Claude Code permissions by example, auto-allow npm scripts, confirm git push, block force push
Originally published at https://aicoding-guide.com . When you let Claude Code drive, you usually want three lines drawn. Scripts you wrote yourself, such as npm run lint and npm run test , should run without a prompt. git push reaches the remote, so you want one last look right before it. git push --force should never run at all. All three fit in a single permissions block in settings.json ,…
Claude Code lets you set permissions for scripts and Git commands using a settings.json file. Allow rules run commands without prompting, ask rules prompt before running, and deny rules block commands entirely.
The example configuration allows npm run scripts automatically, confirms Git pushes before allowing, and blocks force pushes.
Auto-allowing npm scripts uses the Bash(npm run:*) prefix match, which triggers for any npm run command followed by a space. Install commands use Bash(npm install:*) and similar patterns for other package managers.
Git push is confirmed with Bash(git push:*) in ask mode, giving a prompt before running. Force pushes are blocked by a deny rule matching Bash(git push --force:*) and other force push variations.
Putting all these rules together in settings.json allows team members to run their own scripts and commits without interruption, while still reviewing pushes and preventing accidental force pushes.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.