Use the GitLab Duo CLI
- Tier: Premium, Ultimate
- Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated
You can use the GitLab Duo CLI in two modes:
- Interactive mode: Provides a chat experience similar to GitLab Duo Chat in the GitLab UI or in editor extensions. Supports build, plan, and auto modes.
- Headless mode: Enables non-interactive use in runners, scripts, and other automated workflows.
Prerequisites
- The GitLab Duo CLI installed and set up.
- A default GitLab Duo namespace set, or an open project that has access to GitLab Duo.
Interactive mode
To use the GitLab Duo CLI in interactive mode:
Based on your setup, enter the command to start interactive mode:
glab duo cliduoThe prompt
>appears in your terminal window. After the prompt, enter your question or request and press Enter.For example:
What is this repository about? Which issues need my attention? Help me implement issue 15. The pipelines in MR 23 are failing. Please help me fix them.
To cancel a response while the GitLab Duo CLI is working, press Escape. The GitLab Duo CLI stops the current operation and returns to the prompt.
Use the ↑ key to view your prompt history, or Control+R to search it.
Switch modes
In interactive mode, you can switch the GitLab Duo CLI between modes as you work:
| Mode | Permissions | How it works |
|---|---|---|
| Build mode (default) | Read-write | GitLab Duo can execute tasks and make changes to your project. |
| Plan mode | Read-only | GitLab Duo can analyze your project and create plans without making changes. |
| Auto mode (beta) | Read-write | GitLab Duo can use tools without asking for approval first. For more information, see auto mode. |
For example, start by discussing a problem with GitLab Duo in plan mode. When you’re ready, switch to build mode and instruct GitLab Duo to implement the plan.
The GitLab Duo CLI displays the current mode under the > prompt. To switch between modes, press
Tab.
Slash commands
In interactive mode, use slash commands to configure the GitLab Duo CLI and perform actions. Enter a slash command at the prompt and press Enter.
The following slash commands are available:
| Command | Description |
|---|---|
/copy | Copy the last GitLab Duo response to the clipboard. |
/doctor | Show diagnostics for the GitLab Duo CLI environment. |
/exit | Exit the GitLab Duo CLI. |
/feedback | Submit a bug report or feature request. |
/goal | Start a session that works toward a goal. |
/help | Display a list of available slash commands. |
/mcp | View configured MCP servers and their status. |
/model | Switch the AI model for the current session. |
/new | Start a new chat session. |
/sessions | Browse, search, and switch sessions. |
/settings | Open the settings panel. |
/skills | List available Agent Skills in the current project. |
You can also create your own slash commands. For more information, see custom slash commands.
Settings
To change a setting:
- In interactive mode, type
/settingsand press Enter. - Use the arrow keys to navigate the list of settings.
- To change the selected setting, press Enter or Space.
- To close the panel, press Escape.
Changes persist across sessions.
The following settings are available:
| Setting | Description |
|---|---|
| Telemetry | Send anonymous usage data to improve GitLab Duo. |
| Enable global skills | (Experimental) Discover user-level Agent Skills from ~/.agents/skills/ and ~/.gitlab/duo/skills/. A restart is required for changes to take effect. |
| Notifications | Control system notifications (auto or disabled). |
| Show work items on session start | Display your open work items when you start a new session. |
| Run suggested prompts as /goal sessions | Run suggested prompts as /goal sessions instead of plain chat messages. A restart is required for changes to take effect. |
| Theme | Change the theme setting. Options include auto, dark, light, dark high contrast, and light high contrast. |
System notifications
The GitLab Duo CLI can send a system notification when a session needs your attention (for example, when it finishes a task or requires a tool approval) while the terminal window is not focused.
Notifications are controlled by the Notifications setting in the settings panel:
auto(default): Send a system notification when the terminal is unfocused.disabled: Never send system notifications.
Tool approvals
When GitLab Duo needs to use a tool, it prompts you to approve before it begins. For example, when it needs to read a file or run a command.
