Live · Permission modes

Claude Code Auto Mode: How to Turn It Off Now That It's the Default

As of 2026-10-07, Claude Code's interactive terminal and VS Code sessions start in auto mode when no permission mode is configured; to turn it off, press Shift+Tab to switch back to Manual, or set permissions.defaultMode in ~/.claude/settings.json. The official sources date this default differently: the permission modes docs say from v2.1.283, while the changelog applies 2.1.283 only to interactive sessions on third-party providers or with telemetry off and writes "on every plan and provider" under 2.1.284; this page lists both as written. In auto mode a separate classifier model reviews actions before they run instead of asking you at each step. This page explains the six permission modes from the official docs, how to change the default, and what teams and CI pipelines should watch for.

Updated 2026-10-07

#auto mode#Permission modes#defaultMode#disableAutoMode

Four things to remember

2.1.283 / 2.1.284

The two official version statements

The permission modes docs say that from v2.1.283, auto is the built-in starting mode for interactive terminal and VS Code sessions on every plan and provider, and that earlier versions defaulted to auto only on Pro, Max, and Team plans; the changelog puts "on every plan and provider" under 2.1.284. The two don't match, so this page lists both as written.

6

Official permission modes

default (shown as Manual), acceptEdits, plan, auto, dontAsk, and bypassPermissions. They differ in which actions run without asking you.

defaultMode

The setting that changes the default

Put it under permissions.defaultMode in ~/.claude/settings.json; auto or bypassPermissions in a project's .claude/settings.json does not take effect.

disableAutoMode

Turning it off for a team

Set permissions.disableAutoMode to "disable"; in managed settings members can't override it, and auto disappears from the Shift+Tab cycle.

What auto mode is

As of 2026-10-07, auto mode is a Claude Code permission mode in which a separate classifier model reviews actions before they run. In the docs' words it blocks anything that "escalates beyond your request, targets unrecognized infrastructure, or appears driven by hostile content Claude read". Routine actions no longer prompt one by one, but your explicit ask rules still force a prompt. The docs also warn that auto mode reduces permission prompts but does not guarantee safety, so sensitive operations still need your review. It has model requirements: on the Anthropic API it needs Claude Opus 4.6 or later, Sonnet 4.6 or later, or a Fable model; Sonnet 4.5, Opus 4.5, Haiku, and claude-3 models are not supported on any provider.

What the vendor says (2.1.283 to 2.1.285)

Three releases in the changelog touch the default. 2.1.283 starts interactive sessions on third-party providers or with telemetry off in auto mode when no permission mode is configured. 2.1.284 says interactive terminal and VS Code sessions start in auto mode "on every plan and provider". 2.1.285 makes claude -p and Python Agent SDK sessions on third-party providers or with telemetry off start in auto mode too, and also shows the one-time offer to make auto your default on third-party providers and with telemetry off, when your user settings default to another mode. All three default changes say they can be overridden: permissions.defaultMode for interactive sessions, --permission-mode for claude -p. The permission modes docs, by contrast, say that from v2.1.283 auto is the built-in starting mode for interactive terminal and VS Code sessions on every plan and provider. The two sources give different versions, the vendor has not said which one is authoritative, and this page lists both as written.

Timeline of the default change

2026-09-25

Claude Code 2.1.283 ships: interactive sessions on third-party providers or with telemetry off start in auto mode when no permission mode is configured; permissions.defaultMode still overrides it.

2026-09-28

2.1.284 ships: interactive terminal and VS Code sessions start in auto mode when no permission mode is configured, on every plan and provider.

2026-09-29

2.1.285 ships: claude -p and Python Agent SDK sessions on third-party providers or with telemetry off also start in auto mode; --permission-mode still overrides it.

