Skip to main content
Add .embedderignore at the project root to restrict direct agent edits to selected files. Embedder can still read, search, and reference matching files.
.embedderignore
This is an edit restriction, not a way to hide files or a filesystem sandbox. It does not prevent arbitrary build tools or scripts from writing to those paths.

Write patterns

Patterns use gitignore-style syntax:
  • vendor/ matches a directory and its contents.
  • *.bin matches that suffix at any depth.
  • src/**/*.h matches headers below src.
  • /build anchors the match to the directory containing the rule file.
  • !config/public.json allows a path after an earlier restriction.
  • # starts a comment; blank lines are ignored.
For example, allow two files in an otherwise protected directory:

Use rules for one package

A nested .embedderignore applies below its directory:
packages/legacy/.embedderignore
Rules closer to a file can override broader rules. Check nested files when a pattern behaves unexpectedly. Matching is case-insensitive on macOS and Windows by default, and case-sensitive on Linux.

Understand the boundary

Matching paths remain readable. Direct edits and recognized shell writes to them are blocked, even with Skip all approvals enabled. A build system, custom program, or script can write files without the restriction identifying every destination. Commands you enter yourself through the terminal UI’s ! mode are also outside this restriction. Use operating-system permissions or a separate controlled environment if you need to prevent all writes by other programs.

Permit an intended edit

Narrow or remove the matching rule, or add an appropriate exception. Changes to .embedderignore apply without restarting the conversation. There is no one-time approval that bypasses a matching rule. Ask Embedder to explain the blocked path before changing the restriction.

Troubleshoot

  • A protected file is still visible: expected; the restriction applies to edits.
  • A rule does not match: check the active project root, relative path, and nested overrides.
  • A build changed a file: the build may write beyond the recognized direct-edit forms.
  • An alias is blocked: rules also apply to the resolved target of a symbolic link.
Last modified on September 12, 2026