Concepts
Permission bits
How a v4 hook address encodes which callbacks the PoolManager will call.
Uniswap v4 reads a hook's permissions from the lowest 14 bits of its address. If bit 7 is set, the PoolManager calls beforeSwap; if it is clear, it never does, whatever the code says. This makes permissions checkable by anyone in one step: take the address, mask the low 14 bits.
permissions = uint160(hookAddress) & 0x3FFF
beforeSwap enabled <=> permissions & (1 << 7) != 0The delta flags matter most
Four flags let a hook change token amounts instead of only observing them: beforeSwapReturnDelta, afterSwapReturnDelta, afterAddLiquidityReturnDelta, afterRemoveLiquidityReturnDelta. A hook with these can take a share of what you pay or receive. That is how burns, taxes and streams work, and it is also how a malicious hook would steal. Read every rule that uses them.
Consistency
A delta flag without its base callback is invalid: afterSwapReturnDelta is meaningless without afterSwap. The composer and scanner both flag this.
The full list is in hook permissions.