Claude Code Auto Mode vs --dangerously-skip-permissions: Letting Claude Work Without Asking
If you’re searching for “claude dangerously-skip-permissions,” you probably want Claude Code to keep working without stopping for approval. This guide explains how bypass mode differs from auto mode, what safeguards remain, and how to configure unattended work with the permission and sandbox controls available as of September 27, 2026.
What claude dangerously-skip-permissions actually does
The command activates Claude Code’s bypassPermissions mode:
claude --dangerously-skip-permissions
The equivalent explicit command is:
claude --permission-mode bypassPermissions
Both bypass routine permission approval, subject to remaining safeguards. They do not mean that every action must succeed or that Claude Code can never ask another question.
The official CLI reference also distinguishes activation from availability. This command starts in plan mode while making bypass mode available:
claude --permission-mode plan --allow-dangerously-skip-permissions
The extra word allow matters: --allow-dangerously-skip-permissions does not immediately activate bypass mode.
“Without asking” has two meanings
When developers ask how to allow Claude Code to do everything without asking, they may mean either “approve actions automatically” or “never stop for a permission prompt.” Those goals lead to different configurations.
Bypass mode removes routine approval gates. Auto mode evaluates actions with a classifier. An unattended configuration can instead deny anything that would need a prompt, allowing the session to continue within those limits.
Skipping permission approval can produce dangerous and destructive outcomes. Anthropic recommends using bypass mode only in isolated environments. Treat that as a constraint on where you run the command, especially when the task involves deletion, credentials, external data sharing, or deployment actions.
Compare the Claude Code permission modes
Claude Code permission modes answer different questions: whether edits can proceed, whether an action needs review, and what happens when approval would be required.
| Mode | Baseline behavior | Command |
|---|---|---|
default |
Requests approval for actions requiring permission. | claude --permission-mode default |
acceptEdits |
Automatically accepts file edits and common filesystem operations in permitted working directories. | claude --permission-mode acceptEdits |
plan |
Explores and plans without editing source files; auto-mode availability can affect which commands run. | claude --permission-mode plan |
auto |
Uses background classifier review instead of routine approval prompts. | claude --permission-mode auto |
dontAsk |
Denies actions that would require a prompt; already permitted actions still run. | claude --permission-mode dontAsk |
bypassPermissions |
Bypasses routine permission approval, subject to remaining safeguards. | claude --dangerously-skip-permissions |
These are baseline meanings. Fine-grained behavior depends on the installed version, and live documentation can include changes beyond this article’s publication date. The Claude Code CLI guide provides a useful place to continue when choosing startup options.
Auto, acceptEdits, and dontAsk are different choices
Use acceptEdits when your goal is to approve file changes and common filesystem operations in permitted working directories automatically. That permission does not amount to blanket approval for every action.
Auto mode delegates permission decisions to a classifier. Approved actions proceed; blocked actions cause Claude to try another approach. Repeated blocks can trigger human approval.
dontAsk takes a different approach: actions that would require a prompt are denied, while already permitted actions can run. It is useful to distinguish “no approval prompt” from “automatic approval,” because those produce very different results.
Auto mode: review, defaults, and classifier billing
Auto mode launched on March 24, 2026, initially as a research preview for Team users. The official auto-mode announcement records general availability for all users on July 10, 2026.
Its purpose is to replace routine manual permission decisions with classifier review. That review reduces risk but remains imperfect: auto mode can approve risky actions or block benign ones. Anthropic also recommends isolation for auto mode.
The risks described in the engineering explanation include overeager actions, mistaken scope, prompt injection, credential exploration, external data sharing, and bypassing deployment checks. Removing routine prompts does not remove the need to define the task’s scope.
What changed in September
Claude Code 2.1.278, released September 19, 2026, changed auto mode to default to server-side classification for Claude API and Enterprise users, and on Bedrock, Vertex, Foundry, and gateways. Its billing wording was specific: server-side classification “does not charge for classifier overhead.” The release also said it “warns on billed fallback.”
That change concerns where the classifier runs and how its overhead is billed. It does not promise free coding or model usage, and it did not make auto mode the starting permission mode for every user.
By September 27, additional releases mattered. The tagged 2.1.283 changelog records two separate developments:
- Version 2.1.281 extended
CLAUDE_CODE_AUTO_MODE_SERVERto direct Anthropic API connections. Setting it to0opts out and uses a classifier that counts toward usage;1opts in. It also recorded server-side review of read-only and sandboxed shell commands. - Version 2.1.283, published September 25, changed interactive sessions on third-party providers or with telemetry disabled to start in auto mode when no permission mode is configured.
permissions.defaultModestill overrides that starting behavior.
Do not attribute the September 25 starting-mode change to 2.1.278 or treat the two defaults as interchangeable.
Check the session rather than guessing
Run /status and inspect the Auto mode server row to see whether the session’s classifier runs on the server.
For Bedrock, Vertex, Foundry, and gateways, CLAUDE_CODE_AUTO_MODE_SERVER=0 opts out of server-side classification. The later direct-API behavior described above also supports explicit opt-in with 1.
