Make Claude Code confirm every git push with an ask rule

Claude Code Published:

Let Claude commit on its own but stop before git push, using permissions.ask. Covers which rule wins when allow and ask both match, branch-scoped rules, and how to verify it.

Verified on Sep 7, 2026 These tools change quickly. Please also check the latest official documentation.
Contents
  1. The setting
  2. What the prompt's options do
  3. Auto-allow one branch only
  4. Verify it
  5. Related settings
  6. Summary

"I want Claude to commit on its own, but a push reaches the remote, so I want the last word." That requirement is one line: put git push in permissions.ask.

An ask rule means "prompt me even if an allow rule matches." You can automate the read-only Git commands and commits while still stopping at the push.

KEY POINT

What you will learn

  • How to write an ask rule that only stops git push
  • Which rule wins when allow and ask both match
  • What the prompt's options do, and what they change in your settings

The setting

{
  "permissions": {
    "allow": [
      "Bash(git status)",
      "Bash(git diff:*)",
      "Bash(git log:*)",
      "Bash(git add:*)",
      "Bash(git commit:*)"
    ],
    "ask": [
      "Bash(git push:*)"
    ],
    "deny": [
      "Bash(git push --force:*)",
      "Bash(git push -f:*)"
    ]
  }
}

With this, git status, git diff, git add and git commit run without a prompt, and only git push opens a dialog. Force pushes are blocked outright by the deny rules.

用語解説

Rule precedence: rules are evaluated deny, then ask, then allow, and the first match in that order decides. Specificity does not change the order, so an allow rule for Bash(git:*) does not stop an ask rule for Bash(git push:*) from prompting.

What the prompt's options do

OptionEffect
Allow onceRuns this one call
Don't ask againAppends an allow rule to settings.local.json — but you are still prompted next time while the ask rule remains
DenyDoesn't run, and lets you tell Claude why

That "don't ask again" leaves the ask rule in place is intended. It keeps you from undoing "I always review pushes myself" with one careless keystroke.

Auto-allow one branch only

If you want pushes to your own working branches to go through, write a narrower allow rule. An ask rule for Bash(git push:*) would still prompt, so scope the ask rule too.

{
  "permissions": {
    "allow": [
      "Bash(git push origin feature/*:*)"
    ],
    "ask": [
      "Bash(git push origin main:*)",
      "Bash(git push origin develop:*)"
    ]
  }
}

This depends on Claude writing the command in the git push origin feature/xxx shape. A bare git push matches neither rule and falls through to your defaultMode. If you care more about reliability than convenience, skip the branch scoping and keep a single "always confirm pushes" rule.

Verify it

  1. Save the setting and restart Claude Code.
  2. Make a small change and say "commit this and push it."
  3. The commit should go through without a prompt, and a dialog should appear right before the push.

For the overall design, see the parent article, Design permissions in Claude Code's settings.json. To block force pushes outright, see Deny git push --force in Claude Code.

Summary

  • Bash(git push:*) in permissions.ask forces a prompt right before every push
  • Ask outranks allow, so a blanket allow rule for Git does not let a push through
  • "Don't ask again" writes an allow rule but does not remove the ask rule, so prompts continue
  • Branch scoping depends on how Claude spells the command; a single always-confirm rule is the reliable choice

FAQ

If allow has all of git and ask has git push, which wins?
Ask wins, so git push prompts. An ask rule exists precisely to force a prompt even when an allow rule also matches the call.
What happens if I choose "don't ask again" at the prompt?
An allow rule is appended to settings.local.json, but as long as the ask rule is still there you keep getting prompted. To stop the prompts, edit the settings file and remove the ask rule.

Primary sources

This article was drafted by AI from official documentation and reviewed by the site operator before publishing. Found a mistake? Let us know via the contact page.