Warp’s AI Agent: The Terminal That Codes
Warp is a terminal that grew a coding agent. What the Warp Agent does today, where it runs, which models it uses, how it handles MCP servers, rules files and permissions, what its privacy settings mean, and how it compares with running Claude Code in the same window.
7 min read
Warp AI is the coding agent built into Warp, a terminal for macOS, Linux and Windows that now calls itself an agentic development environment. The agent, called the Warp Agent, takes a task in plain English, runs commands in a real terminal, reads the output, edits files and asks before anything risky. It runs in the Warp app, in any other terminal through the warp command, and in the cloud. It uses models from OpenAI, Anthropic, Google, xAI and open-weights labs, reads project rules from AGENTS.md, and connects to MCP servers. Warp can also host other agents, such as Claude Code or Codex, in its tabs with extra features around them.
What Warp is
At its core Warp is a terminal: commands and their output grouped into Blocks, an input editor that behaves like a text editor, and command search. Around that it has added a code editor, code review and Git worktree support, and its client is open source under AGPL v3. The AI features sit on top of that terminal rather than inside an IDE, which is the main reason people pick it: the agent sees the same shell, the same SSH sessions and the same long-running processes you do.
The Warp Agent, and what it used to be called
Warp’s agents overview (opens in a new tab) describes the Warp Agent as its built-in coding agent that works through multi-step tasks, running commands and using the output to decide what to do next, while you approve actions and review diffs. You reach the same agent three ways:
- In the Warp app: the full experience, with the conversation beside the terminal, code review and agent management.
- In any terminal: the Warp Agent CLI, started with
warp, runs the same agent in another terminal emulator, over SSH, or on a machine without the Warp app. It uses the same account, models, rules and skills. - In the cloud: cloud agents run in the background from a trigger, a schedule or an integration, on what Warp calls its Automation Platform, managed from the Oz web app.
Names have moved. Older videos and help articles say Agent Mode, which replaced Warp’s original AI chat panel; the docs now say Warp Agent. The # command generator is labeled Generate (Legacy), and its use inside interactive programs has been replaced by Full Terminal Use, where the agent drives REPLs, database shells and full-screen apps itself. Agent Memory, which shares memory across the Warp Agent, Claude Code and Codex, is a research preview enabled per team.
What the agent can do
- Planning:
/planwrites an editable plan in Warp’s editor. Each revision is versioned, and you can ask the agent to run all of it or one phase. - Task lists: longer jobs get a task list that updates as steps finish.
- Codebase Context: Warp indexes Git-tracked files so the agent can find the right code; Warp says no code is stored on its servers.
- Full Terminal Use and Computer Use: the agent can interact with running terminal programs, and with a desktop through screenshots, clicks and typing.
- Skills and slash commands: reusable instructions for specific jobs, invoked by name.
- Web search: optional, for current documentation.
Models
Warp picks for you or lets you choose. Its model choice page (opens in a new tab) lists four Auto options (Responsive, Cost-efficient, Genius and Open-weights) and named models from OpenAI, Anthropic, Google and xAI, plus open-weights models such as Kimi, GLM and Qwen hosted through Fireworks AI, with a reasoning level per model. Each Agent Profile sets a base model, and planning can use a separate one. You can bring your own Anthropic, OpenAI or Google API key, stored only on your device, or point Warp at an OpenAI-compatible endpoint; enterprises can route through Amazon Bedrock or Vertex AI. One limit to know: Warp’s FAQ says you cannot sign in with a ChatGPT or Claude consumer subscription to power the Warp Agent.
MCP servers
The Warp Agent is an MCP client. Warp’s MCP page (opens in a new tab) covers local servers started from a command and remote servers reached by URL over Streamable HTTP or SSE, with custom headers, environment variables and OAuth login through the browser. Add them under Settings > Agents > MCP servers; configurations copied from most other clients can be pasted in as they are.
{
"mcpServers": {
"fenbs": {
"url": "https://fenbs.ai/api/mcp"
}
}
}Warp also reads servers from files. ~/.warp/.mcp.json and a project’s .warp/.mcp.json are its own, and it can pick up Claude Code’s and Codex’s configurations and a shared .agents/.mcp.json too. Global Warp servers start automatically; servers from other agents start only after you turn on a toggle; and project-scoped servers from any source need your approval each session. That last rule is worth keeping, because a cloned repository should not be able to start servers on your machine by itself. Which servers the agent may call without asking is set per profile, with an MCP allowlist and denylist.
Rules: AGENTS.md, WARP.md and Global Rules
Warp has Global Rules, which apply everywhere and live in Warp Drive, and Project Rules, which live in the repository. Its rules page (opens in a new tab) says Project Rules go in AGENTS.md, with WARP.md still read for backward compatibility, and that the file name must be in capitals. Warp applies the file at the root and in the current directory, and makes a best effort with other subdirectories you edit in; the most specific file wins, then the root, then Global Rules. If your project already has a CLAUDE.md, .cursorrules, GEMINI.md or .github/copilot-instructions.md, Warp can link it to AGENTS.md rather than keeping a second copy. How the other tools resolve their files is in AI context files compared, and a starting file is in AGENTS.md examples.
Permissions and autonomy
- Agent Profiles set autonomy per action (apply diffs, read files, create plans, run commands, interact with running commands): Agent Decides, Always ask, Always allow or Never.
- A command allowlist runs matching commands without asking; it is empty by default. A command denylist, which starts with
curl,wget,rmandeval, always asks and beats both the allowlist and Always allow. - Run until completion (
Cmd+Shift+Ion macOS,Ctrl+Shift+Ielsewhere) auto-approves every step of the current task and, by default, bypasses the denylist too. Turn that off under Settings > Agents > Warp Agent > Input if you want the denylist to hold. Denylist rules an admin sets for a team are never bypassed.
Privacy settings
Warp states that it is SOC 2 compliant and has zero data retention agreements with its contracted model providers. What Warp itself collects depends on your plan and one setting. Its privacy page (opens in a new tab) says that if “Help improve Warp” is on, Warp may collect AI interactions and console inputs, always with secret redaction; turn it off under Settings > Privacy and, it says, no console interactions are persisted on its servers. Business and Enterprise plans are covered by a zero data retention agreement under which no AI interaction or console data is collected. You can also switch the AI features off entirely under Settings > Agents > Warp Agent. The FAQ adds that Warp reserves the right to use collected data to train models, so check the setting before you paste anything sensitive.
Warp vs Claude Code, and running both
These are less rivals than neighbors. Claude Code is Anthropic’s agent, running Claude models in any terminal, IDE extensions, a desktop app and the web, and reading CLAUDE.md. Warp is a terminal whose own agent runs models from several providers and reads AGENTS.md. And Warp hosts Claude Code: its third-party CLI agents page (opens in a new tab) lists Claude Code, Codex, OpenCode, Copilot CLI, Cursor CLI, Gemini CLI and others, and adds a rich input editor (Ctrl-G), code review comments and Remote Control around them, with notifications for Claude Code through a plugin. So the practical choices are Warp’s agent, Claude Code inside Warp, or Claude Code in whatever terminal you already use. Other terminal agents are compared in Claude Code alternatives.
Keep the task list where every agent can reach it
Warp’s plans and task lists belong to a conversation. If you run Warp’s agent in one tab and Claude Code in another, each keeps its own. fenbs keeps one list both can reach over MCP: tasks in lanes To Do, Next Up, In Progress and Completed, each with a note, a plan and a test status, and History recording which assistant changed what. Add the URL above in Warp, or claude mcp add --transport http fenbs https://fenbs.ai/api/mcp in Claude Code, and sign in with OAuth, or issue a token with a name, scopes and an optional expiry under Settings.
Related
Set-up pages: Claude Code, Codex CLI and the MCP docs. Before loosening approvals: how to keep an AI agent from wrecking your board.