Admit model switches like privilege changes
Use
when:
a
Claude
Code
session
may
change
models
through
/model,
Remote
Control,
an
SDK
host,
fast
mode,
automatic
fallback,
or
resume,
especially
when
cache
loss
or
model
policy
matters.
2.1.251
or
later,
add
a
managed
PreModelSwitch
command
hook
matching
.*.
Read
from_model,
to_model,
source,
context_tokens,
and
estimated_cache_write_usd;
return
deny
for
forbidden
targets,
ask
above
your
re-cache
threshold,
and
allow
otherwise.
Add
PostModelSwitch
to
write
a
receipt
and
return
target-specific
additionalContext.
In
-p
and
SDK
runs,
ask
becomes
refusal.Acceptance check: switch from Sonnet to an allowed model; one pre-hook receipt must contain both model IDs, source, token estimate, and decision. A forbidden target must leave Sonnet active. Trigger an automatic fallback and resume restoration; both must emit post-hook receipts, and only the final target’s guidance may enter the next request.
2.1.251
release
introduces
both
events.
The
current
hook
reference
specifies
canonical
matching,
a
fail-closed
pre-hook
timeout,
decision
precedence,
cost
fields,
and
automatic-switch
post
events.
Issue
#89209
records
a
prior
transcript
where
Opus
served
the
turn
while
the
model
claimed
Fable.
Caveat:
PreModelSwitch
cannot
intercept
automatic
fallback
or
resume,
and
PostModelSwitch
cannot
undo
them.
Command
hooks
execute
with
user
authority;
keep
policy
in
managed
scope
and
test
it.