Verbs

agentproto hook

Status: Experimental

agentproto hook inbox [--session <id>] [--event <name>] [--max <n>]

Claude Code hook commands. Today there is one: inbox.

hook inbox

Meant to run as a Claude Code UserPromptSubmit or PostToolUse hook. It reads the session's unread AIP-46 inbox from the daemon (GET /sessions/:id/inbox), prints the oldest items as additionalContext in the hook JSON protocol, then acks exactly the items it printed (POST /sessions/:id/inbox/ack). This is how a Claude Desktop or claude CLI session that the daemon did not spawn (an external session) sees sentinel, session_follow and workflow notifications.

The injected text is wrapped in an <agentproto-inbox untrusted="true"> block that tells the model the items are data, not instructions. An item containing the closing tag has it neutralised, and each item is truncated at 2000 characters.

FlagDefaultDescription
--session <id>$CLAUDE_CODE_SESSION_ID, else the hook payload's session_idSession whose inbox to read.
--event <name>the payload's hook_event_name, else UserPromptSubmitHook event name echoed in the output (UserPromptSubmit | PostToolUse).
--max <n>20Maximum items per invocation (capped at 20), oldest first.

The command never fails the hook: with no daemon, an unknown session, an empty inbox or any error it prints nothing and exits 0.

Example settings.json entry:

{
  "hooks": {
    "UserPromptSubmit": [
      { "hooks": [{ "type": "command", "command": "agentproto hook inbox" }] }
    ]
  }
}

The session must already be registered with the daemon: an MCP connection to /mcp?callerSessionId=<id>&host=claude-desktop registers it on its first authenticated request.

On this page