Permissions & settings.json
Permissions: three levels
Permissions decide "which actions need no question". Below is a conservative example: read-type actions allowed; commit/push/remote commands need confirmation; dangerous actions and key files forbidden.
.claude/settings.example.json Download{
"permissions": {
"allow": [
"Bash(git status:*)",
"Bash(git diff:*)",
"Bash(git log:*)",
"Bash(ls:*)",
"Bash(wc:*)",
"Bash(node --check:*)",
"Bash(python -m py_compile:*)",
"Read",
"Glob",
"Grep"
],
"ask": [
"Bash(git commit:*)",
"Bash(git push:*)",
"Bash(scp:*)",
"Bash(ssh:*)"
],
"deny": [
"Bash(rm -rf:*)",
"Bash(git reset --hard:*)",
"Read(./.env)",
"Read(./secrets/**)"
]
}
}
settings.json; it only creates settings.kit-example.json, which you compare and merge yourself.Permissions
Before Claude Code runs a command or edits a file it checks the permission settings. They live in settings.json, in several layers; the higher one wins:
| Layer | Location |
|---|---|
| Managed by a company | managed-settings.json etc. |
| Start-up flag for this run | claude --settings |
| Project local (personal, not checked in) | .claude/settings.local.json |
| Project shared | .claude/settings.json |
| User global | ~/.claude/settings.json (Windows: C:\Users\UserName\.claude\settings.json) |
{
"permissions": {
"allow": ["Bash(git status:*)", "Bash(npm run build)"],
"deny": ["Bash(rm -rf:*)"]
}
}
Entries in allow are not asked about again, entries in deny are refused outright, everything else follows the current "mode". Common modes from strict to loose: ask every time (default) → auto-accept edits (acceptEdits) → auto (auto, with a background review) → list only (dontAsk) → plan mode (plan, look but do not change) → skip all checks (bypassPermissions, the official advice is to use it only in isolated environments). Press Shift+Tab to switch modes during a conversation. Official pages: settings, permissions.