitHub repositories into and finds them under.
A session started by naming a repository as owner/repo runs in that repository's folder here.
Changing the setting moves nothing: checkouts already cloned stay where they are.
| Field | Values | Default |
|---|---|---|
| Base folder | An absolute path, typed or chosen | The Repos folder in the home directory |
| Save | Writes the path | Nothing is written until pressed |
On a machine whose folder cannot be changed, the row reads Workspace and draws no field. The Android host is such a machine: its workspace root is its base folder. See Set the base folder.
External editor
In the Workspace group. What the conversation header's editor button opens a session's folder in.
| Values | Default |
|---|---|
| Whichever is installed, one specific installed editor, or a typed command | Whichever is installed |
A typed command runs with the folder appended as its last argument.
MCP servers
A group of its own. It holds a row for each server configured at user scope in the Claude Code configuration. Each row's switch sets whether a new session starts with that server on. A session's own switches, under its composer, override this list once it exists; only servers configured for every directory appear here.
| Values | Default |
|---|---|
| On, Off, per server | Off for every server |
Show thinking
In the Conversation group, this sets whether a conversation draws the model's thinking. A model that reasons before it answers writes that reasoning as a block of its own, drawn as a collapsed line above the reply. Off, no conversation in this app draws that line, while it streams or after it settles. The model is asked for exactly the same thinking either way.
Each client keeps its own answer. The desktop app opens with thinking drawn, and the phone apps open with it hidden. Moving the switch here leaves every other client as it was.
| Values | Default |
|---|---|
| On, Off | On |
Show debug cards
In the Conversation group. Puts debug cards in the conversation. A card shows the system prompt a session runs under, the options its subprocess started with, its tools and servers, and what the turn cost. Every card starts closed.
| Values | Default |
|---|---|
| On, Off | On |
Offer Coding v2
In the Conversation group, marked experimental. Offers Coding v2 on the new-session screen. A session already running in it keeps running whichever way this is set.
| Values | Default |
|---|---|
| On, Off | Off |
Mute sounds
In the This machine group. A session can ask this machine to play a short preset sound. On, the machine stays silent and the session is told the sound was muted. The volume is the system's own.
| Values | Default |
|---|---|
| On, Off | Off |
Map tiles
In the This machine group. The MapLibre style every map viewer draws its base map from. Turret fetches it through its own cache, for the desktop and for connected phones, and only from the hosts the style names. Tiles are kept at least a week, and nothing is downloaded in advance.
It saves on Enter and on blur, and refuses an address that does not start with https://.
Reset clears it to the default. The line under the field names the hosts the style leads to.
| Values | Default |
|---|---|
| An https style URL | https://tiles.openfreemap.org/styles/liberty |
Map tile cache
In the This machine group, under Map tiles. How much disk the fetched map tiles may take up. A map opened before draws from this cache without downloading it again, even when the tile server is unreachable. When the cache fills, the tiles read longest ago go first.
Picking a smaller size removes tiles straight away until the cache fits. The line under the size says how much the cache holds now.
The desktop's cache serves every connected phone. The Android app keeps its own cache on the phone, set from its own Settings.
| Values | Default |
|---|---|
| 128 MB, 256 MB, 512 MB, 1 GB, 2 GB, 4 GB, 8 GB | 512 MB |
Full disk access
In the This machine group, drawn on macOS alone, this row shows whether Turret holds Full Disk Access. The first time a session reaches the Desktop, Documents or Downloads folder, iCloud Drive, or a removable or network volume, macOS raises a dialog. A backgrounded shell command that trips this dialog waits on it until answered. A single grant covers all of them, for Turret and every session under it.
| Values | Default |
|---|---|
| Granted, Not granted | Not granted |
Computer use
In the This machine group, drawn on macOS, Windows and Linux. Whether sessions on this computer may take screenshots of its primary display and click, scroll, type and open apps on it. The setting applies to every session on the computer, wherever the session was started. Switching it off stops every session's clicks and typing at once, and their turns carry on.
| Values | Default |
|---|---|
| On, Off | Off |
The rows under the switch report state and grant nothing:
| Row | Drawn | Reads |
|---|---|---|
| Computer use helper | Where the helper that takes screenshots and sends input is missing, failed to start, or has no way into this Linux desktop | Not installed, Failed to start, Not supported |
| Accessibility | macOS | Granted, Not granted, Unknown |
| Screen Recording | macOS | Granted, Not granted, Unknown |
| Administrator apps | Windows | Not driven |
| Desktop | Linux | The desktop driven: GNOME on Wayland, or X11 and the desktop's name |
| Screen | While the screen is locked | Locked |
On macOS, Open System Settings opens the matching pane and Check again reads the state again. Turret also reads it when its window regains focus. Screen Recording takes effect after Turret relaunches.