Historical fallback eligibility is not fully established by the available brief. The supported conclusion is narrower: server-side classifier overhead is uncharged, billed fallback can produce a warning, and ordinary model usage remains separate. For broader usage context, see the Claude Code pricing guide.
Run unattended without approving everything
For CI or other unattended tasks, bypass mode is not the only available approach. Claude Code 2.1.259, released September 2, 2026, added --permission-prompts none.
The 2.1.259 release notes describe the behavior: anything that would prompt is automatically denied, while the selected permission mode continues deciding.
For example:
claude -p "Run the test suite" --permission-mode auto --permission-prompts none
Auto mode still reviews actions. If an action reaches a point where permission approval would be needed, this configuration denies it instead of waiting for a person.
That is a useful choice when the requirement is unattended execution with review. It does not guarantee completion: an action needed for the task may be blocked or denied. Choose the configuration based on whether your priority is automatic review, automatic editing, or bypassing routine approval.
Why project settings may not activate the mode
Since version 2.1.257, released September 1, defaultMode: "bypassPermissions" is ineffective in both .claude/settings.json and .claude/settings.local.json. This matches the restriction on "auto" in those project settings files.
Use user or managed settings, or pass --permission-mode when starting Claude Code. For a specific unattended run, an explicit command makes the requested mode easy to inspect.
The same workflows can run through an API gateway such as AI Prime Tech; see using Claude Code with an API key. AI Prime Tech is independent and is not affiliated with Anthropic or OpenAI.
Combine permissions with sandboxing
Permission mode controls approval decisions. Sandboxing controls what commands can access. Use both when you want fewer interruptions alongside restrictions on filesystem and network access.
Anthropic’s sandboxing announcement, published October 20, 2025, describes filesystem and network isolation enforced through Linux bubblewrap and macOS Seatbelt, including spawned subprocesses. Run /sandbox to configure it.
Anthropic reported an 84% reduction in permission prompts in internal usage. That is an internal result, not a promise that every project or task will see the same reduction.
Relevant sandbox controls
These settings enable sandboxing, disable the dangerouslyDisableSandbox escape hatch, and require the enabled sandbox to start:
{
"sandbox": {
"enabled": true,
"allowUnsandboxedCommands": false,
"failIfUnavailable": true
}
}
The controls have distinct purposes:
sandbox.enabledenables sandboxing.sandbox.allowUnsandboxedCommands: falsedisables the escape hatch.sandbox.failIfUnavailable, added in version 2.1.83 on March 25, 2026, exits if the enabled sandbox cannot start instead of continuing unsandboxed.
Auto mode or bypass mode can be combined with sandboxing. Neither permission choice makes sandbox configuration irrelevant, and server-side review can also apply to sandboxed shell commands.
Some deletion prompts remain
“Skip permissions” does not guarantee zero questions. By the publication cutoff, the changelog records dangerous rm prompts in both bypass and auto modes waiting two minutes, then denying the action with a rewrite hint.
CLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT=1 disables that timeout. It should not be described as disabling every deletion safeguard or making all commands automatically succeed.
For unattended work, account for the possibility of denial. A task that depends on a blocked action may need a revised approach even when routine permission prompts have been removed.
Key takeaways
claude --dangerously-skip-permissionsactivatesbypassPermissions, removing routine permission approval while remaining safeguards still apply.- Auto mode uses classifier review. It can approve actions, block them, or eventually require human approval after repeated blocks.
- Server-side classifier defaults and starting permission-mode defaults are separate changes. Version 2.1.278 changed classification; version 2.1.283 changed starting behavior for specified interactive sessions.
- For unattended execution with review, combine auto mode with
--permission-prompts none; actions that would prompt are denied. - Use isolation and sandbox controls alongside permission choices. Project settings cannot activate auto or bypass through
defaultMode, so use user or managed settings, or an explicit CLI mode.
FAQ
Does claude --dangerously-skip-permissions allow everything without asking?
It bypasses routine permission approval by activating bypassPermissions, but remaining safeguards still apply. By September 27, 2026, dangerous rm prompts in bypass and auto modes could wait two minutes before denying the action with a rewrite hint.
Does Claude Code auto mode still block commands or ask for approval?
Yes. Auto mode lets approved actions proceed, blocks others so Claude can try another approach, and can trigger human approval after repeated blocks. Adding --permission-prompts none automatically denies anything that would otherwise prompt.
Does server-side auto-mode classification cost extra?
Version 2.1.278 states that server-side classification does not charge for classifier overhead and warns on billed fallback. This does not make ordinary coding or model usage free; check the Auto mode server row in /status to identify where the session’s classifier runs.
Why does defaultMode fail to activate auto or bypass in my project?
Project settings restrictions make "auto" and "bypassPermissions" ineffective as defaultMode values in .claude/settings.json and .claude/settings.local.json. Use user or managed settings, or start Claude Code with an explicit --permission-mode argument.
One API key for Claude Opus 5.5, Sonnet 5, Haiku 4.5 and Fable 5.1, plus GPT-6 models. Pay as you go, no subscription.
Get Your API Key →