---
title: The stdin payload, per event — Claude Code's fields
at: 2026-09-18T09:58:31+00:00
source: the agent
track: main
---
Every event carries: `session_id` (a UUIDv7), `transcript_path` (the rollout file, e.g. ~/.codex/sessions/2026/09/18/rollout-2026-09-18T11-56-48-<session_id>.jsonl — its stem is NOT the session id, it is rollout-<time>-<id>), `cwd`, `hook_event_name`, `model` ("gpt-5.5"), `permission_mode` ("bypassPermissions" under exec with the sandbox flag; also default, acceptEdits, plan, dontAsk). Turn-scoped events add `turn_id`.

    SessionStart      + source: "startup"
    UserPromptSubmit  + prompt
    PreToolUse        + tool_name: "Bash", tool_input: {"command": "echo forbidden > probe.txt"}, tool_use_id: "call_…"
    PostToolUse       + tool_name, tool_input, tool_response (a string; "" for a command with no output), tool_use_id
    Stop              + stop_hook_active: false|true, last_assistant_message: "done"

No environment variables named CODEX reach the hook, and it gets no argv. Measured payloads (session_id and paths shortened):

    {"session_id":"01a0b3f2-…","transcript_path":"…/rollout-2026-09-18T11-56-48-01a0b3f2-….jsonl","cwd":"…/codexprobe","hook_event_name":"SessionStart","model":"gpt-5.5","permission_mode":"bypassPermissions","source":"startup"}
    {"session_id":"…","turn_id":"01a0b3f2-7dd5-…","transcript_path":"…","cwd":"…","hook_event_name":"PreToolUse","model":"gpt-5.5","permission_mode":"bypassPermissions","tool_name":"Bash","tool_input":{"command":"echo forbidden > probe.txt"},"tool_use_id":"call_dZLGeT6WMHgYEXkn3tUsZuve"}
    {"session_id":"…","turn_id":"…","transcript_path":"…","cwd":"…","hook_event_name":"Stop","model":"gpt-5.5","permission_mode":"bypassPermissions","stop_hook_active":false,"last_assistant_message":"done"}

The shell tool is named `Bash` with `tool_input.command`, exactly as in Claude Code, so hook.py's `_is_write`, `_pieces` and the journal-verb detection read a Codex call unchanged.
