Library · Setting up Claude Code

Claude Code permission modes and CLI launch modes

Builder45 minUpdated: October 2026
9 of 105 in the library

Module: 3. The WAT framework | Time: about 25 min theory + 20 min practice


The gist

Claude Code has two layers of "modes." The first is how you launch Claude (interactively, as a single request, through a pipe). The second is how much control you keep for yourself while it works (permission modes).

🎨 Picture this: launch modes are how you come to the kitchen: you can walk in and cook alongside the head chef (interactive), you can shout your order through the pass and wait for the finished dish (print), or you can send ingredients in on a conveyor belt (pipe). Permission modes are what happens once you're in the kitchen: the chef asks before every cut (Manual), cuts on their own (Accept edits), or runs on full autopilot (Bypass).


Key concepts

CLI launch modes: how to call Claude from the command line

  • Interactive mode (claude): a REPL in the terminal (the terminal is the program for working with the command line), a back-and-forth conversation
  • Print mode (claude -p "request"): one question, one answer, exit
  • Pipe mode (cat file | claude -p "..."): data comes in through a Unix pipe
  • SDK mode: calling it from Python or TypeScript code (TypeScript is JavaScript with types; both are programming languages)

Permission modes (how much control)

  • Manual (the settings value is default, the standard out-of-the-box value): Claude asks permission before every file change and command
  • Accept Edits (acceptEdits): Claude edits files on its own but asks before shell commands
  • Plan Mode (plan): Claude analyzes and proposes a plan, changes nothing
  • Auto Mode (auto): works without the usual questions; every action is checked by a separate classifier model. Since version 2.1.283 this is the default starting mode in the terminal and VS Code
  • Don't Ask (dontAsk): carries out only actions approved in advance and rejects everything else
  • Bypass Permissions (bypassPermissions): no checks at all (only in isolated environments!)
  • Shift+Tab: the hotkey for switching between modes
  • --allowedTools: an allowlist of specific tools

Theory

Part 1: CLI launch modes

You can launch Claude Code in four ways. Each fits different situations.

Interactive mode (the default)

Just type claude in the terminal and an interactive session (REPL) opens. You write a request, Claude answers, you clarify, it refines. The conversation goes on until you exit (Ctrl+D or /exit).

bash
# Start an interactive session
claude

# Start with an initial request (but stay in the conversation)
claude "explain the structure of this project"

🎨 Picture this: it's like sitting at a table with a colleague. You discuss, clarify and edit together.

The --print flag (or the short form -p) changes the behavior: Claude gets a request, does the work, prints the answer to stdout and ends the process. No conversation.

bash
# One question, one answer, exit
claude -p "Generate a UUID v4 in Python"

# With a model choice
claude -p "Explain this code" --model sonnet

🎨 Picture this: like calling out a question at a drive-through window. You get the answer and move on.

Pipe mode (a Unix pipeline)

Claude Code fully supports stdin, so you can pass data through a pipe like with any Unix tool:

bash
# Analyze a log
cat server.log | claude -p "Find all ERROR entries, group them by type"

# Code review through a pipe
cat src/payment.py | claude -p "Find security vulnerabilities"

# Generate a commit message from a diff
git diff HEAD | claude -p "Write a commit message in Conventional Commits format"

Limitation: a pipe is handy for small amounts of data. For big files, it's better to give the path in the request.

🎨 Picture this: a conveyor belt in a factory. You put a part (the data) on the belt and a finished product (the answer) comes out the other end.

SDK mode (calling it from code)

For developers there's the Agent SDK: a library for Python and TypeScript that runs the same agent loop as Claude Code. Package names and installation steps change, so check the Agent SDK Quickstart for current instructions.

The SDK gives you a structured response, callbacks on tool calls and token streaming (tokens are the smallest units of text for AI). More in the lesson Headless Mode and CI/CD and the Anthropic docs.


Part 2: Key CLI flags

Before we get to permission modes, here are the most important flags that work in any mode:

Flag What it does Example
--model Pick the model (aliases sonnet, opus, haiku, fable or the full name) claude -p "..." --model sonnet
--max-turns Limit iterations (print mode only) claude -p "..." --max-turns 3
--output-format Output format: text, json (a key-value data format), stream-json claude -p "..." --output-format json
--continue / -c Continue the last conversation claude -c
--resume / -r Resume a specific session claude -r "auth-refactor"
--allowedTools Allowlist of permitted tools claude --allowedTools "Read,Edit"
--disallowedTools Blocklist of forbidden tools claude --disallowedTools "Bash"
--permission-mode Start in a specific permission mode claude --permission-mode plan
--append-system-prompt Add instructions to the system prompt (the text instructions to the AI) claude --append-system-prompt "Write in TypeScript"
--max-budget-usd Spending cap in dollars (print mode) claude -p "..." --max-budget-usd 5.00
--bare Fast start without loading hooks (scripts that react to events), skills (reusable instructions) or MCP (Model Context Protocol) claude --bare -p "..."
--mcp-config Connect MCP servers from a file claude --mcp-config ./mcp.json

--bare mode is recommended for scripts and CI/CD (Continuous Integration/Delivery: automatic building and shipping). It skips auto-loading hooks, skills, subagents, plugins, MCP servers, auto memory and CLAUDE.md. Startup is faster, and the result is the same on any machine.


Part 3: Permission modes

How to switch between modes

  • In the terminal (CLI): Shift+Tab cycles through default → acceptEdits → plan. The auto mode joins the cycle if it's available; bypassPermissions appears only if you enable it separately (the --allow-dangerously-skip-permissions flag). The current mode shows in the status line under the input box.
  • In VS Code (a popular code editor from Microsoft): a mode indicator in the prompt panel
  • In the desktop app: a list of modes next to the send button (Cmd+Shift+M); Shift+Tab doesn't work there
  • At launch: the --permission-mode plan flag (or auto, acceptEdits, dontAsk, bypassPermissions; for Manual mode the value is default or the alias manual)
  • As the default: the defaultMode setting in settings.json

Mode 1: Plan Mode

🎨 Picture this: Plan Mode is like a surgeon who talks through the whole plan out loud before the operation: "I'll make the incision here, then go to this vessel, then..." It's not a waste of time; it's insurance. Catch a mistake in the plan before the operation and you won't be fixing it during.

What happens: Claude analyzes the task and builds a detailed plan. It doesn't carry out anything. It waits for your "yes" or your edits.

Sample Plan Mode output:

Type this into the chat
Context: need to create a LinkedIn post
Steps:
1. Read voice-samples.md to understand the tone
2. Create linkedin-post.md in the outputs/ folder
3. Write a 200-250 word post with a hook in the first sentence
4. Add 3-5 hashtags

Files to be created: outputs/linkedin-post.md
Files to be read: context/voice-samples.md

After reviewing the plan you choose: "Yes, and use auto mode" (carry it out in auto), "Yes, manually approve edits" (check each edit) or "No, keep planning" (continue planning). If auto isn't available, the first option is called "Yes, auto-accept edits."

Plan Mode bonus: you can add comments right into the plan. For example, write "make the tone more conversational" under step 3, and Claude will update the plan and carry it out with that edit.

When to use it:

  • A complex task with several steps
  • The first time you're doing something in an unfamiliar project
  • Risky operations (data migration, a big refactor, mass-editing files)
  • You need to explain to a client exactly what will be done
  • You want to understand Claude's reasoning before it acts

A rule from practice: a minute of planning saves 10 minutes of redoing. For any task where something can go wrong, start with Plan Mode.


Mode 2: Manual (value default, formerly Ask Before Edits)

🎨 Picture this: Manual is like an experienced plumber who says before every action: "I'm going to shut off the hot water, okay?", "I'm replacing this pipe, take a look." A little slower, but no surprises.

Name: Manual in the interface, default in the settings.

What happens: Claude reads files automatically, but before every file change or shell command it shows what it's about to do and asks for confirmation.

bash
# Launch in Manual mode (since version 2.1.283, new terminal sessions don't start in it; they start in auto)
claude --permission-mode default

When to use it:

  • You're working in a production project where a mistake is costly
  • It's your first time working with someone else's code or an unfamiliar project
  • You want to see every step (learning, auditing, reviewing)
  • The task touches critical files
  • Sensitive work with secrets or configs

When it's overkill:

  • A routine task you've done many times
  • Creating new files from scratch (not editing existing ones)
  • Simple content tasks

Mode 3: Accept Edits (in VS Code: Edit automatically)

Official name: acceptEdits

What happens: Claude creates and edits files without asking. It also automatically runs basic file commands (mkdir, touch, mv, cp and the like). But more serious shell commands and network requests still require confirmation.

bash
# Launch in acceptEdits mode
claude --permission-mode acceptEdits

This is a comfortable working mode when you review the changes yourself. It's one press of Shift+Tab from Manual.

