Claude Code CLI Workflow & Multi-File Refactoring Guide
Anthropic's Claude Code is an agentic coding tool that can inspect a workspace, propose or apply edits, and run approved commands. Its models, commands, permissions, and account availability change over time, so this guide focuses on a durable review workflow and links to the current official documentation instead of hard-coding an unverified model name.
1. Installation & Initial Configuration
Install Claude Code globally via NPM or Homebrew, then authenticate with your Anthropic Console API key or Claude Pro account:
# Install Claude Code CLI
npm install -g @anthropic-ai/claude-code
# Launch interactive CLI inside your repository
cd /path/to/reviewed-project
claude
Verify the current installation path and authentication options in Anthropic's setup documentation. Use a clean test repository first. Do not launch an agent in a home directory, secrets folder, production checkout, or workspace containing unrelated private files.
2. Architectural Deep-Dive: How Claude Code Operates
From an operator's perspective, the important behavior is a repeated observe–propose–validate–execute loop. The exact internal implementation is vendor-controlled and should not be inferred from a UI:
Execution Cycle:
- Inspect: Reads selected project context and current repository state.
- Propose: Describes a plan, edit, or tool action based on the task.
- Authorize: Permission rules and the operator decide whether a requested action may run.
- Execute: The tool edits or runs a command within the available environment.
- Verify: Tests and diff review provide evidence; model confidence is not proof.
3. Advanced Multi-File Refactoring Example
Suppose you need to migrate your Node.js Express authentication middleware from legacy session cookies to JWT tokens across 8 controller files. Simply issue a multi-step instruction:
> Refactor src/middleware/auth.js to validate Bearer JWT tokens instead of session cookies.
> Update all controller handlers in src/controllers/*.js to extract user object from req.user.
> Run npm test after editing to ensure zero test failures.
4. Refactoring Workflow with Review Gates
- Start from a clean branch and record the initial commit.
- Ask the agent to inspect and propose a plan before editing.
- Constrain files, behavior, compatibility requirements, and commands that may run.
- Request the smallest coherent change and inspect the diff immediately.
- Run focused tests, then broader regression checks, linting, and type checks.
- Review dependencies, generated files, secrets, permissions, and user-visible behavior.
- Commit only the verified scope; keep deployment and publication as separate approved actions.
5. Permissions and Prompt-Injection Boundaries
Repository instructions, issues, logs, web pages, packages, and MCP results are untrusted inputs. Review project configuration before trusting a repository. Grant the narrowest filesystem and command access, avoid skip-permission modes for ordinary work, and require fresh approval for network access, installs, credential use, deletion, push, deployment, and external communication.
MCP expands the tool surface. Verify each server's publisher, code, startup command, scopes, data flow, and uninstall path. A connected database or ticket system still needs server-side authorization; the model must not decide which tenant or record a user may access.
6. Cost and Context Discipline
- Narrow the task: provide acceptance criteria and relevant paths instead of asking for a repository-wide improvement.
- Prefer targeted search: read symbols and files needed for the next decision rather than repeatedly sending the full tree.
- Stop failed loops: after repeated equivalent errors, inspect the environment or ask for help.
- Measure usage: compare accepted changes, model calls, tool calls, elapsed time, and subscription or API cost.
- Confirm current features: caching, effort controls, and quotas depend on product and model documentation.
7. Integration with Model Context Protocol (MCP)
Claude Code supports custom MCP servers, allowing you to connect local PostgreSQL databases, Redis caches, and GitHub PR workflows directly to the CLI interface. Read our complete MCP Setup Guide for server configurations.
8. Evaluation Checklist
- The requested behavior changes and specified tests pass.
- No unrelated file, dependency, permission, or workflow change appears.
- Commands and external access match the approved plan.
- Failure, cancellation, and stale-state cases stop safely.
- The operator can explain and revert every changed line.
- Model, tool version, configuration, test command, and final commit are recorded.
9. Primary References
What a refactoring session costs
Multi-file refactoring is the most cache-dependent workflow in this guide, because the agent re-reads the same repository state dozens of times within one session. Below: one session at 150K input, 100K cached, 12K output. Of the 150,000 input tokens, 100,000 are billed at the cache-read rate and 50,000 at full input rate.
| Model | Cost per session | Monthly at 600 sessions |
|---|---|---|
| Claude Sonnet 5 | $0.240 | $144 |
| GPT-5.6 Sol | $0.480 | $288 |
| Claude Fable 5.1 | $1.12 | $675 |
Two thirds of the input is cached, so the flagship models cost far less here than their list prices suggest. The practical consequence: keeping a session open and continuing is materially cheaper than restarting it, because a restart cold-loads the prefix at full input price.
Rates verified against provider documentation on September 18, 2026. Promotional rates expire, so re-check before budgeting: LLM API cost planning · September 2026 pricing update. Run your own numbers in the cost calculator.