> ## Documentation Index
> Fetch the complete documentation index at: https://cli-docs.relai.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# User configuration

> Change RELAI CLI preferences and global permissions in ~/.relai/config.toml.

RELAI stores machine-wide CLI preferences in `~/.relai/config.toml`. These
settings apply across repositories for your user account. The file uses TOML;
create it if it does not exist, and keep it private because it can contain an
API key.

Use `relai setup --theme light` or `relai setup --theme dark` to change the
terminal theme. Use `relai setup` and the `relai auth` commands to manage your
connection and sign-in. Edit the file directly for permission rules and
telemetry preferences.

## Terminal theme

Choose `light` or `dark` under `[ui]`. If no theme is set, RELAI uses `light`.

```toml theme={"system"}
[ui]
theme = "dark"
```

For profile behavior, protected paths, and runtime secrets, see
[Configuration & permissions](/configuration).

## Permissions

`[permissions] profile` sets the default permission profile for agentic CLI
workflows. The default is `auto`. You can choose `auto`, `accept_edits`, or
`ask`. On commands that expose it, `--permissions` overrides this setting for that run.
Simulation and optimization do not expose this flag. Resume resolves the profile
again, so repeat a permission override when you need the same boundary.

```toml theme={"system"}
[permissions]
profile = "accept_edits"

[permissions.read]
allow = ["src/**", "README.md"]
deny = ["src/private/**"]

[permissions.write]
allow = [".relai/**", "docs/generated/**"]
```

Read and write `allow` lists restrict access to matching paths. If omitted,
they allow the full workspace; `allow = []` allows no paths. `deny` lists block
matching paths. Patterns use Gitignore-style syntax and are relative to the
repository root. Global allowlists combine with any repository allowlists by
intersection. Global and repository deny rules combine, and deny rules and
built-in protected paths always take precedence.

The repository's `.relai/config.toml` can add path rules but cannot set the
profile or loosen global rules. See [Permissions](/cli/init#permissions) for
profile behavior and examples.

## Settings managed by RELAI

RELAI also stores connection and sign-in metadata under `[api]`, plus update
check state under `[updates]`. Manage the connection with `relai setup`,
`relai auth login`, and `relai auth logout` instead of editing those fields.
OAuth tokens are kept as plaintext in the user-only
`~/.relai/credentials.json`, not in this file. If API-key authentication is
configured, the key is sensitive; do not share or commit either file.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.