Blog

How to run Claude Code overnight, safely

10 October 2026 · 7 min read

In shortRun each task with claude -p in its own git worktree, set the permission mode and an allowlist explicitly, deny anything that would prompt, cap the turns, and log the exit code. In the morning, check the exit code and re-run the tests yourself before you read any diff.

To run Claude Code overnight safely, start each task with claude -p in its own git worktree, pass an explicit permission mode and a short allowlist, and cap the number of turns. Then treat the morning as the real work: check the exit code, re-run the tests yourself, and only then read the diff.

I run agents most nights. The setup below uses nothing except Claude Code and git. Flags are from the non-interactive mode and CLI reference pages, checked against Claude Code 2.1.296 in October 2026.

What makes an overnight run unsafe?

Three things go wrong when nobody is watching:

  • The agent edits your working copy. You wake up to a half-finished change mixed into whatever you had open.
  • The agent stops on a question. A permission prompt at 23:10 means eight hours of nothing.
  • The agent does more than you meant. It pushes, deletes, installs, or keeps going for 300 turns on a task that needed 20.

Each has a plain fix: a worktree, a run that cannot prompt, and limits.

Step 1: give every task its own worktree

A git worktree is a second checkout of the same repo on its own branch. Claude Code creates one for you with --worktree (or -w). By default it lands in .claude/worktrees/<name>/ on a new branch named worktree-<name>.

echo ".claude/worktrees/" >> .gitignore
claude -p "..." --worktree fix-login-redirect

Two details from the worktrees documentation matter at night:

  • New worktrees branch from the repo's default branch on the remote, not from your local HEAD. Push what the task depends on first, or set worktree.baseRef to "head" in settings.
  • A worktree is a fresh checkout, so gitignored files such as .env are missing. List them in a .worktreeinclude file at the repo root and Claude Code copies them into each new worktree.

If you would rather make worktrees by hand, or you use Codex as well, see Git worktrees for AI coding agents.

Step 2: make the run unable to wait for you

Set the permission mode yourself. The docs say a run where nothing sets a mode takes the built-in starting mode, which can be auto, so pass the one you want. The permission modes page lists them all. For overnight work I use one of two:

ModeWhat runs without askingWhen I use it
acceptEdits plus an allowlistFile edits, common filesystem commands, and the exact commands I listMost nights. I know which commands the task needs.
autoMost actions, each reviewed by a classifier modelTasks where I cannot predict the commands.

Then add --permission-prompts none (Claude Code 2.1.259 or later). Anything that would have prompted is denied, Claude is told nobody can approve it, and the run continues. It also removes the tool Claude uses to ask you a question, so the task cannot sit waiting on one.

Avoid --dangerously-skip-permissions on your own machine. Anthropic's documentation says that mode offers no protection against prompt injection or unintended actions and recommends it only inside a container or VM.

Use deny rules for the things that must never happen. Deny rules block in every mode. In .claude/settings.json:

{
  "permissions": {
    "deny": [
      "Bash(git push *)",
      "Read(./.env)"
    ]
  }
}

Step 3: cap the run

  • --max-turns 60 stops the run with an error when it reaches that many agentic turns. There is no limit by default.
  • --max-budget-usd stops the run once Claude Code's own cost estimate reaches the amount. On a subscription nobody bills you that figure. It still works as a brake.

Step 4: one script, one log line per task

This is the whole thing. caffeinate -i keeps a Mac from idle sleeping while the command runs.

#!/bin/sh
# night.sh NAME "PROMPT": one unattended task in its own worktree
name="$1"; prompt="$2"
logs="$HOME/night-logs"; mkdir -p "$logs"

caffeinate -i claude -p "$prompt" \
  --worktree "$name" \
  --permission-mode acceptEdits \
  --allowedTools "Bash(npm test),Bash(npm test *),Bash(git add *),Bash(git commit *)" \
  --permission-prompts none \
  --max-turns 60 \
  --output-format json > "$logs/$name.json"

echo "$name exit=$?" >> "$logs/summary.txt"

Change the allowlist to your own test and build commands. The trailing * is a prefix match, and the space before it matters.

Queue tasks one after another, so a failure in one does not take the others with it and you can read the results in order:

cd ~/code/app    # the repo; worktrees are created under it
./night.sh fix-login-redirect "Users land on /home after login instead of the page they asked for. Write a failing test in tests/auth, fix it in src/auth/redirect.ts, run npm test, commit on this branch. Do not push."
./night.sh csv-export-dates "..."

Claude Code exits with code 0 on success and a non-zero code when the run fails, so summary.txt tells you which tasks to look at first.

What should you queue overnight?

Queue work that has a check the agent can run and a result you can review in a few minutes:

  • A bug with a reproduction, where the first step is a failing test.
  • Small maintenance: deprecation warnings, a dependency bump with a test suite behind it, a flaky test.
  • A carefully specified change where you have already chosen the approach.

Leave these for daytime: anything that needs credentials or a deploy, schema migrations, and anything you cannot describe in one paragraph. A vague prompt at night costs a morning. Writing the tests before the code helps most here; the workflow is in Tests first with coding agents.

What about usage limits?

On Pro and Max plans Claude Code has a five-hour session limit and a weekly limit, shared with the Claude apps. Claude Code can wait for a reset and continue on its own, but that feature is documented for interactive sessions. For a scripted -p run, plan as if a limit hit ends the run: check the exit code and queue the task again. A smaller model where the task allows it (--model sonnet) and a turn cap help keep the night inside the limit. More in How to make your Claude Code weekly limit last.

What to check in the morning

  1. Exit codes. cat ~/night-logs/summary.txt. Anything non-zero did not finish.
  2. What the agent said. jq -r '.result' ~/night-logs/fix-login-redirect.json.
  3. What it changed. git diff --stat main...worktree-fix-login-redirect. Look for files you did not expect: lockfiles, CI config, test files it was not asked to touch.
  4. Whether the tests pass when you run them. cd .claude/worktrees/fix-login-redirect && npm test; echo "exit $?". Trust this exit code over the summary.
  5. Uncommitted work. git status in the worktree. A run that hit the turn cap often leaves edits behind.

Only then read the diff. How to review AI-written code without reading every line covers that part.

Non-interactive runs do not clean up their worktrees, and Claude Code leaves its lock on each one. When you are done:

git worktree unlock .claude/worktrees/fix-login-redirect
git worktree remove .claude/worktrees/fix-login-redirect
git branch -d worktree-fix-login-redirect

Where Vakr fits

I built Vakr, a Mac app for people who run Claude Code and Codex, because I got tired of maintaining that script. vakr dispatch --tonight "prompt" queues a run for tonight, at a set time, or for when your usage limit allows. Each run gets its own branch and worktree and never touches main. A run that needs an answer shows up in one list, Needs you, and in the morning the review compares what the agent said it ran with the commands and exit codes it actually ran. Vakr is in early access with a waitlist. Everything above works without it.

Questions

Can I use --dangerously-skip-permissions for overnight runs?

Only inside a container or VM. Anthropic's documentation says the mode gives no protection against prompt injection or unintended actions. On your own machine, use acceptEdits with an allowlist or auto mode, plus --permission-prompts none.

Does my Mac have to stay awake?

Yes, for a run on that Mac. Prefix the command with caffeinate -i to prevent idle sleep while it runs. That covers idle sleep only, so leave a laptop open and on power.

Will a scripted run continue after a usage limit resets?

Do not count on it. The wait-and-continue behaviour is documented for interactive sessions. For claude -p, read the exit code and queue the task again.

Can I run several overnight tasks at the same time?

You can, since each has its own worktree. They share one usage limit and you still review them one at a time, so I keep the count to what I can review before lunch.

Why not let the agent work on my main branch?

Because a failed run then leaves your working copy in an unknown state. A branch in a worktree can be deleted without touching anything else.

How Vakr compares with other tools for running agents: One, Orca, T3 Code, Agentbox and Conductor.

Agent work you can merge without reading every line.

Vakr is a Mac app for Claude Code, Codex and about 22 more agents. Free on your own Machines. I’m letting people in a few at a time.