A session never acts while a Turret window is in front, and a click inside a Turret window is refused. While a session drives, a bar at the top centre of the screen names it with Open and Stop.
Updates
In the This machine group. The installed version and channel, and the last time Turret checked for an update.
| Field | Values | Default |
|---|---|---|
| Check for updates | A control, pressed by hand | Not pressed |
| Restart to update | Shown only once a downloaded version is ready | Absent |
Services
Peer discovery
Whether other Turret installs on the same network can find this install and pair with it.
| Values | Default |
|---|---|
| On, Off | Off |
Turning this off closes every paired connection at once. Pairings themselves are kept, and pick back up on their own the next time this is switched on.
Paired peers
Every machine this install has paired with, each with its own Unpair control. Its connection state reads Off while peer discovery is switched off, or Connected, Not connected yet, or Unreachable with the last time it was seen.
Sudo
The password sessions on this machine use when they ask for sudo. Every request asks first, and Turret never shows the password back. The section is drawn only on a machine that has sudo.
| Values | Default |
|---|---|
| A password, or none | None |
Accounts
Every outside account Turret holds credentials for, a panel each, chosen from the sub-menu down the left of the tab. Each entry carries a dot for whether that account is connected, and a line naming who it is connected as. All five accounts read at a glance, without opening any panel.
| Dot | What it means |
|---|---|
| Hollow | The state has not been read yet |
| Green | Connected, with the account named beside it |
| Amber | Connected but unusable, or a connection attempt that ended badly |
| Grey | Not connected |
| Red | The state could not be read |
Each account is its own address: #/accounts/tailscale, #/accounts/github,
#/accounts/telegram, #/accounts/google and #/accounts/google-drive. A bare #/accounts
opens on Tailscale.
Tailscale
Joins this machine to the Tailscale network of the signed-in account, with a sidecar built into the app. Other Turret machines under the same account reach this machine from any network and pair with it without a PIN. See Sign in to Tailscale for the steps.
| Control | What it does |
|---|---|
| Sign in to Tailscale | Opens Tailscale in the browser, to sign in with the account the other machines use |
| The switch | Turns the sidecar on and off. Off keeps this machine signed in |
| Sign out | Takes this machine off the tailnet, without asking first |
The section warns from fourteen days before the key expires. A machine whose key has expired drops off the tailnet until someone signs in again at it.
Telegram
The bot a session sends messages through, and the chats it may send to. See Send a message to Telegram.
| State | What the panel shows |
|---|---|
| No token | A box for the token BotFather answered with, and Save |
| Token set | The bot's @username, Replace token and Remove token, and the table of chats |
| Token refused | A warning that Telegram no longer accepts the token, with Replace token |
The token is never shown back once saved. Each chat in the table carries Ask first, which holds a send behind a permission card.
GitHub
The account Turret clones private repositories with, and lists repositories from on the New
Session screen. Public repositories clone without it. The same sign-in reaches git and gh
inside sessions started afterwards; sessions already running keep the sign-in they started with.
| State | What the section shows |
|---|---|
| Signed out | Sign in with GitHub, which copies a code and opens the device page |
| Waiting | The code, its expiry, Copy code, Open GitHub again and Cancel |
| Signed in | The account name and Sign out |
| Rejected | A warning that GitHub no longer accepts the sign-in, with Sign in with GitHub beside Sign out |
| Signed in through the GitHub CLI | The account name, and a line saying gh auth logout signs it out |
| GitHub CLI rejected | A warning that GitHub no longer accepts the CLI's sign-in, and to run gh auth login |
When gh is signed in on the computer running Turret, Turret uses the CLI's token and offers no
sign-in of its own. Every Turret on that computer then shares the CLI's token. Turret's own sign-in
applies where gh is missing or signed out.
Signing out removes the stored token and asks nothing first.
Google Photos
The Google account the composer attaches pictures from Google Photos with. The section takes the JSON file of a Desktop app OAuth client from the person's own Google Cloud project. The client file and the connection are stored encrypted on this machine, and neither is shown again.
| State | What the section shows |
|---|---|
| No client | A box for the client's JSON, Choose file… and Save client |
| Client saved | Connect Google account, Replace client and Remove client |
| Connecting | Waiting for Google in the browser… and Cancel |
| Connected | Connected as and the account's address, with Disconnect |
| Photos left unticked | A warning under the address, with Connect again |
| Connection ended | A warning that Google stopped accepting the connection, with Connect Google account |
Removing the client also removes the connection made with it. The attach-image control in the composer offers From Google Photos… once a client is saved. See Attach a picture from Google Photos.
Google Drive
The Google account folders sync with Google Drive through. It uses Turret's own Google access, so there is nothing to set up in Google Cloud, and it is separate from the Google Photos account. The connection is stored encrypted on this machine. See Sync a folder with Google Drive.
| State | What the section shows |
|---|---|
| Not in this build | A line saying this build of Turret was made without Google Drive access |
| Not connected | Connect Google Drive |
| Signing in | A line asking to finish signing in in the browser, and Cancel |
| Connected | The account's address, Disconnect, and how many folders sync, with Manage |
| Drive left unticked | A warning that Drive access was not granted, with Connect again |
| Connection ended | A warning that Google stopped accepting the connection, with Reconnect |
Disconnecting stops every synced folder on this computer, and asks first. The files stay where they are, on this computer and in Drive.
Auto-Sync
Every repository a session is open in, a row per repository, sorted by folder name. A row names the folder, its path, and where its autosync stands. Opening a row shows the repository's two settings files and the same controls the session header's autosync popover has.
Autosync commits each turn's work, pulls the upstream's new commits and pushes, using git alone.
A repository's turret.json holds the setting for everyone who clones it, and
turret.local.json beside it holds this computer's. A committed turret.json that turns
autosync on asks once on each computer before anything is pushed.
| Field | Values | Default |
|---|---|---|
| Keep this repository in sync | On or off | Off |
| Saved for | This computer (turret.local.json) or Everyone (turret.json) |
The file the value already comes from, else This computer |
| Pause, Resume | Stops or restarts autosync for every session in the repository | Not paused |
| Sync now, Retry | Runs a sync at once |
A file that cannot be parsed is shown with its parse error. Its choice under Saved for stays unavailable until the file is fixed by hand.
Google Drive
Every folder on this computer that syncs with Google Drive, a row per folder, the ones waiting on a person first. A row names the folder, its path, and where its sync stands. Opening a row shows who the folder is shared with, its last sync, and anything it is waiting on. Its controls are Share, Pause, Sync now and Stop syncing.
| Group | What it holds |
|---|---|
| Synced folders | The folders that sync here, and Add a folder… |
Shared with you |
Folders other people shared with this account, each with Sync…. A folder this account can only view is shown dimmed |
| Not syncing on this computer | Folders set up to sync that this computer keeps out, each with Sync again |
A folder's turret.json records which Drive folder it syncs with, so the record travels with
the folder. turret.local.json beside it records that this computer keeps it out. Nothing is
deleted for good: a removed file goes to this computer's trash and to Drive's trash.
Claude
Engine
The engine card for Claude Code, the same card the Set up an engine screen shows. It reports whether Claude Code works on this computer and carries the buttons that install, update, fix, sign in and sign out.
| Field | Values |
|---|---|
| Status | Working, or Not ready with the cause |
| Version row | The installed version, how it was installed, and whether a newer version is out |
| Install Claude Code | Offered while no copy is installed |
| Update Claude Code | Offered beside the version row while a newer version is out |
| Fix… | Offered while a copy is installed and does not start |
| Sign in to Claude Code | Offered while Claude Code is installed and signed out |
| Sign out | Offered while Claude Code works |
Install downloads Claude Code from Anthropic into ~/.local/bin, with no administrator rights, and shows
each step. A copy installed by Homebrew, WinGet or a Linux package gets no Update button. The
card names the package manager instead. Claude Code updates itself, so the tab has no switch for it.
Sign in opens a sheet that runs claude auth login and shows what it prints. A box under the
output sends what is typed to the CLI. Closing the sheet, Escape and Cancel sign-in all cancel the
run, and the sheet closes itself when the CLI exits successfully.
The footer's Sign in another way signs in with an Anthropic Console account or single sign-on instead. Sign out asks first, since it signs Claude Code out in every terminal on the computer too.
Fix opens a sheet that lists every copy of Claude Code Turret found, with what each copy printed when it was started. Its single action uses a copy that works, installs a fresh copy, or switches an npm copy to Anthropic's installer. An old copy stays where it is. Choose executable… in the sheet points Turret at a copy it did not find.
Permissions
How every Claude session's asks are answered.
| Field | Values | Default |
|---|---|---|
| Permission mode | Manual, Auto, Bypass | Manual |
Manual sends every ask to Turret's own modal, and nothing runs until it is answered. Auto lets Claude Code's own classifier answer what it is confident about, escalating only what it is not. Bypass asks nothing except the Deny List and always-asks below, and still refuses a write outside the working directory whatever this is set to.
The Allow List holds every rule Turret has stored, grouped by project scope, with a form to add a rule by hand. Turret cannot show how many times a rule has fired or when it last matched — the CLI never reports that. A separate, read-only section shows the rules already in Claude Code's own settings files; Turret never writes to those files.
The Deny List is refused on every session, in every project, under every mode above, bypass included. A removed row can be restored to its built-in defaults. The always-asks are put to a person rather than answered from a rule, on every session and in every project. Each starts switched on, and can be switched off independently.
Built-in tools
Every built-in tool Claude sessions are given, grouped, each with an on/off switch. A switched-off tool is left out of the list the model sees and is never asked for at all. The tool list is fixed when a session's subprocess starts, so a change reaches a running session only the next time it spawns.
| Values | Default |
|---|---|
| On, Off, per tool | On for every tool |
Codex
Engine
The engine card for Codex. It has the same fields as the Claude tab's card, with Install Codex,
Update Codex, Fix…, Sign in to Codex and Sign out. Install runs OpenAI's own installer into
~/.local/bin, with no administrator rights. Sign in runs codex login, and the sheet's Sign in another way offers a one-time
code, for a computer with no browser to finish in.
| Field | Values | Default |
|---|---|---|
| Keep Codex up to date | On, Off | Off |
While Keep Codex up to date is on, Turret runs codex update when a newer Codex is out and no Codex
session is working.
Sandbox
The whole of what a Codex session is allowed, decided before it starts rather than asked mid-turn.
| Field | Values | Default |
|---|---|---|
| Sandbox mode | Read only, Workspace write, Full access | Workspace write |
| Network access | On, Off | Off |
| Extra writable directories | Any number of paths | None |
Read only lets a session read anywhere it can reach and write nowhere. Workspace write adds writes inside the session's own working directory and the extra directories above. Full access removes the sandbox: a session can read and write anywhere the machine lets it.
Gemini
API key
Sets, replaces or clears the Google API key a Gemini session runs with, or reports whether a key is already set. Encrypted on the machine that holds it, and never read back — here or from a phone.
| Values | Default |
|---|---|
| Set, Not set | Not set |
Permissions
The whole of what a Gemini session is allowed, frozen before its chain starts. No approval prompt exists on either side of this protocol.
| Field | Values | Default |
|---|---|---|
| Permission mode | Read only, Full — unsandboxed | Read only |
| Always refused | Any number of tool names | None |
Read only lets a session read, search and plan; Bash and writes are refused outright, at the tool layer. Full runs as the desktop user, in the session's own working directory, with Turret's own environment — no sandbox, no workspace boundary, no approval prompt.
DeepSeek
API key
Sets, replaces or clears the key a DeepSeek session runs with, or reports whether a key is already set. Encrypted on the machine that holds it, and never read back — here or from a phone.
| Values | Default |
|---|---|
| Set, Not set | Not set |
Permissions
The whole of what a DeepSeek session is allowed, frozen before its chain starts. No approval prompt exists on either side of this protocol.
| Field | Values | Default |
|---|---|---|
| Permission mode | Read only, Full — unsandboxed | Read only |
| Always refused | Any number of tool names | None |
Read only lets a session read, search and plan; Bash and writes are refused outright, at the tool layer. Full runs as the desktop user, in the session's own working directory, with Turret's own environment — no sandbox, no workspace boundary, no approval prompt.