Blog / permission prompts
How to approve Claude Code permission prompts from your phone
Send only prompts, questions and blockers to your phone, allow only what it shows in full, keep risky actions for the keyboard, and never let silence approve.
On this page
- What should reach your phone, and what should not
- Safe rules for approving agent actions from a phone
- Which actions always need a person at the keyboard
- One inbox for several coding agents
- What happens when the answer does not arrive
- When this is not enough
- Where Joxo fits
- Frequently asked questions
- Can I approve Claude Code permission prompts from my phone?
- Is it safe to approve coding agent commands from a phone?
- What happens if I do not answer a permission prompt?
Send your phone only what needs you: permission prompts, questions and blockers, one notification each, answerable in one tap. Keep a short list of actions that always wait for you at the keyboard, never let one agent approve another, and make sure a prompt nobody answers waits or is denied, never approved.
An agent that asks "may I run this?" while you are at lunch sits idle until you return. Answering from your phone fixes that; doing it carelessly turns a safety check into a reflex. This applies to Claude Code and to any coding agent that asks before it acts; the glossary has the one-line version.
What should reach your phone, and what should not#
The phone is for things that stop work until a person answers.
| Event | Send to the phone? | Why |
|---|---|---|
| A permission prompt | Yes | The agent is stopped until you answer |
| A question with a default answer | Yes | A quick answer unblocks it |
| A blocker that needs a person | Yes | Someone has to decide |
| A teammate hands you a task | Yes, once | You need to know it is yours |
| A commit pushed, tests started | No | Status; it belongs on the task |
| Every tool call the agent makes | No | Noise teaches you to tap Allow without reading |
The last row matters most. A phone that buzzes forty times an hour teaches you to approve the forty-first prompt unread.
Safe rules for approving agent actions from a phone#
- Only a person approves. An agent never approves another agent's prompt, and a request passed along by another agent is information, not permission.
- Only the owner of the computer approves its prompts. A teammate can answer a question about their part of the code. They should not approve a command on your machine.
- Read what will run. If the phone cannot show you the whole command or the whole file change, do not allow it: deny it, or answer at the keyboard.
- Approve once, for this call. An approval is for this exact action, now. If the command changes, it is a new prompt.
- Keep "always allow" narrow. Allow one command in one folder, such as the test runner, never a whole tool or "anything in the shell".
- When in doubt, deny with a reason. "Denied: use the staging database" gives the agent another path.
Which actions always need a person at the keyboard#
Some actions are too risky to judge on a small screen. Decide the list before you need it, and put it in your agent's instructions.
| The agent asks to | If nobody answers | Who may answer |
|---|---|---|
| Run the tests or the linter | Wait | You, phone or keyboard |
| Edit a file inside the task's folder | Wait | You, phone or keyboard |
| Install a package | Wait | You, after reading the exact name |
| Push a branch | Wait | You, phone or keyboard |
| Push to main, force-push or deploy | Deny | You, at the keyboard |
Read or change secrets, keys or .env files | Deny | You, at the keyboard |
| Delete data or migrate a shared database | Deny | You, at the keyboard |
| Change the agent's own permissions or settings | Deny | You, at the keyboard |
No row says "allow". Silence should never count as yes.
One inbox for several coding agents#
With one agent, its own notification is enough. Some agents now offer their own way to continue a session from your phone, prompts included, and for one session of one tool that works well.
With three agents across two tools and two computers, separate notifiers mean separate apps, and you stop knowing where to look. What you want is one list, where every item says:
- which computer and which agent is asking, and for which task;
- exactly what it wants to do;
- how long it has been waiting.
Answer items one at a time: a button that approves everything approves something you did not read. Quiet hours matter too: a question that can wait until morning should wait, and the agent should move to other work in the meantime, as we describe in how to coordinate AI coding agents across a team. Questions that need a whole team rather than one person belong in chat, as in team chat for coding agents.
What happens when the answer does not arrive#
Your phone is offline, or you are asleep. The safe behaviour:
- The prompt stays on the computer. You can still answer it at the keyboard. Nothing is approved by silence.
- With nobody at the computer, no answer means deny. The agent notes the blocker on its task and moves on, rather than waiting all night.
- A late answer counts only for the call it was given for. If the agent has since changed the command, the old answer must not apply to the new one.
Test it once before relying on it: ask your agent for something harmless that needs permission, such as listing a folder outside the project, and answer from your phone. Then do it again, do not answer, and check the prompt is still waiting when you get back.
When this is not enough#
Phone approvals keep an attended agent moving. They are not a reason to leave risky work running unattended: if a task needs many keyboard-only actions, do it at the keyboard. An approval is also not a review of the pull request that follows. And if your company needs central approval policies or an audit trail for every action, that is a different kind of tool.
Where Joxo fits#
Joxo's iPhone app (beta) shows permission prompts from Claude Code and Codex, and your agents' questions, from the computers you have linked to it, and you answer each with a tap. Phone approvals stay off until you turn them on for a computer, and signing in to the app is not enough: the computer trusts your phone only after you scan the code it shows, or, without a camera, after the app's 28-character code is entered on that computer.
What the agent wants to run is encrypted so that only your phone can read it, and your prompts go to your own phone, not to your teammates'. The phone is asked only after a prompt has waited unanswered on the computer, and the prompt still shows there, so you can answer at the keyboard instead. If no answer arrives, nothing is approved.
Allow works only on what the phone showed in full. A command too long to show can be denied from the phone but not allowed, and long text has to be opened before Allow lights up. "Always allow" is offered only for narrow, safe things, such as one test command or one project folder, never for a deploy, an install or a secrets file. It is kept on that computer and ends when you remove the phone. Setup is on the setup page, the FAQ covers what Joxo can see, and the hackathons page shows how a team uses it.
Frequently asked questions#
Can I approve Claude Code permission prompts from my phone?#
Yes, with a tool that sends the prompt to your phone and your answer back to the session. Whichever you use, check three things: it shows the full command before you approve, it approves only that one call, and a prompt you do not answer stays waiting on the computer rather than being approved by default.
Is it safe to approve coding agent commands from a phone?#
For routine actions, yes: running tests, editing files inside the task, pushing a branch. Keep a short list that always waits for you at the keyboard, such as deploys, force-pushes, secrets, deleting data and changes to the agent's own permissions. Never let another agent approve on your behalf, and deny anything the phone cannot show you in full.
What happens if I do not answer a permission prompt?#
It should wait. A well-behaved setup leaves the prompt on the computer so you can answer when you are back, and never treats silence as approval. For an agent working with nobody at the computer, an unanswered prompt should count as a deny, and the agent should note the blocker and move to other work.