These are the allow/ask/deny rules both CLIs consult before running a tool. A rule set to "ask" still shows the CLI's own y/n prompt right in the terminal -- this just controls whether it asks at all.
How each CLI authenticates and which model it defaults to. API keys are stored on the bridge's backend only and are never sent back to this page once saved -- leave a key field blank to keep its current value, or press Clear to remove it. Changes apply the next time you start a session for that backend; an already-running session keeps using what it started with.
Optional. If set, Claude Code bills against this API key instead of using the subscription browser login.
Format "provider/model-id", e.g. "local-network/local" or "anthropic/claude-sonnet-4-5". Leave blank to pick the model inside the CLI itself.