{
  "id": 12856261,
  "title": "Claude Code Agent Loop Deep Dive (1): From Tool Declarations to Pre-Execution Approval",
  "url": "https://urgent.news/2026/10/08/claude-code-agent-loop-deep-dive-1-from-tool-declarations-to-pre",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-08T11:31:21.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/_94be737e156beb4d74df2/claude-code-agent-loop-deep-dive-1-from-tool-declarations-to-pre-execution-approval-397e"
  },
  "original_language": "en",
  "account": "The article delves into the inner workings of an agent loop, specifically how the LLM determines which tools it can call and what happens after requesting a tool.\n\nA complete Messages API request contains three sections: system prompt, available tools, and conversation history. The model only calls tools listed in the tools array during training. The tools section is essentially the LLM's tool menu.\n\nWhen the LLM receives a tool request, it may not execute the tool immediately. Instead, it can present an approval prompt, especially for potentially destructive actions. This is the only exception to the rule that the user is absent during most of the loop.\n\nThe loop includes mechanisms for permission approval, interruption, and iteration limits. Claude Code uses several sources of approval rules, prioritizing them based on their importance. These sources include abortController, denyRule, askRule, and defaultMode.\n\nWhen no automatic rule can decide, the control flow involves presenting an approval dialog to the user. The user's deliberation time does not add API cost as the loop awaits a Promise. Three approval sources can also race together: user interface, PermissionRequest hook, and an AI classifier. The first result is authoritative and decisive.",
  "summary": "In the opening article , I introduced the five-line skeleton of an agent loop: call the LLM, check for tool_use , execute requested tools, and stop when there is no tool call. This article examines the first question inside every iteration: how does the LLM know which tools it can call, and what still happens after it asks to call one? More concretely: Why does an LLM know that Read exists in the…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}