Claude Code fork subagents keep plan mode: paid Sume tools
Since 2.1.285 a fork subagent runs under its parent's permission mode and cannot exit plan mode. Two more gates still guard paid Sume MCP tools.

A fork subagent in Claude Code now stays in the mode its parent session is in. The 2.1.285 changelog says a fork runs under its parent's permission mode and cannot exit plan mode, and it names dontAsk mode as kept too. So a plan-mode session cannot hand a paid Sume call to a fork that runs more freely.
That line is from the Claude Code changelog entry dated September 29, 2026, read 2026-10-01. The permission mode is one gate. Sume has two more on the server, and they apply whichever agent makes the call.
What did the 2.1.285 fix change?
Per the changelog, fork subagents were not keeping the session's plan mode or dontAsk mode. They now do. The same entry says hooks and SDK permission callbacks no longer see a missing or outdated plan on ExitPlanMode when the plan was written in the same response. This post relies only on the fork line.
What other gates sit in front of a paid Sume call?
Three layers apply, and they are independent. The first is the Claude Code permission mode. The second is the OAuth scope: a session with only mcp:read sees read-only tools, and mutating or paid tools return insufficient_scope. The third is the call itself, where idempotency_key is required and dry_run and max_spend_usd are optional.
| Gate | Set by | What it does |
|---|---|---|
| Permission mode (plan, dontAsk) | Claude Code | Forks now inherit the parent's mode |
mcp:read vs mcp:write | Consent page on the MCP host | Read-only sessions cannot see paid tools |
idempotency_key, dry_run, max_spend_usd | The tool call | Dedup, cost preview, optional cap |
Should a research fork get write scope at all?
Only if it has to submit. Sume's default OAuth grant is read-only, and Write is an opt-in toggle on the consent page; there is no mcp:paid scope, so paid submits are governed by wallet and admission. A fork that only lists models, reads jobs or checks balance needs nothing beyond mcp:read. See OAuth and API keys.
How do I preview the cost from a plan-mode session?
Use generation_admission_preview, or the paid tool with dry_run=true, which returns an admission and cost preview without submitting the job. The tools and gates page describes both. Whether a given tool call is allowed in plan mode is Claude Code's rule, not Sume's, so test it in your own session.
Sources
Related posts
More in Integrations
- Claude Code headless MCP: a failed first connect is now retried
Since 2.1.283, headless Claude Code retries a remote MCP server whose first connect fails transiently. What to check in a CI run that calls Sume.
- MCP tool call ran twice in Claude Code: can Sume bill it twice?
Claude Code 2.1.287 fixed an MCP connector call that could run twice when the server changed protocol version. How Sume's idempotency_key and jobs_list help.
- Claude Code /mcp shows no Authenticate for a server: check the URL
Since 2.1.283, /mcp no longer offers Authenticate for a server with no valid URL. Re-add Sume as an http server at https://mcp.sume.com/mcp and sign in.
- Claude Code MCP sign-in link stopped working: use the newest one
A repeat MCP sign-in request replaces the pending link in Claude Code, so the older link can stop working. Finish the newest Sume sign-in link only.
Written by Sume