Enable or disable
-g/--global to apply it across all your projects, or --local for a gitignored personal override that nobody else sees.
--client <name> (or --client all); by default it applies to the clients detected in the project.
What gets redacted
Enabling privacy mode injects two flags into every DevTools MCP server’s environment:
You still get the structural signal: which tools ran, verdicts, timing, and the session lifecycle all keep flowing. The heavy, potentially sensitive payloads stay on your machine. Disabling privacy mode removes both flags, so the DevTools resume their default reporting.
This is a DevTools-side switch. The CLI’s own event pipeline already whitelists tool input and strips tool responses before sending - shell commands, for example, are reduced to coarse binary/subcommand labels, and a command that can’t be parsed confidently is dropped rather than guessed - so privacy mode is specifically about the extra detail and artifacts the DevTools MCP servers contribute.
Tool-call reasons
IronBee asks its verifier and scenario sub-agents to annotate each DevTools call with a one-sentence reason - why this call, what it expects to see - which is recorded on thetool_call event and rendered on the Console timeline. It’s a readability feature: it never changes what a tool does or whether a cycle passes.
Because it’s model-authored free text, it’s worth knowing exactly where it sits:
- Privacy mode does not redact it. The two flags above gate the DevTools’ tool input/output detail and artifacts; the reason is a separate top-level field on the
tool_callevent that the CLI records itself. - There’s no switch for it. The channel that carries it (
TOOL_INPUT_EXTRAS_ENABLE) is one of the IronBee invariants that always wins last when the DevTools MCP env is rendered, so anironbeeDevTools.envoverride can’t turn it off. If you need it gone, suspend the Collector (collector.enable: false) - then nothing ships at all. - IronBee instructs the agent to keep it to one sentence and to put no secrets, tokens, or personal data in it. The instruction lives in the sub-agent prompts, so it only reaches the modes that have one.
Scope: reasons come from the delegated sub-agents - Claude Code’s verifier and scenario agents, and Codex in its default
sub-agent mode. Where the main agent drives the tools itself (Cursor, and Codex in main-agent mode) no annotation is requested, so no reason is recorded. On Claude Code there’s one extra source: a Bash call the agent didn’t annotate records the model’s own description for the command (a field Claude Code already asks for) instead. Codex and Cursor shell tools carry no description.How it relates to telemetry and the collector
These three are independent knobs, privacy mode doesn’t touch the other two:
To stop sending your session data entirely, suspend the Collector (
collector.enable: false) rather than reaching for privacy mode: privacy mode trims what is sent, not whether anything is sent.
VCS linkage sends repository and branch names through the CLI’s own pipeline, which privacy mode doesn’t touch (it gates the DevTools payloads). If branch names in your repos can carry sensitive text, opt out of the linkage itself with
ironbee config set vcs.enable false.For a checkout of a github.com repository, every event, including the DevTools events, also carries the repository’s owner/repo, so the console can file it under the GitHub project. That’s independent of vcs.enable. The only way to stop it is to suspend the Collector.Config equivalent
The command is a convenience wrapper around one config key:privacy.enable value and re-render artifacts. The key is read from disk when the DevTools env is built, so the layer that wins (local > project > global) is the one that takes effect.
Gate only one channel
Privacy mode flips both flags together. If you want, say, recordings off but tool detail on, set the DevTools env override yourironbeeDevTools.env values are applied after the privacy flags, so they win:
What’s next?
Telemetry
The other data toggle - anonymous CLI telemetry.
Configuration
The
privacy.enable key and the DevTools env overrides in full.