All 6 Claude Code permission modes, and what each one allows

Claude Code has 6 permission modes, not the 3 most guides teach. Here is what each one lets through, how auto mode decides what is safe, and which to use when a job runs for an hour without you.

Navid Moazzezby Navid Moazzez·Updated 2. okt. 2026·7 min read·

The first real question about Claude Code is not what it can do. It is what it is allowed to do to your files.

Most guides answer that with 3 modes: ask first, accept edits, or turn the safety off. There are 6, and 1 of the 3 missing ones is the one you want when a job is running for an hour without you.

On a current version, that is also the one you start in. And you change it with a single keypress.

In this guide, I'll show you:

  • All 6 permission modes, and what each one lets through without asking
  • How auto mode decides what is safe, from Anthropic's own explanation
  • The 1 keypress that switches between them mid-session
  • Which mode to use for reviewing, for iterating, and for a long unattended run
  • The actions no mode will ever auto-approve, and why deny rules outrank everything

And I'll go through all 6, starting with the careful one.

key_takeaways.mdTL;DR

Key takeaways

A permission mode is the baseline for what Claude Code can do without stopping to ask you. There are 6, not the 3 most guides teach.
On a current version, a terminal or VS Code session starts in Auto: everything runs, with background safety checks. Manual reads only and asks for everything else.
Auto mode sends risky actions to a separate classifier that checks them against what you asked for, and it never sees Claude's own reasoning.
Press Shift+Tab to switch modes mid-session. Asking Claude in chat to change it does not work.
Deny rules block in every mode, including bypass. A rule is enforcement, and a line in CLAUDE.md is only a request.

What is a permission mode?

A permission mode is the baseline for what Claude Code can do without stopping to ask you.

It is not a setting you configure once and forget. You switch it during a session as the work changes: careful while you are reviewing, looser while you are iterating, locked down when something else is running it.

Modes set the baseline. Permission rules layer on top to pre-approve or block specific tools, and a deny rule blocks in every mode, including the one that skips all checks.

The 6 modes

The name you see and the name a settings file wants are not the same, so both are below. The label is what the mode picker shows you, and the value in backticks is what you type into a config or a flag.

Manual, config value default, lets Claude read without asking, and everything else asks first. It is the right mode for anything sensitive.

Accept edits, acceptEdits, also lets through file edits and common filesystem commands like mkdir, touch, mv and cp. Use it for iterating on work you are watching. The VS Code extension is the one place that labels this Edit automatically, and it is the same mode.

Plan, plan, allows reads, plus classifier-approved commands where auto mode is available. Use it to let Claude look around before it changes anything.

Auto, auto, lets everything through with background safety checks. This is the one the 3-mode guides miss, and it is what you want for a long task rather than turning safety off entirely. On a current version, a session you start in the terminal or VS Code begins here.

Don't ask, dontAsk, allows only pre-approved tools and denies everything else automatically. It is not in any mode picker, so you will not find it by looking: you set it on the command line with --permission-mode dontAsk. It's built for scripts and CI, where a prompt nobody sees is a hang.

Bypass permissions, bypassPermissions, lets everything through with no checks. The docs are blunt about the scope, which is isolated containers and VMs only.

Pro tip A settings file cannot put a cloud session into bypass or don't ask. Those 2 values are ignored there, silently.

How auto mode decides what is safe

In Anthropic's own research, 97% of permission prompts in Claude Code get approved. Approving each one gives you control, but on a long task it turns into approval fatigue, and auto mode exists for that.

Claude doesn't approve its own actions in auto mode. A separate classifier checks each risky action against what you asked for. It sees your messages and Claude's tool calls, but not Claude's reasoning or its replies, so the conversation can't talk it into saying yes.

Not every action goes to the classifier. Your deny, ask and allow rules run first. Reading and editing files inside your project is easy to undo, so it skips the check, and shell commands, web fetches and anything that reaches outside your project go through it.

When the classifier denies something, Claude usually looks for a safer way on its own. For example, a force push to main that gets denied can become a push to a new branch. If it keeps getting denied, auto mode pauses and asks you.

Web pages and files can carry hidden instructions too. So before that content reaches Claude, a probe scans every tool result for them and adds a warning to anything suspicious.

Anthropic explains all of it in its video on how auto mode works.

Switching mid-session

In the terminal, press Shift+Tab. The cycle runs Manual, then Accept edits, then Plan, then back. If you are in Auto, the first press takes you to Manual.

The status bar tells you where you are: ⏸ manual mode on, ⏵⏵ accept edits on, ⏸ plan mode on, ⏵⏵ auto mode on.

Two modes are not in that cycle by default. bypassPermissions only appears if you started the session in a way that puts it there, and dontAsk never appears at all, which is why the flag is the only way to reach it.

In VS Code it is the mode indicator at the bottom of the prompt box rather than a keypress, and in the desktop app it is the mode selector.

In the VS Code extension there is a catch worth knowing: picking Manual, Edit automatically or Auto is remembered for your next conversation. Picking Plan or Bypass permissions applies to that conversation only, so a session you thought was still in Plan will not be.

One thing that does not work, and people try it constantly, is asking Claude in chat to change the permission mode. It is a control, not a request.

Pro tip Switching mid-check is safe. Claude Code drops a verdict your new mode would not have asked for, and prompts you instead.

Which one I actually use

I use Auto for most things.

It approves what passes its safety check and stops for anything risky, which is the behaviour people are reaching for when they turn permissions off entirely. You get through a long task without babysitting it, and it still pauses at the parts worth pausing at.

Accept edits earns its place when you are working through a specific file and every prompt is the same yes. And Manual is right the moment the work touches something you would not want changed by accident.

The point is that these are session controls, not a preference you set once. Shift+Tab exists because the right answer changes 3 times in an afternoon.

The rest of my setup, including the AI OS every session reads, is on How I use AI.

What no mode will auto-approve

Bypass does not mean bypass everything, and this is the part worth knowing before you trust it.

Claude Code never auto-approves anything matched by an explicit ask rule, any tool that needs you (like a question it asks you directly), or rm and rmdir targeting a critical path. That last one cannot be approved by an allow rule or a hook either.

So the floor is higher than the name suggests. But that is a floor, not a safety net, and the docs still scope bypass to isolated machines.

Watch out That floor is not a safety net. It blocks rm against a critical path, not against the folder you happen to be standing in.

Rules beat modes

A deny rule blocks in every mode, including bypassPermissions.

An allow rule does the opposite: it has no effect in bypassPermissions, because there is nothing left to allow.

Writes to protected paths are never auto-approved except in bypass, or in a plan-mode session where bypass is already available.

So if there is 1 thing you want never touched, a deny rule is the way to say it. Putting it in CLAUDE.md is a request, and a rule is enforcement.

More AI coding tools I've reviewed

These are my reviews of Claude Code and the agents I compare it with:

What to do next

0/6

FAQs about Claude Code permission modes

The nervous ones first, then the practical ones.

Permission modes are the baseline for what Claude Code can do without asking you first.

There are 6: Manual, Accept edits, Plan, Auto, don't ask, and Bypass permissions.

On a current version, a terminal or VS Code session starts in Auto.

Manual allows reads only and asks for everything else.

Press `Shift+Tab` in the terminal to cycle through them, and the status bar shows which one is active.

Asking Claude in chat to change mode does not work.

It is a control you operate, not something you request.

Use Manual while you are reviewing, Accept edits while you are iterating on work you are watching, and Auto for a long task running without you.

Most people reach for bypass when auto is what they actually wanted.

A separate classifier checks each risky action against what you asked for.

It sees your messages and Claude's tool calls, but not Claude's reasoning.

Reading and editing inside your project skips the check, while shell commands, web fetches and anything outside your project go through it.

Anthropic explains it in its own video.

The docs scope it to isolated containers and VMs, and that is the honest answer.

It is not quite everything: deny rules still block, `rm` against a critical path is still refused, and tools that need your input still ask.

But treat that as a floor, not protection.

It starts the session in Bypass permissions, so nothing asks first.

The docs scope that to isolated containers and VMs.

For a long task on your own machine, Auto cuts the prompts without switching the checks off.

They are the same mode.

Manual is the name you see in the CLI, the extensions and the desktop app, and `default` is the config value that hooks and the SDK use.

The CLI accepts `manual` as an alias, so `claude --permission-mode manual` works.

Auto runs everything with background safety checks, and it is the mode most 3-mode guides leave out.

It is the one to use for a long task where prompt fatigue is the real problem, instead of turning permissions off completely.

On a current version, a terminal or VS Code session starts in it.

You can, with a deny rule.

Deny blocks in every mode, including bypass.

Writing "never edit this" in `CLAUDE.md` is a request that Claude can miss.

A deny rule is enforcement.

It only joins the cycle if you started the session in a way that puts it there, such as `--permission-mode bypassPermissions`.

`dontAsk` never appears in the cycle at all and has to be set with a flag.

They don't change what Claude reads at launch.

Your CLAUDE.md and context files load the same way in every mode.

They affect what it may change.

In Manual it will ask before editing any of those files, and in Accept edits it will not.

Final thoughts on Claude Code permission modes

These are session controls, not a preference you set once. Shift+Tab exists because the right answer changes 3 times in an afternoon.

Keep reading:

Then write your first deny rule, for the one folder you never want touched.

Navid Moazzez

AI business strategist & AI OS builder

Navid Moazzez helps creators and founders master AI and build their own AI Operating System (AI OS) to automate their business and life.

Navid.me is reader-supported. When you buy through links on this site, I may earn an affiliate commission. Learn more.

Related free tools

Free AI newsletter

The most actionable AI newsletter for founders

Every week, get proven AI strategies, curated tools, and step-by-step systems to grow your audience, create better content, and build a profitable creator business.

No fluff, no filler, no BS. Just five minutes each week that might level up your online business and life.

P.S. Sign up now to get free access to my ultimate AI tools guide for creators.

Loved by 10,000+ readers