.loopback.yml
Everything in .loopback.yml is optional: defaults are detected from the repository and the workspace settings. The onboarding pull request writes the file with the choices you made in the setup, and again whenever you change them in the settings. A change pushed to the file on the default branch applies when it restricts the workspace (share: references-only, a lower autonomy, release.merge: off, release.changelog: false) or sets the repository’s release.tag; a wider setting is changed in the settings.
Reference
Generated from the schema the API and the runner validate the file with.
| Key | Values | Default | Description |
|---|---|---|---|
agent.mode | managed | runner | mcp | runner | Where the analysis runs. |
agent.name | claude-code | codex | opencode | builtin | cursor | windsurf | zed | kiro | antigravity | continue | cline | copilot | other | builtinOther in MCP mode | The agent that works the jobs. |
agent.auth | api-key | chatgpt | bedrock | vertex | subscription | api-key | How the agent authenticates with its model provider. |
agent.model | Any text | The provider’s default | Model of the agent, when you want a specific one. |
autonomy | copilot | approve | autopilot | approve | What happens without a click: Copilot, Approve or Autopilot. |
test | Any text | auto | The test command; auto detects it from the package manager and the manifest. |
release.tag | semver | calver | manual | semver | How the tag of a release is chosen: semver patch, calver or manual. |
release.merge | squash | merge | rebase | off | squash | Merge method after the approval; off waits for a person to merge, then tags. |
release.changelog | true | false | true | Write the changelog in the GitHub Release. |
share | snippets | references-only | snippets | references-only keeps code snippets out of diagnoses. |
Example
# .loopback.yml — everything is optional, defaults are auto-detectedagent: mode: runner name: claude-code auth: api-keyautonomy: approvetest: npm testrelease: tag: semver merge: squash changelog: trueshare: snippetsValidation
- Unknown keys are errors, also inside sections: a typo such as
nmaefails instead of being ignored. - Forbidden combinations are refused with the reason, for example a Claude subscription with
mode: runner. - With
share: references-only, diagnoses carry file and line references but no code snippets.
The workflow file
The same pull request adds the workflow that runs jobs in your GitHub Actions. It is described in GitHub Action.
# .github/workflows/loopback.ymlname: Loopbackrun-name: Loopback ${{ github.event.client_payload.job_id }}on: repository_dispatch: types: [loopback-job]permissions: contents: write pull-requests: write id-token: write # OIDC sign-in to Loopbackconcurrency: group: loopback-${{ github.event.client_payload.job_id }}jobs: run: runs-on: ubuntu-latest timeout-minutes: 75 steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 persist-credentials: false - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 if: ${{ github.event.repository.private }} with: path: .vexp key: loopback-index-${{ github.run_id }}-${{ github.run_attempt }} restore-keys: loopback-index- - name: Install bubblewrap run: sudo apt-get update -q && sudo apt-get install -y bubblewrap - uses: loopback-dev/action@v1 with: agent-key: ${{ secrets.LOOPBACK_AGENT_KEY }} api-url: "https://api.loopback.so" - uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 if: ${{ !cancelled() && github.event.repository.private }} with: path: .vexp key: loopback-index-${{ github.run_id }}-${{ github.run_attempt }}