When to use it:

  • A clear task with a well-configured CLAUDE.md
  • Tasks you've done many times
  • Writing text, creating files
  • Iterations: Claude already did good work, and you're asking it to improve it

The difference from Bypass: Accept Edits still asks before shell commands and network requests. Bypass never asks.


Mode 4: Auto Mode (an AI-supervised autopilot)

Official name: auto

What happens: Claude works without your confirmations, but every action is checked by a separate AI model (a safety classifier). If the classifier sees a dangerous action, it blocks it automatically. Since version 2.1.283, auto is the default starting mode in the terminal and VS Code; if auto isn't available (because of the model or organization settings), the session starts in Manual.

bash
# Launch in auto mode
claude --permission-mode auto

Requirements for auto mode:

  • Plan: any (on Team and Enterprise it's on by default, and an admin can turn it off). It's also available on Pro
  • Model: a supported, recent model; the list depends on the provider and changes over time. Check the permission modes docs and the What's current page
  • Provider: the Anthropic API (Application Programming Interface), as well as Amazon Bedrock, Google Cloud Agent Platform and Microsoft Foundry

What the classifier blocks by default:

  • Downloading and running code (curl | bash, where bash is the command language of the Unix terminal)
  • Deploying (publishing) to production
  • Mass deletion of files
  • Force push and push to main
  • Sending data to external servers

When to use it:

  • Long tasks where you're tired of pressing "Yes" every 10 seconds
  • You trust the direction of the work but want a safety net
  • You need speed but aren't ready for full Bypass

🎨 Picture this: a car's driver-assist. The car drives itself, but the system watches the road and brakes if it sees an obstacle. Not perfect, but much better than driving with your eyes closed.


Mode 5: Don't Ask (only what's pre-approved)

Official name: dontAsk

What happens: Claude can carry out ONLY the actions you approved in advance in the rules (permissions.allow). Everything else is automatically rejected without asking. Fully non-interactive.

bash
# Launch in dontAsk mode
claude --permission-mode dontAsk

When to use it:

  • CI/CD pipelines with no human present
  • You need strict control over exactly what's allowed
  • You know the full set of operations in advance

Mode 6: Bypass Permissions

Official name: bypassPermissions

What happens: Claude gets full autonomy. No confirmations, no classifiers, no pauses. It does EVERYTHING it thinks is necessary. Even writes to protected paths (.git/, the folder of git, the version control system for code; .vscode/ and others) go through without asking.

How to turn it on:

bash
# Via the CLI
claude --permission-mode bypassPermissions

# Short form (same effect)
claude --dangerously-skip-permissions

In VS Code: Settings → search for "allow dangerously" → turn the option on. After that, Bypass appears in the mode menu.

When to use it:

  • Isolated containers, VMs, dev containers without internet access
  • CI/CD pipelines in a sandbox environment
  • You've already checked the plan in Plan Mode and want to run it without interruptions

When NOT to use it:

  • On your main computer
  • With unfamiliar code
  • In a production environment

The Plan → execution pattern (recommended):

Code
1. Got a complex task
2. Ran it in Plan Mode → studied the plan → added edits
3. Approved the plan → Claude offers:
   - Yes, and use auto mode
   - Yes, manually approve edits
   - No, keep planning
4. Picked the right level → execution

Warning: Bypass doesn't protect against prompt injection or unintended actions. If you need autonomy WITH safety, use Auto Mode.

🎨 Picture this: Bypass is like handing the car keys to a blindfolded driver. Auto Mode is handing over the keys with working emergency braking. The first option belongs only on a closed test track (a container).


allowedTools: an allowlist of tools

The --allowedTools flag lets you permit specific tools for a single run without opening up full Bypass.

