- fix(mcp): derive model output schemas from serialization
- fix(tenki): upgrade sdk and preserve timeout failures
- chore(deps): bump gitpython from 3.1.59 to 3.1.62
- fix(skills): check local skill ownership before validating arguments
- chore(deps): bump pyjwt from 2.14.0 to 2.15.0
- chore(deps): bump urllib3 from 2.7.0 to 2.8.0
AG2 by AG2
Overview
A community-driven continuation of the original AutoGen codebase, maintained as an open-source multi-agent framework.
AG2 was downloaded 31.9K times from PyPI in the week ending Oct 4, 2026, down 20.8% on the week before and down 44.5% over the last 30 days compared with the 30 before. The GitHub repository has 4,975 stars, 83 of them added in the last 30 days. The latest stable release is 1.1.2, published Oct 3, 2026; there were 6 stable releases in the past 30 days.
AG2 usage and attention over time
Download the raw daily series: ag2.csv
Install AG2
| PyPI | pip install ag2 |
|---|
These commands use the packages tracked on this page. The vendor may recommend a different installer; see the official documentation.
Key facts
| Maker | AG2 |
|---|---|
| Type | Multi-agent framework |
| License | Apache-2.0 |
| Interfaces | Python library |
| Main language | Python |
| Open issues and PRs | 53 |
Pricing
AG2 is open source and free to use; you pay only for the models and infrastructure it runs on.
, checked Oct 5, 2026. Prices change often; confirm before you buy.
Pulse Score breakdown
Each component is scored 0 to 100 from public signals; a dash means no data for it. Methodology.
What changed: recent AG2 releases
10 stable releases in the last 90 days · Full changelog
- BedrockConfig(session=...) takes an aiobotocore.session.AioSession. A boto3.Session fails on the first call with AttributeError: 'Session' object has no attribute 'createclient'.
- The bedrock extra installs aiobotocore>=3.9.1,<4 instead of boto3. If your application also installs boto3, pick a version whose botocore fits aiobotocore's pin.
- Explicit keys and regionname passed together with session= now apply. They used to be silently ignored.
- Pipes, redirects, chaining, globs, ~ and variables are not available in restricted mode. Shell syntax is refused with a clear error, and globs reach the program literally.
- readonly=True only allows commands that cannot write files or run other programs. find, file, sort, uniq and git … are no longer in the built-in set; list the ones you need in allowed.
- blocked=[...] is unchanged and remains best-effort. It is not a security boundary.
- MessageEnqueued — ConversationContext.enqueue() now announces a transient event after appending to an agent's inbox, so a live session can react between model responses. The calling API is unchanged.
- MCP errors follow the spec. Prompts with required arguments are validated before rendering, and protocol-level failures return the prescribed JSON-RPC codes instead of a generic error or a tool…
- A shared event descriptor could retarget under concurrency, leaving a tool awaiting a result that never matched. Seen as intermittent worker-thread hangs on Windows CI.
- Provider payloads are built from the SDKs' own param types, with the remaining mappers under strict mypy. SDK drift — a renamed, removed or narrowed field — now fails in CI rather than arriving as…
- fix(mcp): validate required prompt arguments before rendering
- refactor(mappers): put the remaining provider mappers under strict mypy
- fix(mcp): decode resource template URI variables
- feat(mcp): let a served agent own its HTTP transport settings
- feat(tealtiger): add ratelimit governance policy
- feat(skills): render a MemorySkill body per read
- fix(a2a): require only the chosen transport's SDK extra
- fix(subagents): lock maxconcurrency semaphore provisioning per loop
- Serve MCP Apps: AG2 can now serve MCP Apps, with structured tool output and extension support.
- Input requests, both directions: An AG2 MCP server can ask the calling client for input, and an AG2 MCP client can answer a server that asks for it.
- outputscan: A new policy that inspects what a tool returns, rather than what it was asked to do. Every policy so far ran before the call; this one runs after, so a tool that returns something it…
- Middleware: Chat spans now record the full history and tool-call output, rather than a partial view.
- Dead table-of-contents anchors and moved contribution-policy links repaired.
- chore(deps): bump github/codeql-action/upload-sarif from 4.37.8 to 4.37.9 in the github-actions group
- Anthropic SDK 1.x — AG2 adapts to the breaking changes in the Anthropic SDK 1.x line, with Anthropic model name references updated to match.
- OpenAI SDK 3.x — Support for the OpenAI SDK 3.x line, including hosted shell and MCP events.
- AnthropicBashTool — New built-in tool, with improved event handling for Anthropic.
- toolblocklist — Deny specific tools by pattern, the inverse of the allowlist, for cases where blocking a known-bad set is clearer than enumerating everything permitted.
- argvalidation — Validate tool arguments before the call runs.
- session/load — An AG2 Agent served over ACP can now resume a prior session, rather than every connection starting fresh. Documentation.
AG2 alternatives
| # | Agent | Pulse | Downloads 7d | 7d | 30d | VS Code installs | Stars | Latest release | Price | Last 90 days | |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 4 |
LangChainLangChain |
77 | 44.3M | up 1.9% | down 22.0% | — | 147K+45/day | 1.4.38d ago | Free (OSS) | ||
| 10 |
LangGraphLangChain |
69 | 16.1M | up 11.4% | down 21.8% | — | 42.7K+48/day | 1.2.13yesterday | Free (OSS) | ||
| 11 |
AI SDKVercel |
67 | 34.5M | up 13.5% | up 20.9% | — | 27.1K+18/day | 6.0.301yesterday | Free (OSS) | ||
| 13 | 63 | 8.7M | up 0.6% | up 2.0% | — | 8,679+23/day | 1.58.0yesterday | Free (OSS) | |||
| 17 |
Claude Agent SDKAnthropic |
59 | 21.5M | up 14.6% | up 0.6% | — | 8,219+5/day | 0.2.1636d ago | Free (OSS) | ||
| 21 |
MastraMastra |
58 | 2.2M | up 11.1% | up 19.1% | — | 28.6K+27/day | 1.74.0yesterday | Free (OSS) | ||
| No agents match that filter. | |||||||||||
AG2 FAQ
How much does AG2 cost?
AG2 is open source and free to use; you pay only for the models and infrastructure it runs on.
Is AG2 open source?
Yes. AG2 is open source, released under the Apache-2.0 license.
How popular is AG2?
AG2 was downloaded 31.9K times from PyPI in the week ending Oct 4, 2026, down 20.8% on the week before and down 44.5% over the last 30 days compared with the 30 before. The GitHub repository has 4,975 stars, 83 of them added in the last 30 days. The latest stable release is 1.1.2, published Oct 3, 2026; there were 6 stable releases in the past 30 days.
What is the latest version of AG2?
The latest stable release we track is 1.1.2, published on Oct 3, 2026.
What are the alternatives to AG2?
The closest alternatives in the same category by Pulse Score are LangChain, LangGraph, AI SDK, Strands Agents.
Where these numbers come from
PyPI: ag2. GitHub: ag2ai/ag2. See data sources for how each one is collected.
