Claude Code: allow MCP tools without approving every call
Allow MCP tools in Claude Code with permission rules named mcp__server__tool. Allow one tool or a whole server; keep paid tools on ask.

To allow MCP tools in Claude Code, add permission rules that name them mcp__<server>__<tool>. mcp__puppeteer__puppeteer_navigate allows one tool; mcp__puppeteer or mcp__puppeteer__* allows every tool from that server. Add the rules with /permissions or in the permissions.allow list of a settings file. There is no single allow rule for every server.
Rule syntax comes from Claude Code's Configure permissions docs, read on 2026-09-28. The paid-server example is Sume's hosted MCP server, from MCP tools and gates. Sume has no official Claude Code integration; it is a remote MCP server you add yourself.
How do I write an MCP permission rule?
Use the server name exactly as you configured it in Claude Code. Rules go in project settings at .claude/settings.json, local settings at .claude/settings.local.json, or user settings at ~/.claude/settings.json.
- Rules are checked in order: deny, then ask, then allow. A matching ask rule prompts even when a more specific allow rule also matches.
- Claude Code skips any
mcp__rule with parentheses in a settings file; to match an MCP tool's parameter, pass a deny rule with--disallowedTools.
| Rule | What it matches |
|---|---|
mcp__puppeteer | Any tool from the puppeteer server |
mcp__puppeteer__* | All tools from the puppeteer server |
mcp__puppeteer__puppeteer_navigate | One tool from that server |
mcp__github__get_* | The github server's tools whose names start with get_ |
mcp__* as an allow rule | Nothing: skipped with a warning |
mcp__* as a deny rule | Every MCP tool on every server |
Can I allow all MCP tools at once?
Not with one rule. Allow globs work only after a literal mcp__<server>__ prefix, so you allow each server by name. The mode that skips prompts altogether, bypassPermissions, is one Claude Code's docs say to use only in isolated environments like containers or VMs. On a server whose tools spend money, it also removes the prompt before paid calls, except those listed under ask.
Which tools should I allow on a paid media server?
The ones that only read. Sume's hosted server marks each tool's safety in tools_list, and its docs say to give agents read-only commands first and require explicit confirmation before write or paid generation. With the server added as sume, this keeps discovery and waiting prompt-free and paid creates on ask (the Agent SDK version covers SDK apps):
- List read tools by name rather than a glob like
mcp__sume__jobs_*, which would also matchjobs_cancel, a write tool. - Put paid creates under
ask, not just outsideallow. Ask beats allow, so they keep prompting even if someone later allowsmcp__sume__*, andpermissions.askprompts even inbypassPermissionsmode.
{
"permissions": {
"allow": [
"mcp__sume__mcp_health",
"mcp__sume__tools_list",
"mcp__sume__tools_schema",
"mcp__sume__jobs_status",
"mcp__sume__jobs_wait",
"mcp__sume__jobs_result"
],
"ask": ["mcp__sume__generate_image", "mcp__sume__generate_video"]
}
}Isn't the server's own safety check enough?
It's a second layer, not a replacement. Sume requires an idempotency_key on write and paid tools, but its docs call that a key for transport and dedup, not human approval. What limits spend on the server side:
- Sign in with OAuth and leave Write off: the session then sees read-only tools, and paid calls return
insufficient_scope. - Ask for
dry_run=truefirst; it previews admission and cost without submitting the job. - Pass
max_spend_usdto cap a call; it is enforced only when provided.
Sources
Related posts
More in Integrations
- Claude Code MCP project scope: share a server with your team
Claude Code's project scope saves an MCP server to .mcp.json at the repo root for the team to commit. How approval, sign-in, and keys work.
- Cloud Scheduler trigger for a Cloud Run job, retry-safe
Add a Cloud Scheduler trigger to a Cloud Run job with a cron and a time zone. A failed task retries 3 times by default, so key paid calls to the date.
- Codex MCP tool timeout: tool_timeout_sec and slow jobs
Codex gives each MCP tool call 60 seconds by default. Raise tool_timeout_sec per server in config.toml, or keep slow media jobs inside the limit.
- Continue MCP server: add Sume in .continue/mcpServers
Add Sume's hosted MCP server to Continue with a YAML block in .continue/mcpServers: type streamable-http, the URL, and a key from a secret.
Written by Sume