Skip to content
Agents tracked: 258 Downloads (7d): 219M up 6.1% GitHub stars: 5.5M VS Code installs: 148M Releases (7d): 327 Agent status: 1 with issues Updated Oct 7, 2026

AG2 changelog: what's new each month

Every stable AG2 release summarised by month: the highlights, new features, improvements, fixes and anything you need to act on. 12 months covered; the current month updates daily.

October 2026 · so far

1 release: 1.1.2

October brought AG2 1.1.2 with UI improvements and important fixes for model output handling and skill execution.

Highlights

  • AG-UI now served at version 1.0 with updated interface.
  • Model output schemas now properly derived from serialization.
  • Skill execution now respects declared paths for nested scripts.
  • Timeout failures in tenki integration are now preserved correctly.

New

  • AG-UI 1.0 interface.

Improved

  • Model output schema handling through serialization.
  • Skill ownership validation before argument checking.
  • Tenki SDK upgraded with better timeout failure handling.

Fixed

  • Nested script execution now uses declared paths instead of arbitrary locations.
  • Local skill ownership validation improved.
  • Timeout failures in tenki integration now handled correctly.

September 2026

5 releases: 1.0.4 → 1.1.1

September brought major SDK compatibility updates and significant MCP enhancements, including support for Anthropic SDK 1.x and OpenAI SDK 3.x. The month also added session persistence, new governance policies, and improved error handling across the platform.

Action needed
  • Bedrock requires aiobotocore session (boto3.Session will fail); install aiobotocore>=3.9.1,<4.
  • Restricted shell mode (readonly=True) no longer includes find, file, sort, uniq, git and similar tools; explicitly list allowed commands.
  • MCP tools can no longer shadow local tools; colliding MCP tools are dropped with a warning.

Highlights

  • AG2 agents can now resume prior sessions over ACP instead of starting fresh each time.
  • AG2 can serve MCP Apps with structured tool output and extension support.
  • New policies added: toolblocklist for denying specific tools by pattern, and outputscan for inspecting tool results after execution.
  • Anthropic SDK 1.x and OpenAI SDK 3.x are now fully supported with updated model references.
  • Bedrock configuration now properly uses aiobotocore sessions and respects explicit keys and region parameters.

New

  • AnthropicBashTool built-in tool with improved event handling.
  • argvalidation to validate tool arguments before execution.
  • outputscan policy to inspect tool results after they return.
  • Bidirectional input requests: AG2 MCP servers can ask clients for input, and clients can answer servers.
  • MessageEnqueued event announced when items are added to an agent's inbox during live sessions.
  • Ratelimit governance policy for tealtiger.
  • MemorySkill body now renders per read.
  • Trace conversion functions (readablespanstotrace, spanstotrace) are now public API.

Improved

  • Middleware now records full conversation history and tool-call output on chat spans instead of partial views.
  • Structured tool results are now recorded on spans instead of being flattened.
  • MCP resource template URI variables are properly decoded.
  • Served agents can now own their HTTP transport settings.
  • MCP tool discovery follows pagination to ensure all tools are found.
  • Anthropic thinking tokens are now reported, with measured zeros preserved.
  • Strict mypy type checking applied to remaining provider mappers to catch SDK drift in CI.
  • Tool resolution order clarified: code-declared tools override MCP and client tools, with later declarations in code winning over earlier ones.

Fixed

  • Shared event descriptors no longer retarget under concurrency, fixing intermittent worker-thread hangs on Windows.
  • MCP protocol failures now return the spec's prescribed JSON-RPC error codes instead of generic errors.
  • Prompts with required arguments are validated before rendering.
  • Bedrock session configuration now works correctly with aiobotocore sessions.
  • Subagent maxconcurrency semaphore provisioning is now locked per loop.
  • Restricted shell mode now clearly rejects pipes, redirects, globs, and variable syntax.

August 2026

2 releases: 1.0.2 → 1.0.3

August brought major protocol upgrades and network expansion to AG2, with support for exposing agents over ACP, remote agent communication via HTTP and WebSocket, and a complete migration to MCP 2.0. Security and governance capabilities were significantly strengthened with signed agent cards, TLS transport, and a comprehensive new audit and control system.

Action needed
  • All MCP surfaces now require MCP 2.0 protocol; older protocol versions are no longer supported.

Highlights

  • AG2 agents can now be exposed over ACP protocol, allowing ACP clients to drive them like any other agent.
  • Drive remote ACP agents across networks over HTTP and WebSocket, not just local subprocesses.
  • Complete migration to MCP 2.0 protocol across all client and server surfaces.
  • New governance system with three modes (ENFORCE, MONITOR, OBSERVE) for managing agent behavior and costs with full audit trails.
  • Kill switch and budget controls let you freeze agents and set hard spending ceilings.