Your options are:
- Approve: GitLab Duo can use the tool once.
- Approve for session: GitLab Duo can use the tool with these arguments for the remainder of the session. Different arguments require additional approval.
- Deny: GitLab Duo cannot use the tool.
To use the Approve for session option, your administrator must turn it on for your group or instance. For more information, see tool approvals.
Auto mode
- Tier: Premium, Ultimate
- Offering: GitLab.com
- Status: Beta
The availability of this feature is controlled by a feature flag. For more information, see the history.
In auto mode, GitLab Duo uses tools without asking for approval. Where your settings allow it, GitLab Duo can perform the following actions:
- Run any shell command, including commands that delete files or change your system.
- Run
gitcommands, including commits and pushes. - Create or update issues, merge requests, and other GitLab resources.
- Run MCP tools and start flows.
Auto mode does not override agent tool governance. Tools set to Always Deny stay blocked.
GitLab Duo can make mistakes. Any content that GitLab Duo reads, such as files, issues, merge requests, or web pages, might contain malicious instructions used for prompt injection. To limit the risk:
- Use auto mode only in repositories you trust and on branches you can discard.
- Do not use auto mode on devices or in shells that contain sensitive credentials.
- Stay in the session and review all changes before merging.
- Switch back to build mode when you do not need auto mode.
For more information, see security considerations for editor extensions.
Turn on auto mode
The Auto mode setting is off by default. Auto mode must be turned on for your group or project before you can use it. Subgroups and projects inherit the setting from their parent group.
Prerequisites:
- The Owner role for the group.
To turn on auto mode for a group:
- In the top bar, select Search or go to and find your group.
- Select Settings > GitLab Duo.
- Select Change configuration.
- From the Auto mode dropdown list, select one of the following options:
- On by default: Auto mode is available. Subgroups and projects can turn it off.
- Off by default: Auto mode is not available. Subgroups and projects can turn it on.
- Always off: Auto mode is not available. Subgroups and projects cannot turn it on.
- Select Save changes.
If a parent group has set auto mode to Always off, the project setting is locked and cannot be turned on.
Prerequisites:
- The Maintainer or Owner role for the project.
To turn on auto mode for a project:
- In the top bar, select Search or go to and find your project.
- Select Settings > General.
- Expand GitLab Duo.
- Turn on the Auto mode toggle.
- Select Save changes.
Use auto mode
Prerequisites:
- GitLab Duo CLI 9.22.0 or later.
- Auto mode turned on for your project.
To use auto mode:
- Start or restart the GitLab Duo CLI in your project to pick up the setting.
- Press Tab until the mode under the
>prompt showsauto. - Enter your prompt. Auto mode applies from that prompt onward.
To stop using auto mode, press Tab to switch to another mode. The change applies to your next prompt.
Auto mode does not persist between sessions.
Each new or resumed session, including a session you start with /new, starts in build mode.
Troubleshooting auto mode
If auto does not appear when you press Tab:
- Confirm that the Auto mode setting is turned on for your project.
- Confirm that no parent group is set to Always off.
- Restart the GitLab Duo CLI.
Headless mode
Use headless mode with caution and in a controlled sandbox environment.
To run a workflow in non-interactive mode, use the command for your setup:
Use glab duo cli run:
glab duo cli run --goal "Your goal or prompt here"For example, you can run an ESLint command and pipe errors to the GitLab Duo CLI to resolve:
glab duo cli run --goal "Fix these errors: $eslint_output"Use duo run:
duo run --goal "Your goal or prompt here"For example, you can run an ESLint command and pipe errors to the GitLab Duo CLI to resolve:
duo run --goal "Fix these errors: $eslint_output"When you use headless mode, the GitLab Duo CLI:
- Bypasses manual tool approvals and automatically approves all tools for use.
- Does not maintain context from previous conversations.
A new workflow starts every time you execute the
runcommand.
Select a model
You can select a model for interactive mode or headless mode.
For interactive mode
The model you select persists across sessions, and you can switch models mid-conversation without losing context.
Prerequisites:
- GitLab Duo CLI 8.76.0 or later.
To select a model for interactive mode:
- In interactive mode, type
/modeland press Enter. - Use the arrow keys to scroll through the list of available models, or enter a model name to filter the list.
- Select a model and press Enter to switch to it.
For headless mode
The model you select does not persist across sessions.
Prerequisites:
- GitLab Duo CLI 8.68.0 or later.
To select a model for headless mode:
Find the
gitlab_identifierfor the model.When you run the GitLab Duo CLI, set the
--modeloption or theGITLAB_DUO_MODELenvironment variable to thegitlab_identifiervalue.Use the
--modeloption:glab duo cli --model <gitlab_identifier_for_the_model>Use the
GITLAB_DUO_MODELenvironment variable:GITLAB_DUO_MODEL=<gitlab_identifier_for_the_model> glab duo cliFor example, to use
GPT-5-Codex - OpenAI:glab duo cli --model gpt_5_codexGITLAB_DUO_MODEL=gpt_5_codex glab duo cliUse the
--modeloption:duo --model <gitlab_identifier_for_the_model>Use the
GITLAB_DUO_MODELenvironment variable:GITLAB_DUO_MODEL=<gitlab_identifier_for_the_model> duoFor example, to use
GPT-5-Codex - OpenAI:duo --model gpt_5_codexGITLAB_DUO_MODEL=gpt_5_codex duo
Switch sessions
GitLab Duo Chat sessions store your conversation history and workflow data, and are shared across the GitLab Duo CLI, the GitLab UI, and editor extensions.
For example, you can start a conversation in your browser and continue it in your terminal.
To browse and switch to a session:
- In interactive mode, type
/sessionsand press Enter. - Use the arrow keys to scroll through the list of available sessions, or enter text to filter the list.
- Select a session and press Enter.
To switch to a session in headless mode, use the --existing-session-id option.
Model Context Protocol (MCP) connections
To connect the GitLab Duo CLI to local or remote MCP servers, use the same MCP configuration as the GitLab IDE extensions. For instructions, see configure MCP servers.
Related topics
- GitLab Duo CLI complete reference
- Security considerations for editor extensions
- GitLab CLI
- Customize GitLab Duo Agent Platform
- GitLab Duo Agent Platform sessions
Troubleshooting
When working with the GitLab Duo CLI, you might encounter the following issues.
Certificate errors
You might encounter certificate errors:
Error: unable to verify the first certificate
Error: self-signed certificate in certificate chainThese errors occur if your organization uses a custom Certificate Authority (CA) for an HTTPS-intercepting proxy or similar.
To resolve certificate errors, use one of the following methods:
Use the system certificate store (recommended):
If your CA certificate is installed in your operating system’s certificate store, configure Node.js to use it. Requires Node.js 22.15.0, 23.9.0, or 24.0.0 and later.
If you run the GitLab Duo CLI in a container, install the CA certificate in the container’s system store, not the host system store.
export NODE_OPTIONS="--use-system-ca"
Specify a CA certificate file:
For older Node.js versions, or when the CA certificate is not in the system store, point Node.js to the certificate file directly. The file must be in PEM format.
If you run the GitLab Duo CLI in a container, set the path to a location in the container. Use a volume mount to provide the certificate file.
export NODE_EXTRA_CA_CERTS=/path/to/custom-ca.pem
Ignore certificate errors
If you still encounter certificate errors, you can disable certificate verification.
Disabling certificate verification is a security risk. You should not disable verification in production environments.
Certificate errors alert you to potential security breaches, so you should disable certificate verification only when you are confident that disabling verification is safe.
Prerequisites:
- You verified the certificate chain in your browser, or your administrator confirmed that this error is safe to ignore.
To disable certificate verification:
export NODE_TLS_REJECT_UNAUTHORIZED=0