Claude Code tool.check ceiling and agentId: gate paid Sume tool calls

Claude Code 2.1.290 adds ceiling and agentId to tool.check, so a hook can tell subagents apart. Pair it with Sume's dry_run and max_spend_usd on paid tools.

4 min readSume
All posts

If you run Claude Code with Sume's MCP tools, you can now write a plugin hook that treats a subagent's paid call differently from the main session's. Version 2.1.290, released October 5, added agentId to the tool.check event of plugin hooks, and added ceiling to the question and verdict a mod's tool.check hook reads, naming the approval an organization requires for a tool. This gives a hook the two facts a spend rule needs: who is asking, and what the policy ceiling is.

What changed in 2.1.290

The changelog also lists 2.1.291, released October 6, as a fix release for cloud sessions and session-end message loss.

  • agentId on tool.check, so a hook can tell a subagent's permission check from the main session's.
  • ceiling in the question and verdict, naming the approval an organization requires.
  • claude plugin validate now lists each hook registered at a gating site and whether it has a .catch.

The Sume side of the rule

Controls to combine at a paid Sume tool call (read 2026-10-06)
ControlWhereEffect
Hook decision on tool.checkClaude Code pluginReturn a verdict on a call using who is calling and the org ceiling
OAuth scopeSume consent pagemcp:read sessions never see paid tools; Write is off by default
dry_runPaid tool argumentPreflights cost without spending
max_spend_usdPaid tool argumentEnforced only when you pass it
idempotency_keyEvery write or paid callA retry does not become a second charge

A sensible policy

Let the main session call read tools freely. For paid or write tools, have the hook require an approval whenever the caller is a subagent, and require that the call carries an idempotency_key and a max_spend_usd. A subagent loop is the usual way a bill grows unnoticed, because nobody watches its individual calls.

The hook cannot replace Sume's own limits. A permission check is a client-side decision, and it only covers sessions that run your plugin. Server-side, an OAuth session without write cannot spend at all, and an Agent Completion needs generation_spend_cap_usd or it fails. Treat the hook as the first fence and the server as the last one.

I have not tested a specific hook implementation here. The changelog gives the event fields, and the exact hook API is in Claude Code's plugin docs.

Sources

More in Developers

All Developers posts

Written by Sume