claude -p --permission-prompts none: Sume tools in CI

With --permission-prompts none, prompts nobody can answer are denied. Which Sume tools still run? Read-only OAuth ones do; paid ones need mcp:write.

4 min readSume
All posts

--permission-prompts none tells Claude Code to deny any permission prompt that nobody can answer. In a Sume CI job, a tool you did not pre-allow is denied instead of hanging. Separately, Sume refuses write and paid tools unless the session has mcp:write or an API key, so the two layers fail the same way: closed.

What does the flag do?

The CLI reference says to pass none when nobody can answer, and Claude Code denies the prompts instead (v2.1.259 and later).

Claude Code CLI reference (read 2026-10-09)
FlagEffectSince
--permission-prompts noneDenies prompts nobody can answerv2.1.259+

Which Sume tools survive?

Under OAuth mcp:read, Sume exposes read-only tools: for example mcp_health, tools_list, account_me, balance_get, catalog_list, jobs_get and generation_admission_preview. A call to a paid tool such as generate_image returns insufficient_scope.

How do you let a job spend?

Two separate grants. First, the Sume session needs mcp:write or an API key. Second, Claude Code needs the tool in its allow rules, because a denied prompt cannot be approved mid-run. Then keep the Sume gates on:

  • idempotency_key on every paid or write call.
  • max_spend_usd on every paid call, so the cap is explicit.
  • dry_run=true for the first call in a new job.

Which should you pick?

For a nightly report on balance and recent jobs, use OAuth read and no allow rules for paid tools. For a build that renders, use a scoped key and a short allow list. See MCP OAuth and API keys.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume