Documentation
Agents, with an explicit boundary.
MCP tools and a separately verified native permission adapter.
MCP
The local stdio MCP server exposes notification and question tools. MCP clients can request a reply; support for those tools does not imply native interception of every host permission prompt.
Claude Code
The PermissionRequest adapter is designed for one invocation, with a 90-second remote wait and 100-second hook timeout. It must preserve existing deny rules and other hooks. The terminal can take over. A late Allow cannot revive an invocation that has ended. Unsupported tools, oversized context, verification failures, and timeouts return control to the terminal.
Verification status
Claude Code 2.1.283 on Linux x64 has completed real noninteractive Bash / Edit / Write Allow and Deny runs using the compiled CLI and local encrypted relay. Process termination, a 90-second unanswered timeout, existing deny rules, and coexisting hooks were checked. The receiver in those tests was programmatic, not a physical iPhone. Interactive terminal-choice precedence remains unverified; see the release report for the precise boundary. Other agents are MCP-only unless an adapter is explicitly listed and verified.
What an approval means
Approval permits the original, bound request once. It does not authorize arbitrary future shell commands. ntfyx records a unique remote decision and one-time consumption; it cannot guarantee exactly-once effects for every external system.