Skip to content
c permission
Edit
On this page

Reference for the c permission command group — subcommands, flags, arguments, and usage details for the permission group in the c CLI.

#c permission

add, remove, and list permission rules across Claude profiles

#permission add

Add a permission rule to a profile's settings.json. Takes a category (allow, deny, or ask) and a rule string such as Bash or Read(//home/**). Writes the rule into the specified category array. Use --profile to target a single profile or --all-profiles to apply the rule across every registered profile. Skips duplicates if the rule already exists in the category.

Effect: mutating

#Flags

Flags
NameShortTypePresenceEnvDescription
targetchoicerequiredSelection (not typed as a flag). Elect exactly one of --profile, --all-profiles. which profiles the operation applies to
    --profilestrrequiredElects target = profile. target one profile, by name Its value: name of the profile to target (e.g. work, personal, research)
    --all-profilesrequiredElects target = all-profiles. target every registered profile at once

#Arguments

Arguments
NameTypePresenceDescription
categorystrrequiredpermission category to add the rule to: allow, deny, or ask
rulestrrequiredpermission rule string to add (e.g. Bash, Read(//home/**), Edit)

#permission remove

Remove a permission rule from a profile's settings.json. Takes a category (allow, deny, or ask) and the exact rule string to delete. The rule is removed from the specified category array and the file is saved. Use --profile to target a single profile or --all-profiles to remove the rule from every registered profile. Reports whether the rule was found.

Effect: mutating

#Flags

Flags
NameShortTypePresenceEnvDescription
targetchoicerequiredSelection (not typed as a flag). Elect exactly one of --profile, --all-profiles. which profiles the operation applies to
    --profilestrrequiredElects target = profile. target one profile, by name Its value: name of the profile to target (e.g. work, personal, research)
    --all-profilesrequiredElects target = all-profiles. target every registered profile at once

#Arguments

Arguments
NameTypePresenceDescription
categorystrrequiredpermission category to remove the rule from: allow, deny, or ask
rulestrrequiredexact permission rule string to remove (must match an existing entry)

#permission list

List permission rules from a profile's settings.json. Displays rules in grouped or flat format controlled by --format. Use --category to filter output to a single category (allow, deny, or ask). Use --profile to inspect a single profile or --all-profiles to show rules from every registered profile, with each profile's rules displayed under a header. The framework-owned --json answers a machine instead: one envelope carrying every listed profile, whatever --format the human form would have used.

Effect: read_only

#Flags

Flags
NameShortTypePresenceEnvDescription
--formatstrrequiredoutput format: grouped (indented tree) or flat (tsv) Values: grouped (one indented block per category, one rule per line), flat (one tab-separated category-and-rule pair per line).
--categorystroptionalrestrict output to a single permission category (allow, deny, or ask)
targetchoicerequiredSelection (not typed as a flag). Elect exactly one of --profile, --all-profiles. which profiles the operation applies to
    --profilestrrequiredElects target = profile. target one profile, by name Its value: name of the profile to target (e.g. work, personal, research)
    --all-profilesrequiredElects target = all-profiles. target every registered profile at once

More tools from this site

  • claudestream Drive Claude Code from Python: run it as a subprocess and read its output as typed events, with async and sync sessions, sandbox policies, and tools you define in Python
  • dirstat Fast, single-binary directory statistics CLI: every file under a tree grouped by format, with counts, sizes, and lines of code, as a colored terminal table or as JSON
  • fastware A batteries-included ASGI framework: msgspec JSON, a managed Granian server, dependency injection, SSE, WebSockets, auth, and a test client
  • go-toml-edit Zero-dep TOML editing library for Go with comment preservation
  • howmuchleft The fastest Claude Code statusline: context window, 5-hour, and weekly limit usage as three customizable gradient bars, rendering in about 6 ms
  • orxtra
  • pgdesign
  • predraw Declarative rendering pipeline: describe a scene in JSON and get SVG, PNG and WebP out, with light and dark style tokens, reusable components and text converted to path outlines
  • reposummary Turn a git repository's history into a Markdown journal: pick a time window or revision range and get a readable digest of what changed, optionally narrated by an LLM
  • rlsbl Release orchestration and project scaffolding CLI that bumps versions, validates a structured JSONL changelog, tags only the commit CI verified, and publishes to npm, PyPI, Go and more
  • safegit git wrapper CLI that gives each commit its own temporary index and retries ref updates on conflict, so concurrent agents share one repository
  • saferm Command-line replacement for rm that archives every deletion with a mandatory reason and the context it ran in, so deleted files can be listed, inspected and restored
  • selfdoc Static Site Generator that builds a project's documentation site directly from its source code, so the docs can never drift from the code they describe, with SEO/AEO, first-class blog, search, and cross-project linking built in
  • strictcli
  • stricttest An always-on test-isolation floor: a pytest plugin and a Go env-hygiene module that make a test suite structurally unable to reach real credentials, the real HOME, the network, or the development repository.
  • wesktop A Python framework that turns an ASGI web app into a desktop application, serving it from a local Granian server and displaying it in a native OS window via pywebview
Search