Using it in the CLI:

bash
claude --allowedTools "Read,Write,Bash(git commit*)" "commit all the changes"

What this gives you:

  • Fine-grained control: allow reading files but not writing
  • Allow only git operations but not system commands
  • Allow web-fetch but not file editing

A practical example, a nightly routine:

bash
claude --allowedTools "Read,Bash(curl*)" --print \
  "run the API health check and save a report"

Permission modes comparison table

Mode CLI name What runs without asking Control Best scenario
Plan Mode plan Reading only Maximum Complex/risky tasks
Manual default Reading only High Learning, production, auditing
Accept Edits acceptEdits Reading + editing + basic commands Medium Everyday work
Auto Mode auto Everything, but with an AI check Low (AI safety net) Long tasks
Don't Ask dontAsk Only what's pre-approved Strict CI/CD with control
Bypass bypassPermissions Absolutely everything Zero Containers/VMs only

Typical switching scenarios

Scenario 1: First look at a task

Code
Plan Mode → study the plan → approve → Accept Edits or Auto Mode

Scenario 2: A simple task in a clean project

Code
Accept Edits (acceptEdits) → that's enough

Scenario 3: A risky operation in production

Code
Plan Mode → study the plan → add edits → Manual for execution

Scenario 4: A CI/CD pipeline

bash
# Option A: strict control
claude -p "..." --permission-mode dontAsk --allowedTools "Read,Bash(git *)"

# Option B: full autonomy in a container
claude -p "..." --dangerously-skip-permissions --max-turns 5

Scenario 5: A long task touching many files

Code
Plan Mode → make sure the file list is right → Auto Mode

Scenario 6: Picking up yesterday's work

bash
# Continue the last conversation
claude --continue

# Resume a specific session by name
claude --resume "auth-refactor"

Modes as risk management

🎨 Picture this: modes are like speed on the road. School zone: 15 mph. Highway: 70. Autobahn: 110. You don't drive the same speed everywhere; you pick the speed for the conditions. Bypass in production is like doing 110 mph through a school zone.

Modes aren't about convenience; they're about managing risk. The rule is simple:

The higher the stakes of the task, the more control.

Fixing a typo in some text? Accept edits. Deleting a folder of client data? Plan Mode + Manual + reread the plan three times.

The stakes of a task come down to two questions:

  1. How irreversible is it if something goes wrong?
  2. How expensive is it to fix the mistake?

Practice

Exercise: try every mode on one task

Take one task: "Create the file outputs/test-post.md with a short post about how AI helps small businesses, 100-150 words."

  1. Plan Mode: run the task and study the plan. Add the comment "make the tone more conversational." Approve the updated plan
  2. Accept edits: ask Claude to "add three hashtags at the end of the post" and watch it do this without asking
  3. Manual: ask it to "change the post's headline" and watch Claude show the diff and ask for permission
  4. Turn on Bypass Permissions in the settings and ask it to "make a copy of the file called test-post-v2.md"; watch it work without pauses
  5. Run /context and see how many tokens all of this used

Goal: feel the difference between the modes in practice, not just in theory. After this, switching will become a reflex.


Tools and resources

  • Shift+Tab: the hotkey for switching permission mode
  • --permission-mode: the CLI flag for choosing a mode at launch
  • --allowedTools: an allowlist of tools (supports wildcards: "Bash(git *)")
  • --disallowedTools: a blocklist of tools
  • -p / --print: run without interaction (print mode)
  • -c / --continue: continue the last conversation
  • -r / --resume: resume a specific session
  • --model: choose the model (sonnet, opus, haiku, fable or the full name)
  • --bare: fast start without loading context (for scripts)
  • --max-turns: cap on iterations in print mode
  • --max-budget-usd: spending cap in dollars
  • Docs: CLI reference and permission modes

Key takeaways

4 ways to launch: Interactive (conversation), Print -p (one request), Pipe (data in), SDK (from code). For automation: print + pipe. For hands-on work: interactive.

6 permission modes: from maximum control (Plan/Default) to zero (Bypass). Auto Mode is the sweet spot: autonomy with an AI safety net. Accept Edits is the everyday workhorse.

Plan Mode is insurance that costs nothing. A minute on the plan saves an hour of fixes. After you approve the plan, Claude itself offers which mode to run it in.

Bypass is for containers only. If you need autonomy on a real machine, use Auto Mode. Bypass protects you from nothing.

--bare for scripts. When Claude runs from a script or CI, add --bare so it doesn't load extra context. Faster and more predictable.


Next lesson

→ Tokens and context management: tokens, the context window and the economics of requests

The mark stays in this browser only and is never sent anywhere. My progress