Hi @Stanislav_Kostomakha Those afterAgentResponse / stop token counts are the parent agent’s turn only. They do not include tokens used by subagents.
Subagent model calls are billed and reported as their own requests. subagentStop can tell you that a subagent ran (subagent_id, subagent_type, model, duration_ms, message_count, tool_call_count), but it does not currently include token fields. I would not use it as a spend signal.
For the case you described (flag a single request that burned a lot of tokens, then tighten rules or skills), the Admin API usage events endpoint is the better source if you need parent plus subagent usage together. Each event has the model, inputTokens, outputTokens, cacheWriteTokens, cacheReadTokens, and a conversationId. Sum the events that share that conversation ID to get the full cost of the user turn.
If a parent-only threshold is enough, afterAgentResponse is still the simplest hook. Just treat those numbers as parent-only, so a cheap parent with expensive subagents does not slip through.