← cd /blog

Article

Claude Code in VS Code Ignores bypassPermissions Without a Third Key

·
tools

In a terminal, Claude Code warns once before it runs in bypass mode, and accepting the warning writes skipDangerousModePermissionPrompt to ~/.claude/settings.json. In VS Code that dialog never renders, so even with both VS Code bypass settings set the session drops to default mode without a warning and every command raises the permission dialog. Write the key yourself.

The three settings

In VS Code's user settings.json (~/Library/Application Support/Code/User/ on macOS):

"claudeCode.initialPermissionMode": "bypassPermissions",
"claudeCode.allowDangerouslySkipPermissions": true

In ~/.claude/settings.json, at the top level, not inside permissions:

{
  "skipDangerousModePermissionPrompt": true,
  "permissions": {
    "defaultMode": "bypassPermissions"
  }
}

Then quit VS Code with Cmd+Q and reopen it.

The two VS Code settings are on Claude Code's VS Code docs page. skipDangerousModePermissionPrompt is on its permission modes and settings reference pages.

A growing allow list means bypass is off

The allow list in ~/.claude/settings.local.json was gaining entries across sessions. A list in that state looks like this (example entries, not the original file):

{
  "permissions": {
    "allow": [
      "Bash(git status:*)",
      "Bash(npm run build:*)",
      "Bash(ls:*)"
    ]
  }
}

Entries get added only when the permission system saves an approval. In bypass mode there is nothing to approve. A growing list means the extension is running in default mode.

The VS Code settings pass the first guard

Bypass mode has to get past two checks. The first is in the extension's JavaScript, extension.js in ~/.vscode/extensions/anthropic.claude-code-[version]-[platform]/. The decision lives in getInitialPermissionMode():

getInitialPermissionMode() {
  let z = getConfig("initialPermissionMode") || "default";
  if (z === "bypassPermissions" && !this.getAllowDangerouslySkipPermissions())
    return "default";
  return z;
}

Set claudeCode.initialPermissionMode to "bypassPermissions" and claudeCode.allowDangerouslySkipPermissions to true, and both conditions pass. The extension then hands bypassPermissions to the native binary bundled next to it.

The binary has a second guard

Before honouring bypass mode, the binary looks for skipDangerousModePermissionPrompt in its settings files (user, local or managed). The reporter of GitHub issue #25503 gives the check, de-minified:

if ((permissionMode === "bypassPermissions" || dangerouslySkipPermissions) && !skipDangerousModePermissionPrompt())

In a terminal, a missing key brings up the "WARNING: Claude Code running in Bypass Permissions mode" dialog. Accept it once and the binary writes the key to ~/.claude/settings.json for you. In VS Code the dialog never renders. The session falls back to default mode without a warning, and every command asks.

Anything that restores settings.json from elsewhere removes the key again. The issue describes the loop with a git-synced ~/.claude/ directory: the sync overwrites the file, and the dialog comes back.

Note: #25503 was opened on 13 February 2026 against the v2.1.41 CLI on Windows. A commenter confirmed it in v2.1.42 the next day.

What doesn't work

  • claudeCode.permissions.defaultMode in VS Code settings: no such setting, so VS Code ignores it.
  • skipDangerousModePermissionPrompt nested under permissions: also ignored.
  • Developer: Reload Window: the change needs a full quit.
  • The system CLI at ~/.local/bin/claude: the extension does not use it. It runs its own binary from resources/native-binaries/[platform]-[arch]/claude inside the extension folder, falling back to resources/native-binary/claude. The two versions can differ, for example CLI v2.1.42 while the extension runs v2.1.47.

Extension v2.1.47 broke it again

On 19 February, extension v2.1.47 prompted on every tool call, ls included, with all three settings correct. The extension's JavaScript still read both VS Code settings correctly. The workaround was a downgrade to v2.1.45:

code --install-extension anthropic.claude-code@2.1.45

Turn off extension auto-update, or it updates back:

"extensions.autoUpdate": false