# Claude Code Permissions, Cost, and Control — every post | Topic hub

Everything we've published on controlling Claude Code: which tools to deny, how deny lists get bypassed, what a session costs at API rates, and the 76-tool declared surface — all from live captured traffic.

<div class="acp-section" style="padding-top:56px;">
  <div class="acp-container" style="text-align:center;">
    <div style="display:inline-block;padding:5px 16px;border-radius:100px;background:linear-gradient(135deg,rgba(79,70,229,0.14),rgba(6,182,212,0.10));color:var(--color-accent);font-size:12px;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;margin-bottom:16px;">Topic hub</div>
    <h1 class="acp-hero-h1" style="font-size:44px;margin:0 auto;max-width:780px;">Claude Code: permissions, cost, control</h1>
    <p class="acp-subtitle" style="max-width:720px;margin:18px auto 0;">
      A real Claude Code session declares <strong>76 tools</strong> in every API request — the coding loop, plus tools that send messages, publish public web pages, schedule their own future runs, and drive your logged-in browser. Most of what's written about Claude Code permissions covers three of them. These posts cover the rest, from live captured traffic: which tools to deny out of the box, how the deny list gets bypassed, what a full working day costs at API rates ($148.16, in one real session), and how to see all of it on your own machine.
    </p>
    <p class="acp-subtitle" style="max-width:720px;margin:14px auto 0;font-size:14px;">
      Start with the <a href="/tool-surfaces">Tool Surface Index</a> — the live capture this cluster is built on — or the one-command setup on <a href="/for-coding-agents">ACP for coding agents</a>.
    </p>
  </div>
</div>

<div class="acp-section" style="padding-top:8px;">
  <div class="acp-container" style="max-width:780px;">
    <div class="acp-card acp-card-pad">
      <h2 class="acp-section-title" style="margin-bottom:20px;">Posts on Claude Code</h2>
      <ol style="list-style:none;padding:0;margin:0;display:grid;gap:18px;">
        
        
        
        <li style="padding-bottom:18px;border-bottom:1px solid var(--color-border);">
          <a href="" style="font-size:17px;font-weight:600;color:var(--color-text-primary);text-decoration:none;line-height:1.35;"></a>
          <div class="acp-muted" style="font-size:14px;margin-top:6px;line-height:1.5;"></div>
        </li>
        
        
      </ol>
      <p class="acp-muted" style="margin-top:24px;font-size:14px;">
        Related: <a href="/blog/tool-policy/">tool permissions &amp; policy</a> · <a href="/blog/agent-costs/">agent costs</a> · <a href="/series/stop-your-agent">the Stop Your Agent From… series</a> · <a href="/blog">all posts</a>
      </p>
    </div>
  </div>
</div>

<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "CollectionPage",
  "name": "Claude Code: permissions, cost, and control",
  "url": "https://agenticcontrolplane.com/blog/claude-code/",
  "description": "Posts on controlling Claude Code: deny lists and their bypasses, tool allowlists, per-session cost at API rates, and the 76-tool declared surface captured from live traffic."
}
</script>
