Claude Code: allow MCP tools without approving every call

Allow MCP tools in Claude Code with permission rules named mcp__server__tool. Allow one tool or a whole server; keep paid tools on ask.

5 min readSume
All posts

To allow MCP tools in Claude Code, add permission rules that name them mcp__<server>__<tool>. mcp__puppeteer__puppeteer_navigate allows one tool; mcp__puppeteer or mcp__puppeteer__* allows every tool from that server. Add the rules with /permissions or in the permissions.allow list of a settings file. There is no single allow rule for every server.

Rule syntax comes from Claude Code's Configure permissions docs, read on 2026-09-28. The paid-server example is Sume's hosted MCP server, from MCP tools and gates. Sume has no official Claude Code integration; it is a remote MCP server you add yourself.

How do I write an MCP permission rule?

Use the server name exactly as you configured it in Claude Code. Rules go in project settings at .claude/settings.json, local settings at .claude/settings.local.json, or user settings at ~/.claude/settings.json.

  • Rules are checked in order: deny, then ask, then allow. A matching ask rule prompts even when a more specific allow rule also matches.
  • Claude Code skips any mcp__ rule with parentheses in a settings file; to match an MCP tool's parameter, pass a deny rule with --disallowedTools.
From Claude Code's Configure permissions docs, read 2026-09-28.
RuleWhat it matches
mcp__puppeteerAny tool from the puppeteer server
mcp__puppeteer__*All tools from the puppeteer server
mcp__puppeteer__puppeteer_navigateOne tool from that server
mcp__github__get_*The github server's tools whose names start with get_
mcp__* as an allow ruleNothing: skipped with a warning
mcp__* as a deny ruleEvery MCP tool on every server

Can I allow all MCP tools at once?

Not with one rule. Allow globs work only after a literal mcp__<server>__ prefix, so you allow each server by name. The mode that skips prompts altogether, bypassPermissions, is one Claude Code's docs say to use only in isolated environments like containers or VMs. On a server whose tools spend money, it also removes the prompt before paid calls, except those listed under ask.

Which tools should I allow on a paid media server?

The ones that only read. Sume's hosted server marks each tool's safety in tools_list, and its docs say to give agents read-only commands first and require explicit confirmation before write or paid generation. With the server added as sume, this keeps discovery and waiting prompt-free and paid creates on ask (the Agent SDK version covers SDK apps):

  • List read tools by name rather than a glob like mcp__sume__jobs_*, which would also match jobs_cancel, a write tool.
  • Put paid creates under ask, not just outside allow. Ask beats allow, so they keep prompting even if someone later allows mcp__sume__*, and permissions.ask prompts even in bypassPermissions mode.
{
  "permissions": {
    "allow": [
      "mcp__sume__mcp_health",
      "mcp__sume__tools_list",
      "mcp__sume__tools_schema",
      "mcp__sume__jobs_status",
      "mcp__sume__jobs_wait",
      "mcp__sume__jobs_result"
    ],
    "ask": ["mcp__sume__generate_image", "mcp__sume__generate_video"]
  }
}

Isn't the server's own safety check enough?

It's a second layer, not a replacement. Sume requires an idempotency_key on write and paid tools, but its docs call that a key for transport and dedup, not human approval. What limits spend on the server side:

  • Sign in with OAuth and leave Write off: the session then sees read-only tools, and paid calls return insufficient_scope.
  • Ask for dry_run=true first; it previews admission and cost without submitting the job.
  • Pass max_spend_usd to cap a call; it is enforced only when provided.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume