Claude Code mcp_tool hook on PreToolUse for a spend check
Claude Code 2.1.282 makes mcp_tool hooks on blocking events wait for their MCP server. With Sume, the check to run there is a dry_run cost preview.

An mcp_tool hook runs an MCP tool as a Claude Code hook. As of Claude Code 2.1.282, such a hook on a blocking event like PreToolUse waits for its MCP server to connect instead of being skipped. For a spend check against Sume, the tool worth wiring there is a cost preview: generation_admission_preview, or the paid tool itself with dry_run=true.
What changed in 2.1.282?
The changelog says mcp_tool hooks on blocking events (PreToolUse and similar) were being skipped while their MCP server was still connecting, and that they now wait for it, up to the MCP connect timeout. Before the fix, a guard hook could silently not run at session start, which is the worst failure for a spending check.
Which Sume calls preview cost without spending?
Sume's gates table describes dry_run=true as an admission and cost preview only, with the job not submitted. The docs also say to prefer generation_admission_preview and/or dry_run before expensive bursts, and that ordinary single creates do not need admission theater.
| Gate | Required? | Meaning |
|---|---|---|
| idempotency_key | Required on write and paid tools | Stable key for transport and dedup, not human approval |
| dry_run=true | Optional | Admission and cost preview only; the job is not submitted |
| max_spend_usd | Optional | Enforced only when provided |
Why not rely on idempotency_key as the approval?
Because the docs say it is not human approval. It only dedups a submit. A hook that previews cost and lets a person decide supplies the approval step the gate does not. If you also want a hard ceiling, max_spend_usd caps spend, but only when you pass it.
Does the hook need a write session?
Paid tools are hidden until the session has mcp:write or an API key, per the tools and gates page. A read-only OAuth session cannot see generate_image to preview it, so grant Write at consent or use an API key before building the hook around a paid tool. generation_admission_preview is listed under account and catalog tools.
What should the hook do with the preview?
Have the hook call the preview, show the estimate to the person, and only allow the real tool call after a yes. The playbook in Sume's docs is written the same way: review the preview first, then repeat the call without dry_run to submit, and only when the user explicitly confirms spend.
Keep the real call's idempotency_key stable between the preview and the submit, since the docs describe it as a key for transport and dedup. After the submit, poll with jobs_status or jobs_wait and read jobs_result, as the playbook lists.
Sources
Related posts
More in Developers
- Claude Code "No such tool available" on a resumed MCP session
After resuming a Claude Code session, a first MCP call could fail with No such tool available. Claude Code 2.1.284 waits up to 10 seconds. The Sume side.
- OTEL_LOG_TOOL_CONTENT with MCP tool output: what Sume logs could leak
Claude Code 2.1.283 can put MCP tool output on an OTEL span when OTEL_LOG_TOOL_CONTENT=1. With Sume, check that output for signed URLs and keys first.
- Claude Code MCP server connected twice: duplicate connector fix
Claude Code 2.1.281 stopped connecting one MCP server twice when a plugin or connector spells its URL differently. What it means for Sume's single MCP URL.
- Claude Code subagent MCP server: scope Sume tools to one
Put a Sume MCP server in one subagent's mcpServers field so video and image tools stay out of the main chat. Frontmatter for both routes, plus limits.
Written by Sume