Claude Code

Tool reference

Built-in tools, permission rules, hook matchers, Bash/Edit/Grep/Agent behavior, and extending tools with MCP.

Claude Code tool names appear in permissions, hook matchers, subagent tools, skill allowed-tools, and CLI flags. Understanding the names is essential to reliable permission and automation rules.

#Common built-in tools

ToolPurposePermission behavior
ReadRead filesGoverned by Read deny/allow
EditExact replacement in a fileUsually requires approval
WriteCreate or overwrite filesUsually requires approval
BashRun shell commandsUsually requires approval
PowerShellRun PowerShell on Windows or when enabledUsually requires approval
GlobFind filenamesNormally no prompt
GrepSearch contents with ripgrepNormally no prompt, subject to Read path rules
LSPDefinitions, references, type diagnosticsNormally no prompt
AgentStart a subagentLaunch normally has no prompt; internal tools retain checks
MonitorMonitor commands, logs, or WebSockets in the backgroundUsually requires approval
WebFetchRead web pagesUsually requires approval
WebSearchSearch the webUsually requires approval
SkillInvoke a skillDepends on skill and rules
WorkflowRun a dynamic workflowUsually requires approval

MCP tool names use mcp__server__tool. A mcp__* rule can target all MCP tools.

#Permission rule formats

FormatTools coveredExample
Bash(pattern)Bash, MonitorBash(npm run *)
PowerShell(pattern)PowerShellPowerShell(Get-ChildItem *)
Read(path)Read, Grep, Glob, LSPRead(./docs/**)
Edit(path)Edit, Write, NotebookEditEdit(./src/**)
Skill(name *)SkillSkill(deploy *)
Agent(name)AgentAgent(Explore)
WebFetch(domain:host)WebFetchWebFetch(domain:docs.example.com)
WebSearchWebSearchWebSearch

An Edit allow rule usually also grants reads for the same path. Hook matchers use plain tool names, such as Edit|Write|Bash, not permission patterns such as Edit(./src/**).

#Bash behavior

RuleDetail
Each call starts a separate processExported variables do not automatically persist to the next command
cd can persist in the main sessionWithin the project or additionally authorized directories
Subagents do not inherit Bash cwdEach uses its own working directory
Default timeout is about two minutesClaude can request longer; environment variables can configure it
Long output is truncatedFull output may be saved in session files for later reading
Long-running tasks can run in the backgroundInspect or stop them with /tasks

For persistent variables, configure the shell before launching Claude, or use CLAUDE_ENV_FILE / a SessionStart hook.

#Edit behavior

Edit performs exact string replacement, not a fuzzy patch. It checks:

CheckMeaning
Read-before-editThe session must have read the file, without an external change since
Matchold_string must match exactly
UniquenessUsually one match; otherwise provide more context or replace_all

Reading through Bash does not always count. Simple cat, sed -n, head, or tail may qualify, while pipes, redirects, and scripted reads usually do not. Prefer Read when in doubt.

#Grep, Glob, and LSP

ToolNotes
GlobFinds names, sorts by modification time, and may include gitignored files
GrepUses ripgrep, respects .gitignore by default, and follows rg regex syntax
LSPRequires the language's code-intelligence plugin

In large repositories, locate symbols with Grep/LSP before reading a few key files. This reduces context usage and improves cache reuse.

#Agent tool

Agent launches subagents with separate context windows and caches. They return final results to the main session.

ScenarioRecommendation
Broad researchIsolate file reads in a subagent
Result needed immediatelyForeground subagent
Independent parallel workBackground subagent or /batch
Sensitive toolsRestrict tools or disallowedTools in subagent frontmatter

Launching a subagent normally does not prompt, but its Bash/Edit/Write operations still follow permissions. Use worktrees to isolate file changes.

#Extend tools with MCP

Built-in tools handle editing and local execution. Use MCP for external systems:

NeedApproach
Databases, Sentry, Linear, GitHubConnect an MCP server
Many toolsUse supported tool search or split servers
Restrict an MCP tooldeny: ["mcp__server__tool"]
Observe callsMatch mcp__server__tool in a hook

See MCP integration.

#Official references

Support

Need help?

For setup, billing, or model issues, email us. Check the status page for uptime.

WeChat / QQ support is available at the bottom right.