From the Inside Claude Code: The Claude Code Ecosystem architecture map

Tool permission requests fail closed

strength · low · verified

Control Protocol Query answers a can_use_tool request with an error when no callback is registered, an unknown hook callback ID with an error, and any unsupported request subtype with an error, rather than a default allow. A callback that returns anything other than PermissionResultAllow or PermissionResultDeny is also turned into an error response.

_configure_can_use_tool also routes permission prompts to stdio and refuses to combine can_use_tool with permission_prompt_tool_name, so one gate decides each tool call.

The trail

  1. Subprocess CLI Transport
  2. Control Protocol Query
  3. ClaudeSDKClient
Open on the map

More from this board

© 2026 Syntaxia App Platform Ltd.

Syntaxia App Platform Ltd. Registered in England and Wales, company no. 15272701 Registered office: 3rd Floor, 86–90 Paul Street, London EC2A 4NE, United Kingdom contact@provenmap.com