Confirmed vs not verified

Confirmed (verbatim in the official pages)

All of the following can be checked word for word in the Claude Code changelog and docs: the three default changes in 2.1.283, 2.1.284, and 2.1.285 with their release dates; the docs' statement that interactive terminal and VS Code sessions default to auto from v2.1.283 (set against the changelog's version above); the six permission modes and what each runs without asking; the order that decides a session's starting mode (the --permission-mode flag, permissions.defaultMode in settings, then the built-in default); setting permissions.defaultMode in ~/.claude/settings.json; auto and bypassPermissions not taking effect from project or local settings; what disableAutoMode does; the models auto mode supports; and the official warnings about bypassPermissions. Also checkable: QCode's feature availability page (updated 2026-09-18) carries a test record about auto mode. That only shows the page says so; it does not describe current versions.

Unverified or not published

Four things we could not verify, so don't base decisions on them: 1) the auto mode test record in QCode's docs (2026-09-18) predates 2.1.283 and has not been retested since (the page still shows 2026-09-18, and this page has not retested it either); 2) whether auto became the default on every plan and provider in 2.1.283 or in 2.1.284: the docs and the changelog say different things, and the vendor has not said which is authoritative; 3) what the classifier blocks is defined in the docs' "What the classifier blocks by default" section, and block lists or claims about how much safer it is than manual review that circulate online are not in any primary source; 4) whether the built-in default will change again has not been announced, so check the changelog after each upgrade.

How it compares with the other modes

auto vs default / acceptEdits

default (Manual) runs only reads without asking and prompts for everything else; the docs recommend it for sensitive work. acceptEdits also allows file edits and common filesystem commands such as mkdir, touch, mv, and cp, which suits iterating on code you're reviewing. auto runs everything with background safety checks, aimed at long tasks and reducing prompt fatigue. Pick default to approve things yourself, acceptEdits for fewer interruptions without a classifier.

auto vs dontAsk / bypassPermissions

dontAsk runs reads and pre-approved tools and denies anything that would prompt; the docs position it for locked-down CI and scripts. Per the docs, bypassPermissions disables permission prompts and safety checks so tool calls execute immediately. The official warnings: it offers no protection against prompt injection or unintended actions, and it should only be used in isolated environments like containers, VMs, or dev containers without internet access, where Claude Code cannot damage your host system. Deny rules apply in every mode, including that one. auto has classifier review, but the docs also say it does not guarantee safety.

How to turn it off or change the default

1) Check the current mode: the status bar shows ⏵⏵ auto mode on in auto mode. 2) Switch for now: press Shift+Tab to cycle permission modes; from auto the first press goes to default (Manual), then acceptEdits and plan. 3) Change one launch: start with claude --permission-mode default (the CLI also accepts manual as an alias). 4) Change the default for good: the official example puts {"permissions": {"defaultMode": "default"}} in ~/.claude/settings.json, and the next session shows ⏸ manual mode on. If your ~/.claude/settings.json already sets a non-auto defaultMode and no other settings file sets one, sessions keep starting in that mode. 5) Mind the file: auto and bypassPermissions don't take effect from a project's .claude/settings.json or .claude/settings.local.json; other values do. 6) Disable it for an organization: set permissions.disableAutoMode to "disable" in managed settings. auto leaves the Shift+Tab cycle, and a session started with --permission-mode auto starts in Manual; when the setting reaches a running auto session from an admin-deployed source, that session also leaves auto mode (before v2.1.251, a running session kept auto mode until it ended).

On QCode

QCode's docs say connecting Claude Code takes two environment variables: ANTHROPIC_BASE_URL set to https://api.qcode.cc/api (no trailing slash) and ANTHROPIC_AUTH_TOKEN set to the key starting with cr_ that you create in the console. QCode also has a Los Angeles node, us.qcode.cc, for users in North America and Europe. On permission modes, QCode's Claude Code feature availability page (updated 2026-09-18) records a test in which, with a QCode key, Write and Bash were all denied under --permission-mode auto. That is the page's record from 2026-09-18, before 2.1.283 shipped on 2026-09-25, and it has not been retested since; the page itself says it can go out of date and that your own test wins. It is a documentation record about auto mode only. If actions are denied in auto mode, the official docs give these ways out: press Shift+Tab during a session to switch permission modes (from auto, the first press goes to default, that is, Manual); start a single session with claude --permission-mode default; to change the default, set permissions.defaultMode in ~/.claude/settings.json. Models such as claude-sonnet-5-5 and claude-opus-5-5 are billed per token; see /models for each model's rate.

Frequently asked questions

How do I turn off Claude Code auto mode?

In the current session, press Shift+Tab to switch to default (Manual). To turn it off for good, set defaultMode to default or acceptEdits under permissions in ~/.claude/settings.json. For a single launch, use claude --permission-mode default. To remove it for a whole organization, set permissions.disableAutoMode to "disable" in managed settings.

Why does Claude Code start in auto mode after I upgraded?

Because the built-in default changed: with no permission mode configured, interactive terminal and VS Code sessions start in auto. As for the version, the official permission modes docs say v2.1.283, while the changelog has 2.1.283 covering interactive sessions on third-party providers or with telemetry off and 2.1.284 extending it to every plan and provider. The first time the built-in default puts you in auto mode, the terminal shows a notice once at the top of the session. If ~/.claude/settings.json already sets a non-auto defaultMode and no other settings file sets one, sessions keep starting in that mode; on Pro, Max, and Team plans and in sessions that don't fetch feature flags, Claude Code asks once whether to switch the setting to auto, and if you decline, your setting stays as it is.

Why doesn't defaultMode auto in my project's .claude/settings.json work?

That is by design: auto in .claude/settings.json or .claude/settings.local.json doesn't take effect, and Claude Code then uses the built-in default rather than the defaultMode from ~/.claude/settings.json. The docs say to move it to ~/.claude/settings.json, or pass --permission-mode auto at launch. bypassPermissions doesn't take effect from those two files either, and the session starts in Manual.

What is the difference between auto and bypassPermissions?

In auto mode a classifier reviews actions before they run, and explicit ask rules still prompt. Per the docs, bypassPermissions disables permission prompts and safety checks so tool calls execute immediately. The official warnings for bypassPermissions are that it offers no protection against prompt injection or unintended actions and should only be used in isolated environments like containers, VMs, or dev containers without internet access; for auto, the warning is that it does not guarantee safety and is no replacement for reviewing sensitive operations.

What mode do CI runs and claude -p use by default?

It depends on whether the session fetches feature flags. Sessions that do start in default; sessions that don't, such as on a third-party provider or with telemetry off, start in auto from 2.1.285 and in default on earlier versions. To lock CI down, the official example is claude -p with --permission-mode dontAsk and an --allowedTools allowlist. Since 2.1.259 there is also --permission-prompts none, which denies anything that would prompt.

Which models support auto mode?

On the Anthropic API: Claude Opus 4.6 or later, Sonnet 4.6 or later, or a Fable model. Sonnet 4.5, Opus 4.5, Haiku, and claude-3 models are not supported on any provider. When the flag, a settings file, or the built-in default selects auto but auto mode isn't available to the session, Claude Code starts the session in Manual instead.

Sources

Claude Code changelog (CHANGELOG.md in the anthropics/claude-code GitHub repository, fetched 2026-10-07): the entries for 2.1.259, 2.1.283, 2.1.284, and 2.1.285; release dates from the same repository's GitHub Releases publish times (UTC). Claude Code official docs (code.claude.com, fetched 2026-10-07): the permission modes and permissions pages. QCode docs (docs.qcode.cc, fetched 2026-10-07): the environment variables page and the Claude Code feature availability page.

Use Claude Code on QCode

Set ANTHROPIC_BASE_URL and your cr_ key as the docs describe, then reach claude-sonnet-5-5, claude-opus-5-5 and more from one endpoint, billed per token.

Try first, then decide

Not sure which tier? Start with Starter ($8.57/mo) and upgrade when you're happy — the unused value of the old plan goes back to your balance.