cd /news/ai-agents/pretooluse-or-posttooluse-where-to-p… · home › topics › ai-agents › article
[ARTICLE · art-145728] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=· neutral

PreToolUse or PostToolUse? Where to Put a Check in the Claude Agent SDK

A developer explains that in the Claude Agent SDK, checks that must prevent a side effect belong in the PreToolUse hook, since PostToolUse runs after the tool executes and cannot undo it. The writeup notes that async hooks cannot gate actions, that returning 'ask' alone does not create an approval screen, and that the tool service must still repeat authorization and business validation with an idempotency key.

by read2 min views1 publishedOct 5, 2026

If an agent can trigger a business action, the most important design question is where each check runs. In the Claude Agent SDK, hooks give you two points around every tool call. Only one of them can stop the action. A check that must prevent a side effect belongs in PreToolUse. It runs before the tool executes and returns a decision. PostToolUse runs after execution. It can add context, replace the result the agent sees, or record an event, but it cannot undo what the tool already did.

Decision Use it when What happens
deny Required data is missing or a business rule fails The tool does not run. Return a reason the agent and the operator can act on
ask The request is valid but needs a person's approval Your approval handler ( canUseTool in TypeScript,can_use_tool in Python) gets the decision. Returningask alone does not create an approval screen
allow The request meets the hook's policy The call continues to the tool service

A PreToolUse hook can also return changed input. Use that sparingly and log it, because the tool then runs something the agent did not ask for.

Async hooks cannot gate. A callback that returns async: true (async_: True in Python) cannot block the tool or change its input. A hook that gates an action must return its decision before execution.

The hook is not the last line. The hook does not own the business record. The tool service must repeat authorization and business validation, and use an idempotency key so a retry cannot create a duplicate. Passing the hook shows the request looked acceptable, not that the action is correct.

The event names overlap, but the owners differ. Agent SDK hooks are registered by the application running the agent, through ClaudeAgentOptions in Python or the SDK options in TypeScript. Claude Code hooks are configured in the Claude Code environment. Exam questions and real incidents both turn on this difference.

Review the blocked paths as carefully as the successful one.

── more in #ai-agents 4 stories · sorted by recency
── more on @claude agent sdk 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/pretooluse-or-postto…] indexed:0 read:2min 2026-10-05 · —