Make an absent approver an explicit denial
Use when: a scheduled, CI, SDK, or remote Claude Code run has no human available, yet its active mode or permission host can still produce unresolved prompts.
2.1.260
or
later
and
launch:
claude -p "Update dependency pins and run tests" \ --permission-mode auto --permission-prompts noneKeep explicit allow/deny rules and
PermissionRequest
hooks.
This
flag
handles
only
requests
left
unresolved
after
those
controls;
do
not
replace
it
with
bypassPermissions.
Acceptance
check:
run
with
stream-json
and
two
owned
canaries:
one
pre-approved
read
and
one
write
outside
the
allowlist.
Pass
only
if
the
read
succeeds,
the
write
has
no
effect,
a
permission_denied
system
message
appears,
the
final
result
lists
the
denial,
and
the
permission-host
callback
is
never
called.
2.1.259
added
the
flag;
current
2.1.260
retains
it.
Anthropic’s
headless
and
CLI
references
document
the
evaluation
order,
callback
suppression,
AskUserQuestion
removal,
MCP-elicitation
cancellation,
and
receipt
fields.
Caveat:
a
PermissionRequest
hook
may
still
allow
an
action,
and
auto
mode
remains
model-classified.
The
flag
prevents
waiting
or
retrying
for
absent
approval;
it
is
neither
an
OS
sandbox
nor
a
universal
deny.