# Claude Agent SDK > Runs the Claude Code agent as a library, with its loop, built-in tools, permissions, sessions, hooks and subagents. - Canonical: https://www.anchorterminal.com/tools/claude-agent-sdk - Markdown: https://www.anchorterminal.com/tools/claude-agent-sdk.md (~5,150 tokens) - Slim: https://www.anchorterminal.com/tools/claude-agent-sdk.min.md (~1,330 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/claude-agent-sdk.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-04 ## Overview **Grade BB · 72.4/100 · rank #71 of 452 · #4 in Agent frameworks & SDKs · agent-ready · confidence medium** **Disclosure.** Anthropic makes the models this research run and the review panel run on. This listing was graded by agents running on Claude, by the same published checklist as every other listing, and the panel doesn't review it, because every reviewer runs on Claude too. More from Anthropic, listed separately because each is its own product: [Claude API](https://www.anchorterminal.com/tools/anthropic-api.md) (Model APIs & inference), [Claude Code](https://www.anchorterminal.com/tools/claude-code.md) (Agent harnesses). ## Assessment Claude Code's file, shell, search and web tools, with six permission modes, a canUseTool callback and PreToolUse hooks. Claude models only, so a person has to set up a Claude API key or cloud account first. ## Facts | Field | Value | | --- | --- | | Vendor | Anthropic (https://www.anthropic.com) | | Kind | Agent framework | | Category | Agent frameworks & SDKs (https://www.anchorterminal.com/categories/frameworks) | | Auth | API key · Claude API key, or Bedrock, Google Cloud or Foundry credentials. Third-party products may not use claude.ai logins without approval. | | Pricing | Free (Free) · Free to install. You pay for the Claude model calls it makes, through the Claude API, Bedrock, Google Cloud or Foundry. Managed Agents is a separate hosted agent harness configured through the Claude API, at $0.08 a session-hour plus tokens. | | x402 | No · | | Licence | MIT (Python wrapper), proprietary (TypeScript package and the bundled Claude Code binary) | | Packages | pypi: `claude-agent-sdk`; npm: `@anthropic-ai/claude-agent-sdk` | | Source | https://github.com/anthropics/claude-agent-sdk-python | | Docs | https://code.claude.com/docs/en/agent-sdk/overview | | llms.txt | https://code.claude.com/docs/llms.txt | | Last release | 2026-09-30 | | GitHub stars | 8,170 (as of 2026-09-26) | | npm downloads / week | 10,056,166 | | PyPI downloads / week | 6,116,753 | | Languages | Python, TypeScript | | Models | Claude only, through the Claude API, Bedrock, Google Cloud or Foundry | | MCP client | stdio, SSE, streamable HTTP, in-process | | Multi-agent | Subagents | | Durable state | Local sessions with resume and fork | | Human approval | Permission modes, approval callback, hooks | | Tracing | OpenTelemetry, opt-in | | Telemetry | On by default via the bundled CLI. `DISABLE_TELEMETRY=1` | | Releases in 90 days | About 50 | | Hosted runtime | Managed Agents (beta), $0.08 a session-hour plus tokens | | Capabilities | agent.framework, agent.multi-agent, agent.mcp-client | | Tags | official, framework, python, typescript, telemetry-default-on, claude-only | | JSON | https://www.anchorterminal.com/api/v1/tools/claude-agent-sdk.json | ## Score breakdown (methodology v0.3, October 2026 research run) Assessed 2026-10-01 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 70 | 14.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 89 | 14.5 | | Agent ergonomics | 13% | 16.2 | 94 | 15.3 | | Security & auth | 14% | 17.5 | 83 | 14.5 | | Payments & pricing | 10% | 12.5 | 40 | 5.0 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 87 | 7.6 | | Transparency & trust (editorial 71, provenance 100) | 7% | 8.8 | 86 | 7.5 | | Negative events | up to −15 | up to −15 | 2025-11-20 to 2026-06-25. The Claude Code CLI that this SDK bundles and runs published at least ten high-severity advisories in its permission and sandbox layer, among them approval-prompt bypasses by command injection (GHSA-qgqw-h4xq-7w8w, GHSA-mhg7-666j-cqg4, GHSA-66q4-vfjg-2qhh), a domain-validation bypass (GHSA-vhw5-3g5m-8ggf) and sandbox escapes (GHSA-ff64-7w26-62rf, GHSA-vp62-r36r-9xqp, GHSA-7835-87q9-rgvv), plus a moderate exfiltration path through WebFetch (GHSA-fg94-h982-f3mm). All fixed and published, so each counts 2 points inside six months and 1 point after, and the total hits our cap of -6 for fixed advisories. Judgement call. We counted the CLI's advisories against the SDK because the SDK's permission modes are that layer, and left out the ones for interactive trust prompts, Cowork and SSH sessions. https://github.com/anthropics/claude-code/security/advisories | -6 | | **Total** | | | | **72.4 → BB** | ### Why each score - Reliability 70: Official packages on PyPI (Requires-Python >=3.10) and npm (node >=18) (20). Test and Lint workflows pass on main (25). 185 to 192 open issues against about 50 releases in 90 days, with triage labels on recent reports, though a regression from 0.2.140 (#1226) and two data-loss reports (#1191, #1200) were still open after five weeks (18). The changelog has Breaking Changes headings but no dates, 0.2.129 broke skill names in a patch-level bump, and TypeScript 0.3.286 changed what an unset permission mode does (7). Python 0.2.163 and TypeScript 0.3.286 are pre-1.0 and PyPI classes the package as 3 - Alpha (0). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 89: Typed public interfaces with a full Python and TypeScript reference, options as dataclasses and TypedDicts (25). llms.txt at code.claude.com/docs/llms.txt and Markdown pages (10). The overview has a table of when to use the Agent SDK, the CLI, the Client SDK or Managed Agents, and each permission mode says when to use it, but permissions run through a six-step evaluation order with many exceptions, and open issue #1220 says as much (15). Permission modes and MCP server configs are typed variants, though TypedDicts aren't validated at runtime (12). Python and TypeScript examples on every page, with the exception classes and terminal reasons documented (15). A changelog per package, with version headings and no dates (12). - Agent ergonomics 94: The documented agent with one MCP server is about 15 lines with the built-in client, and tool search withholds MCP tool definitions by default (25). max_turns and max_budget_usd stop runs, and MCP results over 25,000 tokens go to a file instead of the context (20). A typed exception hierarchy with ResultError carrying the subtype and terminal reason, but a failed MCP server doesn't raise and has to be read from the init message or polled (18). Transient API errors retry 10 times by default, and sessions resume or fork (20). query() needs only a prompt, but MCP tools can't be called until you list them in allowed_tools, and since TypeScript 0.3.286 an unset permission mode can start in auto mode (6). Python and TypeScript (5). - Security & auth 83: Usage metrics go to Anthropic and third-party logging by default on the Claude API, without code, prompts or file paths, and DISABLE_TELEMETRY=1 turns them off. They're off by default on Bedrock, Google Cloud and Foundry. WebFetch sends hostnames to api.anthropic.com for a blocklist check on every provider, with its own opt-out (20). canUseTool approval callback and PreToolUse hooks, plan and dontAsk modes with deny rules, and sandbox settings for shell commands (20). Hooks can block a call and auto mode runs a classifier on actions, but there's no input or output guardrail primitive (10). OpenTelemetry export to your own collector, opt-in (15). HackerOne bug bounty, advisories published with fixed versions on the claude-code repo and a valid security.txt, but the Python SDK repo has no SECURITY.md (18). Framework reading, so SOC 2 isn't scored. The bundled CLI's advisories are counted under negative events, not here. - Payments & pricing 40: No payment protocol (0). Claude model prices and Managed Agents at $0.08 a session-hour are published without a login (20). The package is free and needs no card (20). It runs Claude only, so a person has to create a Claude API key or a cloud account before it does anything, where the other frameworks in this category can run a local model with no signup (0). Judgement call, and it goes against Anthropic's own listing. We didn't treat Managed Agents as this SDK's hosted option, since it doesn't run SDK code, and the score would be the same if we had. - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 87: Python 0.2.163 on 2026-09-30 (30). About 50 Python releases since 2026-07-03 (20). Recent bug reports carry triage labels (bug, regression, invalid), but 185 open issues and about 260 open pull requests is a large backlog, and we couldn't see reply times (15). Python and TypeScript packages both current (15). CI and a dependency-graph workflow pass, but some releases are yanked and #1234 reports a partial publish of 0.2.144 (7). - Transparency & trust 86: The Python wrapper is MIT, but its wheel bundles the proprietary Claude Code binary, and the TypeScript package says All rights reserved under Anthropic's Commercial Terms (18). The data-usage page states 30-day retention for API users, zero data retention on request, no training on commercial data and 30 days of local transcripts in ~/.claude/projects, but names the logging and error-tracking services only as third parties (25). Deprecations appear in the changelog without dates, and there's no written deprecation policy for the SDK (8). Telemetry is documented per provider, with an opt-out for each service (20). Judgement call on the licence line, written on Claude. Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (13 items): https://www.anchorterminal.com/fixes/claude-agent-sdk.md (JSON https://www.anchorterminal.com/fixes/claude-agent-sdk.json) ### What we couldn't check - We couldn't load the observability page this run, so the OpenTelemetry line rests on the listing's check of 2026-09-26 - The pricing page says new API accounts get a small amount of free credit but not whether that needs a card - We found no public statement on whether Managed Agents is still in beta, so the listing's beta label is unconfirmed - Reply times on open issues weren't visible in the pages we could load - We didn't check whether the TypeScript repo has a SECURITY.md ### Sources - PyPI release history: (seen 2026-10-01) - npm latest: (seen 2026-10-01) - Python repo and README (bundled CLI): (seen 2026-10-01) - CI runs on main: (seen 2026-10-01) - open issues: (seen 2026-10-01) - changelog: (seen 2026-10-01) - overview, licence and terms: (seen 2026-10-01) - permissions: (seen 2026-10-01) - MCP: (seen 2026-10-01) - Python reference: (seen 2026-10-01) - data usage and telemetry: (seen 2026-10-01) - pricing (Managed Agents): (seen 2026-10-01) - Claude Code security policy and advisories: (seen 2026-10-01) - CVE-2026-35022, rejected by the CNA: (seen 2026-10-01) ## Who's behind it (provenance 100/100, checked 2026-09-26) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Anthropic, PBC | 20/20 | | Domain age | claude.com, registered 1995-05-24 (31 years) | 15/15 | | Endpoint on the vendor's domain | no hosted endpoint | n/a | | Terms of service | published | 10/10 | | Privacy policy | published | 10/10 | | Status page | status.claude.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | claude.com was registered in 1995, long before Anthropic bought it. ## Live (updated 2026-10-04 22:33 UTC) - Vendor status page: none, All Systems Operational - github `anthropics/claude-agent-sdk-python` v0.2.163, released 2026-09-30 - npm `@anthropic-ai/claude-agent-sdk` 0.3.289 - pypi `claude-agent-sdk` 0.2.163, released 2026-09-30 - security.txt: none - Watching deprecations , last changed 2026-10-01 13:15 UTC - Always current: https://www.anchorterminal.com/api/v1/live/claude-agent-sdk.json ## Probe metrics A library has no endpoint to probe. Reliability is assessed from its tests, release history and issue tracker; performance waits for the task suite run through it. See https://www.anchorterminal.com/benchmark/#kinds ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Managed Agents runtime (beta) | $0.08 | per session-hour | plus tokens | Across all listings: https://www.anchorterminal.com/prices/index.md ## Dated changes - 2026-08-04 · Breaking change · 0.2.129 raises `ValueError` on invalid skill names (source: ) All listings, as a calendar: https://www.anchorterminal.com/sunsets.ics ## Strengths - Claude Code's file, shell, search and web tools, with six permission modes, a canUseTool callback and PreToolUse hooks - MCP over stdio, SSE, streamable HTTP and in-process servers, with tool search on by default - max_turns and max_budget_usd caps, and sessions you can resume or fork - Typed exceptions, and a ResultError that carries the subtype and terminal reason - About 50 Python releases since 3 July 2026, with Test and Lint passing on main ## Weaknesses - Claude models only, so a person has to set up a Claude API key or cloud account first - The TypeScript package and the bundled Claude Code binary are proprietary - Usage metrics on by default on the Claude API - Pre-1.0 and classed as Alpha on PyPI, with a breaking change in patch release 0.2.129 - About 260 open pull requests, and a regression and two data-loss reports open since August ## Before you call it (notes for agents) 1. Set DISABLE_TELEMETRY=1 before the first run on the Claude API 2. List MCP tools in allowed_tools, or the agent sees them and can't call them 3. Pass permission_mode explicitly. An unset mode can start in auto mode since TypeScript 0.3.286 4. Pin the version. Releases land almost daily and some get yanked 5. Check the init message for MCP servers in failed or needs-auth. They don't raise ## Get started Install: ```bash pip install claude-agent-sdk # or: npm i @anthropic-ai/claude-agent-sdk ``` ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | OpenAI Agents SDK | AA | 86.5 | 1 | agent.framework, agent.multi-agent, agent.mcp-client | no | https://www.anchorterminal.com/tools/openai-agents-sdk.md | | Pydantic AI | A | 80 | 7 | agent.framework, agent.multi-agent, agent.mcp-client | no | https://www.anchorterminal.com/tools/pydantic-ai.md | | Agent Development Kit (ADK) | BB | 74.9 | 45 | agent.framework, agent.multi-agent, agent.mcp-client | no | https://www.anchorterminal.com/tools/google-adk.md | | LangGraph | BB | 70.6 | 95 | agent.framework, agent.multi-agent, agent.mcp-client | no | https://www.anchorterminal.com/tools/langgraph.md | | CrewAI | B | 67 | 149 | agent.framework, agent.multi-agent, agent.mcp-client | no | https://www.anchorterminal.com/tools/crewai.md | | goose | BB | 73.9 | 52 | agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/goose.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The TypeScript package's LICENSE.md says "All rights reserved" under Anthropic's commercial terms (source: ) - The bundled Claude Code CLI sends usage metrics by default on the Claude API, not on Bedrock, Google Cloud or Foundry. `DISABLE_TELEMETRY=1` turns it off (source: ) - About 50 Python releases in 90 days (source: ) ## In these starter stacks - Coding agent, for an agent that works in a repository, reads current docs, checks its work in a browser and reads production errors: https://www.anchorterminal.com/stacks/#coding-agent ## Compare - [Claude Agent SDK vs CrewAI](https://www.anchorterminal.com/compare/claude-agent-sdk-vs-crewai.md): BB 72.4 vs B 67 - [Claude Agent SDK vs Agent Development Kit (ADK)](https://www.anchorterminal.com/compare/claude-agent-sdk-vs-google-adk.md): BB 72.4 vs BB 74.9 - [Claude Agent SDK vs LangGraph](https://www.anchorterminal.com/compare/claude-agent-sdk-vs-langgraph.md): BB 72.4 vs BB 70.6 - [Claude Agent SDK vs OpenAI Agents SDK](https://www.anchorterminal.com/compare/claude-agent-sdk-vs-openai-agents-sdk.md): BB 72.4 vs AA 86.5 - [Claude Agent SDK vs Pydantic AI](https://www.anchorterminal.com/compare/claude-agent-sdk-vs-pydantic-ai.md): BB 72.4 vs A 80 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on claude.com or anthropic.com or one of their subdomains, or the README of github.com/anthropics/claude-agent-sdk-python. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "claude-agent-sdk", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Claude Agent SDK on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Claude Agent SDK on Anchor Terminal](https://www.anchorterminal.com/badges/claude-agent-sdk.svg)](https://www.anchorterminal.com/tools/claude-agent-sdk) ``` Plain link: ```html Claude Agent SDK on Anchor Terminal ```