Claude Code permissions ask rule for paid MCP tools

An ask rule in Claude Code settings prompts every time a named MCP tool runs, even if an allow rule matches. Rules for Sume's paid tools and their limits.

5 min readSume
All posts

Add the tool names to permissions.ask in your Claude Code settings. An ask rule prompts for confirmation whenever Claude Code tries to use the tool, and it wins over an allow rule that also matches. For Sume, list the paid tools there and allow the rest of the server.

That is from Anthropic's permissions page, read 2026-09-29. The paid tool names come from Sume's MCP tools and gates, and the server is called sume as in the MCP quickstart.

What does the settings file look like?

Put this in .claude/settings.json. Anthropic's page says allow rules take tool-name globs after a literal mcp__<server>__ prefix, so the allow line covers the whole sume server, and the ask lines name the paid tools.

{
  "permissions": {
    "allow": ["mcp__sume__*"],
    "ask": [
      "mcp__sume__generate_video",
      "mcp__sume__generate_image",
      "mcp__sume__tts_create",
      "mcp__sume__music_create"
    ]
  }
}

Why does the ask rule win over the allow rule?

Rules are evaluated in the order deny, then ask, then allow, and the first match decides. The page says the same precedence holds between ask and allow: a matching ask rule prompts even when a more specific allow rule also matches. That is why a broad allow plus a few asks works.

From Anthropic's permissions page, read 2026-09-29.
Rule typeEffect
denyPrevents the tool; a bare name removes it from Claude's context
askPrompts every time the tool is used
allowRuns without a manual approval

Can a rule check dry_run or max_spend_usd?

No. The page says Claude Code skips any mcp__ rule that has parentheses when it loads a settings file, so mcp__sume__generate_video(dry_run:true) is ignored. The parameter form works on built-in tools only. An ask rule therefore prompts for a dry_run preview and a real submit alike.

If you want previews to pass and uncapped submits to be denied, that needs a PreToolUse hook, which can read the arguments. See Claude Code: allow MCP tools without approving every call for the allow side.

What does an ask rule not replace?

Sume's own gates still apply. Paid tools require an idempotency_key, and dry_run and max_spend_usd are optional arguments the model has to send. The prompt is your check that it did. Anthropic's page also notes rules are enforced by Claude Code, not the model, so telling the model in a prompt to ask first does not do the same job.

A typo matters: a deny or ask rule whose tool name matches no known tool produces a startup warning, but names containing _ or * are exempt from that check. Every Sume tool name has an underscore, so check the spelling against tools_list yourself.

How do I check the rules loaded?

Run /permissions. The page says the dialog lists every rule and the settings file each one came from. Rules with parentheses on an mcp__ tool would show up in the invalid-settings dialog and in claude doctor.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume