Claude Code tool.check ceiling and agentId: gate paid Sume tool calls
Claude Code 2.1.290 adds ceiling and agentId to tool.check, so a hook can tell subagents apart. Pair it with Sume's dry_run and max_spend_usd on paid tools.

If you run Claude Code with Sume's MCP tools, you can now write a plugin hook that treats a subagent's paid call differently from the main session's. Version 2.1.290, released October 5, added agentId to the tool.check event of plugin hooks, and added ceiling to the question and verdict a mod's tool.check hook reads, naming the approval an organization requires for a tool. This gives a hook the two facts a spend rule needs: who is asking, and what the policy ceiling is.
What changed in 2.1.290
The changelog also lists 2.1.291, released October 6, as a fix release for cloud sessions and session-end message loss.
agentIdontool.check, so a hook can tell a subagent's permission check from the main session's.ceilingin the question and verdict, naming the approval an organization requires.claude plugin validatenow lists each hook registered at a gating site and whether it has a.catch.
The Sume side of the rule
| Control | Where | Effect |
|---|---|---|
Hook decision on tool.check | Claude Code plugin | Return a verdict on a call using who is calling and the org ceiling |
| OAuth scope | Sume consent page | mcp:read sessions never see paid tools; Write is off by default |
dry_run | Paid tool argument | Preflights cost without spending |
max_spend_usd | Paid tool argument | Enforced only when you pass it |
idempotency_key | Every write or paid call | A retry does not become a second charge |
A sensible policy
Let the main session call read tools freely. For paid or write tools, have the hook require an approval whenever the caller is a subagent, and require that the call carries an idempotency_key and a max_spend_usd. A subagent loop is the usual way a bill grows unnoticed, because nobody watches its individual calls.
The hook cannot replace Sume's own limits. A permission check is a client-side decision, and it only covers sessions that run your plugin. Server-side, an OAuth session without write cannot spend at all, and an Agent Completion needs generation_spend_cap_usd or it fails. Treat the hook as the first fence and the server as the last one.
I have not tested a specific hook implementation here. The changelog gives the event fields, and the exact hook API is in Claude Code's plugin docs.
Sources
More in Developers
- CloudEvents envelope for a Sume run webhook: field mapping
Map Sume's agent.run.terminal webhook to CloudEvents 1.0: request_id to id, event to type, created_at to time, with a runnable Python wrapper.
- Cloudflare Quick Tunnel --allowed-mail: do Sume webhooks get through?
Cloudflare's --allowed-mail gate asks visitors for an email PIN, which a Sume webhook POST cannot answer. Test with an open tunnel plus a signature check.
- AGENTS.md rules for a coding agent that calls Sume over hosted MCP
Six AGENTS.md lines that stop a coding agent double-billing Sume video jobs: idempotency_key, jobs_wait slices, dry_run, plus a CI lint script.
- curl and jq script to test a new Sume image model id in one command
A 6-line shell script that posts one prompt to Sume POST /v1/images for any model id and prints the url, cost and status, to vet a gpt-image-1 replacement fast.
Written by Sume