Claude Code fork subagents keep plan mode: paid Sume tools

Since 2.1.285 a fork subagent runs under its parent's permission mode and cannot exit plan mode. Two more gates still guard paid Sume MCP tools.

4 min readSume
All posts

A fork subagent in Claude Code now stays in the mode its parent session is in. The 2.1.285 changelog says a fork runs under its parent's permission mode and cannot exit plan mode, and it names dontAsk mode as kept too. So a plan-mode session cannot hand a paid Sume call to a fork that runs more freely.

That line is from the Claude Code changelog entry dated September 29, 2026, read 2026-10-01. The permission mode is one gate. Sume has two more on the server, and they apply whichever agent makes the call.

What did the 2.1.285 fix change?

Per the changelog, fork subagents were not keeping the session's plan mode or dontAsk mode. They now do. The same entry says hooks and SDK permission callbacks no longer see a missing or outdated plan on ExitPlanMode when the plan was written in the same response. This post relies only on the fork line.

What other gates sit in front of a paid Sume call?

Three layers apply, and they are independent. The first is the Claude Code permission mode. The second is the OAuth scope: a session with only mcp:read sees read-only tools, and mutating or paid tools return insufficient_scope. The third is the call itself, where idempotency_key is required and dry_run and max_spend_usd are optional.

Gates on a paid Sume MCP call, from the docs and changelog, read 2026-10-01.
GateSet byWhat it does
Permission mode (plan, dontAsk)Claude CodeForks now inherit the parent's mode
mcp:read vs mcp:writeConsent page on the MCP hostRead-only sessions cannot see paid tools
idempotency_key, dry_run, max_spend_usdThe tool callDedup, cost preview, optional cap

Should a research fork get write scope at all?

Only if it has to submit. Sume's default OAuth grant is read-only, and Write is an opt-in toggle on the consent page; there is no mcp:paid scope, so paid submits are governed by wallet and admission. A fork that only lists models, reads jobs or checks balance needs nothing beyond mcp:read. See OAuth and API keys.

How do I preview the cost from a plan-mode session?

Use generation_admission_preview, or the paid tool with dry_run=true, which returns an admission and cost preview without submitting the job. The tools and gates page describes both. Whether a given tool call is allowed in plan mode is Claude Code's rule, not Sume's, so test it in your own session.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume