# Agno > Open-source Python framework from Agno Inc. for building agents, teams and workflows, with the AgentOS runtime that serves them over a REST API and an MCP server. Formerly Phidata. - Canonical: https://www.anchorterminal.com/tools/agno - Markdown: https://www.anchorterminal.com/tools/agno.md (~6,000 tokens) - Slim: https://www.anchorterminal.com/tools/agno.min.md (~1,430 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/agno.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade BB · 72.8/100 · rank #85 of 722 · #7 in Agent frameworks & SDKs · agent-ready · confidence medium** ## Assessment An Apache 2.0 Python agent framework at 3.1.1 with an MCP client, tool confirmation and admin approvals, a durable job queue and 25 stable releases in 90 days. Usage telemetry is on by default with unhashed identifiers, and three high or critical advisories were published against it in the last 12 months, all fixed. ## Facts | Field | Value | | --- | --- | | Vendor | Agno Inc. (https://www.agno.com) | | Kind | Agent framework | | Category | Agent frameworks & SDKs (https://www.anchorterminal.com/categories/frameworks) | | Auth | API key · The framework has no account of its own. Each model provider takes its own key from the environment. AgentOS, the server you run, accepts JWTs, a shared OS_SECURITY_KEY or service-account tokens, and takes no credential when none is configured. The hosted control plane at os.agno.com needs a sign-in. | | Pricing | Free (Free · OSS) · The SDK and AgentOS are free under Apache 2.0, and you pay your model provider. The optional hosted control plane is free for a local AgentOS and $150 a month (Pro) for a live deployment, with Enterprise by quote (https://www.agno.com/pricing, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the library source or on the pricing page. The only match in the repository is a cookbook example that calls a third-party x402 MCP server (checked 2026-10-08). | | Licence | Apache-2.0 | | Packages | pypi: `agno` | | Source | https://github.com/agno-agi/agno | | Docs | https://docs.agno.com | | llms.txt | https://docs.agno.com/llms.txt | | Last release | 2026-10-02 | | GitHub stars | 42,612 (as of 2026-10-08) | | PyPI downloads / week | 475,559 | | Languages | Python 3.9 or later | | Version | 3.1.1 on 2 October 2026. 3.0.0 on 24 August 2026 | | Models | Provider modules for OpenAI, Anthropic, Google and others under agno.models (about 60 entries in the source directory) | | MCP client | MCPTools in the agno[mcp] extra. Streamable HTTP and stdio, with SSE marked deprecated. Tool filters, name prefix and dynamic headers | | MCP server | AgentOS with `mcp=True` serves /mcp over Streamable HTTP beside the REST API | | Multi-agent | Team, with a leader that delegates to member agents, and Workflow for sequential, parallel, conditional and looping steps | | Durable state | Sessions and runs stored in your database. AgentOS background runs survive restarts with QueueConfig(durable=True), off by default | | Human approval | requires_confirmation, user input, external execution and admin approvals with stored records, on agents, teams and workflow steps | | Guardrails | PII patterns, literal prompt-injection phrases and OpenAI moderation, as pre-hooks on the run input | | Tracing | OpenTelemetry, stored in your database or exported | | Telemetry | On by default. One event per run to os-api.agno.com with model, feature flags and unhashed identifiers. Off with AGNO_TELEMETRY=false or telemetry=False | | Hosted control plane | os.agno.com. Free for a local AgentOS, Pro $150 a month for one live connection and three seats | | Releases in 90 days | 25 stable and 5 pre-releases on PyPI | | Capabilities | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | | Tags | framework, python, open-source, llms-txt, mcp, otel, free | | JSON | https://www.anchorterminal.com/api/v1/tools/agno.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 83 | 16.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 90 | 14.6 | | Agent ergonomics | 13% | 16.2 | 76 | 12.3 | | Security & auth | 14% | 17.5 | 64 | 11.2 | | Payments & pricing | 10% | 12.5 | 50 | 6.2 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 86 | 7.5 | | Transparency & trust (editorial 73, provenance 93) | 7% | 8.8 | 83 | 7.3 | | Negative events | up to −15 | up to −15 | 2026-06-30. GHSA-m4w4-3r8h-jw98 (CVE-2026-35002, critical), arbitrary code execution through eval() on field_type in a FunctionCall, fixed in 2.3.24. GHSA-w9j5-7p53-pvr3 (CVE-2026-10105, high, published 2026-07-27), SQL injection in the ClickHouse vector store's delete_by_metadata, parameterised in the current source. GHSA-vw84-hprm-cxmm (CVE-2025-64168, high, 2025-10-31), session state written to the wrong session under concurrency, fixed in 2.2.2. All three are fixed and published as advisories in the repository, so 1 point each. https://github.com/agno-agi/agno/security/advisories | -3 | | **Total** | | | | **72.8 → BB** | ### Why each score - Reliability 83: Official PyPI package with Python 3.9 or later stated (20). Public CI runs Ruff, mypy and the unit tests in five groups, and of the 12 latest runs on main, 10 passed and 2 were cancelled (25). 867 open issues, 171 of them labelled bug and 227 older than six months, with 287 opened and 105 closed in the 30 days to 8 October. Recent bug reports mostly have one to three comments (12). Majors 2.0 and 3.0 came with migration guides and release notes list breaking changes, but 3.1.0, a minor, shipped a breaking filesystem table re-key (11). Version 3.1.1 with the Production/Stable classifier (15). Local-software reading. - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 90: A class reference under docs.agno.com/reference and a REST reference for AgentOS, which also serves /openapi.json (25). llms.txt with 3,963 lines, llms-full.txt, a Markdown twin of each page and a docs MCP server (10). Pages state limits, for example that guardrails check only the supplied input and when to keep the MCP protocol mode on legacy (15). Pydantic-typed classes and tool signatures, with a py.typed marker (13). Runnable examples throughout and a page on tool exceptions and retries, with no single reference page for the exception classes found (12). Dated changelog and release notes per version (15). Framework reading. - Agent ergonomics 76: An agent with an MCP server is about ten lines through MCPTools, with include_tools, exclude_tools and tool_name_prefix (22). tool_call_limit exists but defaults to None, and sessions, history and compression are configurable (14). A typed exception hierarchy, with RetryAgentRun and StopAgentRun to steer the loop from a tool (16). Runs continue by run ID after a pause and AgentOS has a durable queue, which is off by default (16). Few required parameters, Python only (8). - Security & auth 64: Telemetry is on by default. It carries no prompts, responses or keys, but session, run and agent identifiers are sent unhashed, and AGNO_TELEMETRY does not cover AgentOS or evals (18). Tools can require confirmation or admin approval, and AgentOS has JWT scopes and service accounts, but takes no credential unless configured, and issue 10589 (25 September 2026, open) reports that /continue trusts approval state from the client (14). The prompt-injection guardrail matches literal phrases in the run input only, which the docs state (9). OpenTelemetry tracing, run history and an audit log in the 3.1 authorisation package (13). A valid security.txt pointing to GitHub advisories and three advisories published in the repository. No SECURITY.md, no bounty found, and the trust centre could not be read (10). Framework reading. - Payments & pricing 50: No payment protocol (0). Self-hosted rule, with the paid option scored. The control plane has public plan prices, Free at $0 and Pro at $150 a month, with Enterprise by quote (10). The package installs with no card (20) and runs with no Agno account (20). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 86: 3.1.1 on 2 October 2026 (30). 25 stable releases and 5 pre-releases on PyPI in the 90 days to 8 October (20). Bug reports are usually answered within days, but 867 issues and 968 pull requests are open, and issues were opened nearly three times as fast as they were closed in the last 30 days (14). The Python package is current (15). CI runs lint, types and tests with pinned development tools. No Dependabot configuration file is in the repository (7). - Transparency & trust 83: Apache 2.0 (30). The telemetry page lists the fields sent and says identifiers are not hashed, and the pricing page says the control plane holds no copy of customer data. The terms and privacy pages render only with JavaScript and were not read, and no retention period for telemetry was found (15). Migration guides for 2.0 and 3.0 and migration notices on what was removed, with no written deprecation policy found (10). Telemetry is disclosed in the README and docs with an opt-out, though the environment variable does not cover AgentOS or evals (18). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/agno.md (JSON https://www.anchorterminal.com/fixes/agno.json) ### What we couldn't check - unchecked: the terms of service and privacy policy at os.agno.com/legal/tos and /legal/privacy. Both pages render only with JavaScript and their text was not read - unchecked: trust.agno.com, which returned only a heading without JavaScript, so any SOC 2 or ISO 27001 status is unknown - Whether the control plane's free plan asks for a card. The pricing page does not say - How long telemetry events are kept. The telemetry page gives no retention period - OSV dates the eval injection and SQL injection records 2026-04-02 and 2026-05-29, earlier than the repository advisories of 2026-06-30 and 2026-07-27. The first was reported through VulnCheck - Whether issue 10589 (approval state trusted from the client in /continue) is confirmed by the maintainers. It was open with two comments on 8 October 2026 - The lead held (Python SDK, AgentOS with REST and MCP, formerly Phidata). The category was kept as frameworks ### Sources - repository clone at b532715 (README, licence, pyproject, workflows, telemetry, guardrails and exceptions source): (seen 2026-10-08) - PyPI document for agno (versions, dates, Python requirement): (seen 2026-10-08) - PyPI download counts: (seen 2026-10-08) - GitHub API, repository statistics: (seen 2026-10-08) - GitHub API, CI runs on main: (seen 2026-10-08) - GitHub search API, open and closed issue and pull request counts: (seen 2026-10-08) - GitHub API, repository security advisories: (seen 2026-10-08) - OSV records for agno on PyPI: (seen 2026-10-08) - release notes for 3.1.1, 3.1.0 and 3.0.11: (seen 2026-10-08) - issue 10589 on approval state in /continue: (seen 2026-10-08) - docs index: (seen 2026-10-08) - telemetry page: (seen 2026-10-08) - MCP client page: (seen 2026-10-08) - AgentOS as MCP server: (seen 2026-10-08) - AgentOS security and authentication modes: (seen 2026-10-08) - human approval: (seen 2026-10-08) - guardrails: (seen 2026-10-08) - tool exceptions and retries: (seen 2026-10-08) - 3.0 changelog: (seen 2026-10-08) - pricing: (seen 2026-10-08) - vendor changelog: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - status page and its incident feed: (seen 2026-10-08) - RDAP for agno.com: (seen 2026-10-08) ## Who's behind it (provenance 93/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Agno Inc. | 20/20 | | Domain age | agno.com, registered 2003-04-13 (23 years) | 15/15 | | Endpoint on the vendor's domain | no hosted endpoint | n/a | | Terms of service | published, but our reader couldn't read it | 7/10 | | Privacy policy | published, but our reader couldn't read it | 7/10 | | Status page | status.agno.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The licence file reads Copyright 2025-2026 Agno Inc. and the site footer reads © 2026 Agno Inc. www.agno.com/.well-known/security.txt gives https://github.com/agno-agi/agno/security as the contact and expires 2027-08-10. The terms and privacy links in the www.agno.com footer go to os.agno.com/legal/tos and /legal/privacy. Both return 200 but render only with JavaScript, so their text was not read. They cover the hosted control plane. The SDK itself is under Apache 2.0. status.agno.com lists Website and AgentOS components, which are the vendor's hosted services, not the library. RDAP gives agno.com a registration date of 2003-04-13. github.com/phidatahq/phidata redirects to agno-agi/agno. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://os.agno.com/legal/tos), read 2026-10-08. Our reader couldn't read it (the page has 0 words of text without a browser, so the document is drawn by script or sits elsewhere). **Privacy policy** (https://os.agno.com/legal/privacy), read 2026-10-08. Our reader couldn't read it (the page has 0 words of text without a browser, so the document is drawn by script or sits elsewhere). ## Live (updated 2026-10-08 20:22 UTC) - Vendor status page: none, All Systems Operational - Watching changelog - Watching pricing - Watching privacy - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/agno.json ## Probe metrics A library has no endpoint to probe. Reliability is assessed from its tests, release history and issue tracker; performance waits for the task suite run through it. See https://www.anchorterminal.com/benchmark/#kinds ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Control plane Pro plan, one live AgentOS connection and three seats | $150 | per month (plan) | | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Apache 2.0, with 25 stable releases on PyPI in the 90 days to 8 October 2026 and 3.1.1 on 2 October - MCP client (MCPTools) over Streamable HTTP and stdio with include_tools, exclude_tools and a name prefix - Tool calls can require confirmation, user input or an admin approval that is stored and audited - llms.txt, llms-full.txt, a Markdown twin of every docs page and a docs MCP server at docs.agno.com/mcp - Unit tests, Ruff and mypy run in public CI, and 10 of the 12 latest runs on main passed with 2 cancelled ## Weaknesses - Usage telemetry is on by default and sends session, run and agent identifiers unhashed. Prompts and outputs are not sent - AGNO_TELEMETRY=false does not cover AgentOS launches or evals, which need telemetry=False on the instance - Three advisories in 12 months, an eval injection rated critical, a ClickHouse SQL injection and a session state leak, all fixed - 867 open issues and 968 open pull requests on 8 October 2026, with 287 issues opened and 105 closed in 30 days - AgentOS requires no credential unless a JWT key or OS_SECURITY_KEY is configured - Terms and privacy pages at os.agno.com render only with JavaScript and could not be read ## Before you call it (notes for agents) 1. Set AGNO_TELEMETRY=false before the first run, and pass telemetry=False to AgentOS and to each eval, which ignore the variable 2. Configure JWT_VERIFICATION_KEY with AgentOS authorisation switched on, or OS_SECURITY_KEY, before exposing AgentOS. With neither set, REST and MCP routes take no credential 3. Mark tools that write with requires_confirmation, and resume with continue_run once every requirement is resolved 4. Set tool_call_limit on agents. The default is None 5. Install extras for what you use, such as agno[mcp] for MCPTools and agno[os,mcp] for AgentOS with its MCP server ## Get started Install: ```bash pip install -U agno # MCP client: pip install -U "agno[mcp]" ``` ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | OpenAI Agents SDK | AA | 86.2 | 1 | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | no | https://www.anchorterminal.com/tools/openai-agents-sdk.md | | Pydantic AI | A | 83.7 | 3 | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | no | https://www.anchorterminal.com/tools/pydantic-ai.md | | Microsoft Agent Framework | A | 82.2 | 6 | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | no | https://www.anchorterminal.com/tools/microsoft-agent-framework.md | | Docker Agent | BB | 76.5 | 30 | agent.framework, agent.multi-agent, agent.mcp-client, agent.durable | no | https://www.anchorterminal.com/tools/docker-agent.md | | Agent Development Kit (ADK) | BB | 74.7 | 58 | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | no | https://www.anchorterminal.com/tools/google-adk.md | | LangGraph | BB | 70.6 | 131 | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | no | https://www.anchorterminal.com/tools/langgraph.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - agno 3.1.1 on PyPI on 2026-10-02, with 25 stable releases and 5 pre-releases in the 90 days to 8 October 2026. 3.0.0 shipped on 2026-08-24 (source: ) - Telemetry is on by default and sends one event per run with model, feature flags and unhashed session, run and agent identifiers. AGNO_TELEMETRY=false does not cover AgentOS or evals (source: ) - AgentOS runs with no central credential unless a JWT key or OS_SECURITY_KEY is configured (source: ) - Three advisories in the repository, GHSA-m4w4-3r8h-jw98 (critical, 2026-06-30), GHSA-w9j5-7p53-pvr3 (high, 2026-07-27) and GHSA-vw84-hprm-cxmm (high, 2025-10-31), all fixed (source: ) - 3.1.0 on 2026-10-01 added role-based access control and an audit log to AgentOS, and its release notes list a breaking filesystem table re-key (source: ) - github.com/phidatahq/phidata redirects to agno-agi/agno, and the phidata package remains on PyPI at 2.7.10 (source: ) ## Compare - [AgentOS vs Agno](https://www.anchorterminal.com/compare/agentos-vs-agno.md): BB 75.3 vs BB 72.8 - [Agno vs Claude Agent SDK](https://www.anchorterminal.com/compare/agno-vs-claude-agent-sdk.md): BB 72.8 vs BB 72.1 - [Agno vs CrewAI](https://www.anchorterminal.com/compare/agno-vs-crewai.md): BB 72.8 vs B 67 - [Agno vs Docker Agent](https://www.anchorterminal.com/compare/agno-vs-docker-agent.md): BB 72.8 vs BB 76.5 - [Agno vs Agent Development Kit (ADK)](https://www.anchorterminal.com/compare/agno-vs-google-adk.md): BB 72.8 vs BB 74.7 - [Agno vs LangGraph](https://www.anchorterminal.com/compare/agno-vs-langgraph.md): BB 72.8 vs BB 70.6 - [Agno vs Microsoft Agent Framework](https://www.anchorterminal.com/compare/agno-vs-microsoft-agent-framework.md): BB 72.8 vs A 82.2 - [Agno vs OpenAI Agents SDK](https://www.anchorterminal.com/compare/agno-vs-openai-agents-sdk.md): BB 72.8 vs AA 86.2 - [Agno vs Pydantic AI](https://www.anchorterminal.com/compare/agno-vs-pydantic-ai.md): BB 72.8 vs A 83.7 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on agno.com or one of its subdomains, or the README of github.com/agno-agi/agno. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "agno", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Agno on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Agno on Anchor Terminal](https://www.anchorterminal.com/badges/agno.svg)](https://www.anchorterminal.com/tools/agno) ``` Plain link: ```html Agno on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Agno is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/agno-dark.png - Light: https://www.anchorterminal.com/assets/share/agno-light.png