TL;DR It's the same thing as
--permission-mode bypassPermissions. Run it inside a container or VM as a non-root user (Anthropic's reference devcontainer ships that way). On your own machine,--allow-dangerously-skip-permissionsputs it in theShift+Tabcycle without starting in it.
claude --dangerously-skip-permissions starts Claude Code in bypassPermissions mode: it edits files, runs commands and calls tools without a single approval prompt. It's the short form of --permission-mode bypassPermissions, and the name tells you what you're signing up for: the human is out of the loop and Claude acts with your user's permissions.
What each flag does
I checked it on v2.1.284 with my user settings left out (--setting-sources project), two ways: in an interactive session, pressing Shift+Tab and reading the status bar, and with claude -p, reading the permissionMode the session reports at startup (--output-format stream-json --verbose):
| You start with | Starts in (interactive, Max plan) | Starts in (-p) |
Shift+Tab cycle |
|---|---|---|---|
| nothing | auto |
default (Manual) |
no bypass |
--dangerously-skip-permissions |
bypassPermissions |
bypassPermissions |
bypass included |
--allow-dangerously-skip-permissions |
auto |
default (Manual) |
bypass included, between plan and auto |
In an interactive session the status bar shows it: ⏵⏵ bypass permissions on. To skip typing the flag, "defaultMode": "bypassPermissions" works in ~/.claude/settings.json, but no longer in the project's .claude/settings.json: since v2.1.257 it's silently ignored.
The first time, it makes you sign
Your first interactive session in this mode opens a full-screen warning. This is its text, pulled from the v2.1.284 binary:
WARNING: Claude Code running in Bypass Permissions mode
In Bypass Permissions mode, Claude Code will not ask for your approval
before running potentially dangerous commands. This mode should only be
used in a sandboxed container/VM that has restricted internet access and
can easily be restored if damaged.
By proceeding, you accept all responsibility for actions taken while
running in Bypass Permissions mode.
❯ No, exit
Yes, I accept
The preselected option is to exit. Accept, and Claude Code writes "skipDangerousModePermissionPrompt": true to ~/.claude/settings.json and never asks again. With -p there's no warning, but a background session started with --bg won't start in this mode until you've accepted it once interactively.
And on my machine, which has bypassPermissions as the default mode in user settings, v2.1.284 opens a second dialog at startup: it offers to make auto mode my default permission mode, with "No, keep bypass permissions" as the other choice. In other words, Claude Code itself points you to the classifier instead of bypass.
Root and sudo: what counts as a sandbox
--dangerously-skip-permissions cannot be used with root/sudo privileges for security reasons
On Linux and macOS, run Claude Code as root (or with sudo) and it refuses to start in this mode. The docs say the check is skipped "inside a recognized sandbox." The v2.1.284 binary spells out what that means, and it's stricter than it sounds: root only gets through when the IS_SANDBOX variable is 1 or CLAUDE_CODE_BUBBLEWRAP is set. Being inside Docker isn't enough: a container running as root throws the same error.
Two ways out, and the first is the right one:
- A non-root user in the container. That's what the reference devcontainer does:
USER nodein the Dockerfile and"remoteUser": "node"indevcontainer.json. IS_SANDBOX=1if the container has to run as root. That variable tells Claude Code it's sandboxed, so set it only where that's true. On your own machine it removes the last brake.
That last part comes from reading the code; I didn't run it as root.
Where it's safe to run
1. In a container or VM
The docs limit it to isolated environments "like containers, VMs, or dev containers without internet access." The reference devcontainer covers all three: a node user, a firewall that comes up with the container and only lets traffic out to the domains it needs, and your machine out of reach. That's where --dangerously-skip-permissions does what it was built for: leaving Claude to work unattended.
2. On your machine: keep it close, not on
claude --allow-dangerously-skip-permissions
You start in your usual mode (auto on my Max plan), or in plan if you add --permission-mode plan, and bypass sits in the Shift+Tab cycle, right after plan, for when you decide to use it, for one specific task. If what you're after is fewer approval prompts without dropping every check, the sandbox fences in disk and network, and this guide ranks the alternatives.
3. On a team: block it
If you manage Claude Code for other people, this in managed settings removes the mode for everyone:
{
"permissions": {
"disableBypassPermissionsMode": "disable"
}
}
What it doesn't skip, despite the name
Explicit ask rules still prompt, and so do rm removals of critical paths and MCP tools that require user interaction. The full list, and why a denied permission in a -p script still finishes green, is in the silent failure tip.
In the VS Code extension the mode doesn't show up until you turn on Allow dangerously skip permissions in its settings; in the desktop app, Allow bypass permissions mode. The other modes, on Shift+Tab, are in the 6 permission modes.
Official docs: Choose a permission mode · CLI reference · Development containers