Claude Code permissions ask rule for paid MCP tools
An ask rule in Claude Code settings prompts every time a named MCP tool runs, even if an allow rule matches. Rules for Sume's paid tools and their limits.

Add the tool names to permissions.ask in your Claude Code settings. An ask rule prompts for confirmation whenever Claude Code tries to use the tool, and it wins over an allow rule that also matches. For Sume, list the paid tools there and allow the rest of the server.
That is from Anthropic's permissions page, read 2026-09-29. The paid tool names come from Sume's MCP tools and gates, and the server is called sume as in the MCP quickstart.
What does the settings file look like?
Put this in .claude/settings.json. Anthropic's page says allow rules take tool-name globs after a literal mcp__<server>__ prefix, so the allow line covers the whole sume server, and the ask lines name the paid tools.
{
"permissions": {
"allow": ["mcp__sume__*"],
"ask": [
"mcp__sume__generate_video",
"mcp__sume__generate_image",
"mcp__sume__tts_create",
"mcp__sume__music_create"
]
}
}Why does the ask rule win over the allow rule?
Rules are evaluated in the order deny, then ask, then allow, and the first match decides. The page says the same precedence holds between ask and allow: a matching ask rule prompts even when a more specific allow rule also matches. That is why a broad allow plus a few asks works.
| Rule type | Effect |
|---|---|
deny | Prevents the tool; a bare name removes it from Claude's context |
ask | Prompts every time the tool is used |
allow | Runs without a manual approval |
Can a rule check dry_run or max_spend_usd?
No. The page says Claude Code skips any mcp__ rule that has parentheses when it loads a settings file, so mcp__sume__generate_video(dry_run:true) is ignored. The parameter form works on built-in tools only. An ask rule therefore prompts for a dry_run preview and a real submit alike.
If you want previews to pass and uncapped submits to be denied, that needs a PreToolUse hook, which can read the arguments. See Claude Code: allow MCP tools without approving every call for the allow side.
What does an ask rule not replace?
Sume's own gates still apply. Paid tools require an idempotency_key, and dry_run and max_spend_usd are optional arguments the model has to send. The prompt is your check that it did. Anthropic's page also notes rules are enforced by Claude Code, not the model, so telling the model in a prompt to ask first does not do the same job.
A typo matters: a deny or ask rule whose tool name matches no known tool produces a startup warning, but names containing _ or * are exempt from that check. Every Sume tool name has an underscore, so check the spelling against tools_list yourself.
How do I check the rules loaded?
Run /permissions. The page says the dialog lists every rule and the settings file each one came from. Rules with parentheses on an mcp__ tool would show up in the invalid-settings dialog and in claude doctor.
Sources
Related posts
More in Developers
- claude -p with --mcp-config: run Sume video tools from a script
Use claude --bare -p with --mcp-config and --allowedTools to call Sume's hosted MCP tools in CI; read mcp_server_errors so an unloaded server fails the job.
- Claude Code hooks not firing on an MCP tool: 6 causes
A PreToolUse hook that never fires on an MCP tool usually has a matcher problem: a bare server name, a plugin's scoped name, or a missing .*. Fixes for Sume.
- Claude Code PreToolUse hook example: gate paid Sume tools
A PreToolUse hook that lets dry_run previews through, denies paid Sume MCP calls with no max_spend_usd, and asks you before the rest. Script and settings.
- Claude Code subagent MCP server: scope Sume tools to one
Put a Sume MCP server in one subagent's mcpServers field so video and image tools stay out of the main chat. Frontmatter for both routes, plus limits.
Written by Sume