New

  • Expose AG2 agents as ACP agents for network-accessible agent control.
  • Remote ACP agent communication over HTTP and WebSocket with bidirectional request handling.
  • Signed and verified AgentCards for establishing card authenticity.
  • gRPC transport security with TLS for agent-to-agent communication.
  • User-defined A2A extensions to build custom protocol capabilities.
  • ElevenLabs integration as a realtime voice provider for LiveAgent.
  • Governance framework with three enforcement modes and reason codes for every decision.
  • Audit trail with risk scores, running cost tracking, and TEEC receipts for tool evaluation.

Improved

  • Upgraded to ACP protocol version 0.12.
  • Added Kilo Code support and model selection to ACP configurations.
  • Conversation handling updated to align with MCP 2.0 model.
  • MCP servers can now expose metadata about themselves.
  • Governance decisions can be shared across multiple agents with unified cost and frozen-agent tracking.
  • Hosts can answer human-input requests from agents served over ACP.

July 2026

3 releases: 1.0.0b0 → 1.0.1

July brought AG2 1.0 with a major restructuring around the new framework, now the mainline codebase. The month added substantial protocol and provider support for broader agent interoperability.

Action needed
  • Classic framework, agents, orchestration surfaces, and interoperability layers removed.
  • Classic command-line entry point removed.

Highlights

  • The autogen.beta framework is now the primary AG2 framework; the classic framework and CLI have been removed.
  • New support for the Natural Language Interaction Protocol (NLIP) and Agent Client Protocol (ACP) for driving external CLI coding agents.
  • Agents can now discover and load tools on demand through server-side tool search with deferred loading.
  • Expanded provider coverage including full Mistral SDK support, new Anthropic tool versions, and enhanced Gemini tool grounding.
  • MCP tool gateway exposes AG2 tools to external agents over the Agent Client Protocol.

New

  • Natural Language Interaction Protocol (NLIP) integration.
  • Agent Client Protocol (ACP) support for driving CLI coding agents like Claude Code, Codex, OpenCode, and Gemini CLI.
  • Server-side tool search with deferred tool loading for on-demand discovery.
  • MCP UI extension support.
  • Z.AI Files API support.
  • Mistral provider with full SDK support, streaming, multi-modality, and structured outputs.
  • Xquik tweet search toolkit.
  • MCP tool gateway that exposes AG2 tools to external agents.

Improved

  • OpenAI provider now supports FileSearchTool and SkillsTool.
  • Anthropic provider updated with new code execution version and current webfetch and websearch tool versions.
  • Gemini provider enhanced with FileSearchTool store search and GoogleMapsTool grounding.
  • UsageEvent telemetry excluded from history compaction via conversational marker.

June 2026

3 releases: 0.13.3 → 0.14.0

June brought major enhancements to AG2's cross-process capabilities, sandbox abstraction, and agent UI generation. The month focused on expanding the framework's ability to handle distributed execution, skills as first-class extensions, and dynamic user interfaces.

Highlights

  • A2UI now available in beta, letting agents generate user interfaces on the fly.
  • Agent Resume feature enables replaying and forking execution from intermediate states, not just turn boundaries.
  • SkillPlugin makes skills a portable, first-class extension surface aligned with agentskills.io spec.
  • New Observable run surface with Agent.run and AgentReply.run methods lets callers watch execution unfold.
  • Cross-process data and control planes introduced via WsLink and frame-based RPC for distributed hub-client communication.

New

  • BackgroundAgentTool for running agents in the background without blocking foreground conversation.
  • Sandbox Protocol and LocalSandbox implementation for clean sandboxed execution abstraction.
  • Amazon Bedrock Beta Client support.
  • Z.AI / GLM model support including GLM 5.2.
  • Gemini image generation and editing capabilities with dedicated imageconfig.
  • Multi-runtime composition and MemorySkill for code-defined skills.
  • UsageEvent for decoupled usage reporting separate from LLM calls.
  • Hub.register convenience method with per-agent client lifecycle.

Improved

  • Optional reference answer support in Agent-as-a-Judge and Pairwise judge evaluators.
  • A2A protocol now creates artifact before appending streamed text chunks and validates protocol version on connection.
  • Stream.get now guards against a second matching event aborting the turn.
  • Beta cookbook examples tweaked for improved reliability.
  • OpenAI reasoning tokens now correctly map to thinking tokens instead of cache creation tokens.
  • Network fails fast when a delegate targets itself, preventing self-delegation errors.

Fixed

  • OpenAI reasoning token mapping corrected from cache creation to thinking tokens.
  • Stream event handling no longer aborts turns on second matching event.
  • Self-delegation detection now fails fast in the network layer.
  • Codecov action updated to v7.0.0, fixing bricked GPG key import failure.

May 2026

5 releases: 0.12.2 → 0.13.2

May brought major architectural advances to AG2, introducing durable agent memory systems, channel-based multi-agent orchestration, and significant expansions to model support and safety features. The month saw both foundational infrastructure improvements and practical new integrations.

Action needed
  • PerplexitySearchTool renamed to PerplexitySearchToolkit for consistency with toolkit naming pattern.

Highlights

  • New KnowledgeStore system enables agents to persist memories across conversations using a virtual filesystem model with multiple backends.
  • Channel-based architecture provides append-only event logs for multi-agent interactions, supporting everything from simple Q&A to complex workflows.
  • Agent Evaluations framework added for assessing and grading agent outputs automatically.
  • Critical security fix for code injection vulnerability in ContextExpression; all users should upgrade.
  • Expanded model support now includes xAI (Grok) and next-generation Anthropic and AWS Bedrock clients.

New

  • KnowledgeStore – agent-owned virtual filesystem with read, write, list, delete, and exists operations across five backends.
  • SandboxCodeTool in beta for running agent-generated code safely in isolated Daytona and Docker environments.
  • Agent Evaluations framework for grading and assessing agent outputs.
  • Dynamic Tool Factory allowing agents to create other agents through their tools.
  • Workflow Finish Tool enabling tools to signal completion and end workflows.
  • ChannelAdapter protocol for custom multi-agent orchestration patterns beyond the four built-in ones.
  • xAI provider support with Grok models and file API.
  • Named Views for clearer multi-party channel addressing with [name] prefixes.

Improved

  • Cross-session memory enables agents to remember context like names and projects across days.
  • Multi-agent knowledge sharing uses cheap reads of exposed paths instead of expensive delegation round-trips.
  • Perplexity Search integration refactored as PerplexitySearchToolkit for consistency.
  • Search tools now use async SDK clients for better performance.
  • Envelope rendering in channels now consistent between current turn and history.
  • Agent Evaluations framework with unified response architecture for Anthropic V2 and Bedrock V2 clients.
  • OpenAI config cleanup omits empty parameters in beta provider.
  • AG-UI now supports reasoning messages and multimodal user content in both directions.

Fixed

  • Code injection vulnerability in ContextExpression (GHSA-9fvw-gr53-m7fw) – string values now escaped before eval.
  • OpenAI image handling on both Chat Completions and Responses APIs.
  • ModelMessage None content handling.
  • Shell operators now blocked in readonly and allowed-command mode.
  • Toolcall simulation in agent messages.
  • Exa API integration updated with integration header set via client.headers.

April 2026

3 releases: 0.11.5 → 0.12.1

April brought significant new capabilities to AG2, including a command-line interface, new agent types, and expanded tool support. The release also deprecated several older agents and modules while introducing modern replacements like the Tasks API and Observer API.

Action needed
  • Docker package is now an optional dependency; install with ag2[docker] to use Docker-based code execution.
  • Deprecated agents: GPTAssistantAgent, LLaVAAgent, WebSurferAgent, TextAnalyzerAgent, MathUserProxyAgent, SocietyOfMindAgent, AgentOptimizer, RetrieveAssistantAgent.
  • Deprecated capabilities: ImageGeneration module, agenteval module.
  • Deprecated interop: CrewAIInteroperability (use LangChain or PydanticAI interop instead).

Highlights

  • New AG2 CLI for building, running, testing, and deploying multi-agent applications.
  • A2UIAgent reference agent for creating dynamic, agent-driven frontends with A2UI protocol support.
  • Agent.astool() enables agent delegation through tool calls with the new Tasks API.
  • Files API Client added for file handling capabilities.
  • New search tools including TavilySearchTool and ExaToolkit for web search integration.

New

  • AG2 CLI with full-featured command-line interface for multi-agent applications.
  • A2UIAgent reference agent combining A2A and A2UI protocols for dynamic frontends.
  • Agent.astool() for agent delegation using tool calls.
  • Observer API to subscribe to Agent events for monitoring and debugging.
  • Files API Client for file handling (Beta).
  • WebFetchTool for fetching web content with domain filtering.
  • TavilySearchTool for Tavily-powered web search.
  • ExaToolkit for Exa search integration.

Improved

  • Telemetry support added for monitoring and analytics.
  • Structured output support using ResponseSchema for more predictable agent responses.
  • Redis stream support for scalable message handling.
  • Tool-scoped middleware hooks for fine-grained control over specific tools.
  • Multi-part ToolResult support allowing tools to return multiple input types.
  • Toolkit Merging API for combining toolkits with updated documentation.
  • Google Vertex AI support for using models on Google's platform.
  • WebSearchTool now includes domain filtering capabilities.

Fixed

  • PerplexitySearchTool restored from deprecation based on community feedback.

March 2026

2 releases: 0.11.3 → 0.11.4

March brought major architectural improvements to AG2, including a new event-driven MemoryStream foundation for safer agent reusability, unified multi-provider LLM support across OpenAI, Anthropic, Google Gemini, and others, and several security enhancements. The release also adds testing capabilities, dependency injection for tools, and new middleware extensibility.

Highlights

  • Event-driven MemoryStream architecture isolates conversation state and enables real-time streaming while making agents safely reusable.
  • Unified LLM support across OpenAI, Anthropic, Google Gemini, Alibaba DashScope, Ollama, and Mistral with consistent configuration.
  • Dependency injection system for tools with automatic JSON schema generation from type hints.
  • Security fixes for shell command injection, path traversal, and sensitive key redaction in logs.
  • First-class testing with TestConfig and TestClient for unit tests using canned LLM responses without network calls.

New

  • MemoryStream pub/sub event bus for real-time streaming and conversation state isolation.
  • Middleware pipeline system with built-in history limiting, token limiting, and LLM retry capabilities.
  • Human-in-the-loop middleware hook for intercepting, transforming, or logging human input.
  • QuickResearchTool for parallel web research across multiple sources.
  • CodeExecutionTool for code execution capabilities.
  • ToolResult final flag to skip follow-up LLM calls and end turns immediately.
  • Gemini client streaming support.
  • Mistral V2 API support.

Improved

  • Tools now auto-generate JSON schemas from Python type hints via dependency injection.
  • Tool calling refactored into dedicated event types for cleaner handling.
  • ClientTool.register now correctly sends ClientToolCall events to the stream.
  • Gemini client improved to handle messages without a content key.

Fixed

  • Shell command injection vulnerability in ShellExecutor now uses shell=False with shlex.split.
  • Path traversal prevention added to MCP resource URIs and file operations.
  • Sensitive keys now redacted in FileLogger output to prevent credential leakage.
  • ClientTool stream event handling fixed.

February 2026

3 releases: 0.11.0 → 0.11.2

February brought significant advances in real-time agent communication and observability. AG2 now supports streaming across agent-to-agent interactions, integrated observability via OpenTelemetry, and migrated to OpenAI's Responses v2 API for stateful conversations.

Highlights

  • AG-UI protocol integration enables dynamic, real-time frontends powered by AG2 agents.
  • Full streaming support for Agent-to-Agent communication on both server and client sides.
  • OpenTelemetry tracing provides complete visibility into multi-agent workflows.
  • OpenAI Responses v2 client brings stateful conversations and built-in tools without manual history management.
  • Agent-to-Agent human-in-the-loop events enable interactive approval workflows in agent pipelines.

New

  • AG-UI Protocol Integration for building dynamic agent-powered frontends.
  • OpenTelemetry tracing and instrumentation for multi-agent workflow observability.
  • A2A Streaming with full server and client-side support.
  • A2A HITL Events for human-in-the-loop processing in agent communication.
  • AG-UI Message Streaming with event-based architecture for real-time response display.
  • Extra headers support in OpenAI and Azure OpenAI configurations.
  • MCP Client Session Manager documentation.
  • Built-in tool documentation in tools section.

Improved

  • Anthropic V1 client now supports streaming and non-beta mode.
  • OpenAI client upgraded to Responses v2 API with stateful conversation management.
  • Anthropic and OpenAI clients fixed to support Agent-to-Agent messages without role field.
  • Docker error messaging improved when Docker is not running.
  • Quick Start documentation cleaned up and simplified.
  • Exception handling improved by replacing bare except statements with except Exception.
  • LLM text streaming now connected through to A2A implementation.

Fixed

  • ToolCall return type TypeError resolved.
  • Gemini client parallel tool calls support fixed.
  • Gemini structured output handling with additionalProperties corrected.
  • OpenAI Responses client empty string content handling and phase key support fixed.
  • Async tool result awaiting in async execution fixed.
  • Group Tool Executor async wrapper preservation in context variable injection.

January 2026

2 releases: 0.10.4 → 0.10.5

January brought significant orchestration and observability improvements to AG2, including powerful step-through execution for workflows and accurate cost tracking across group chats. The month also expanded model support and added critical security fixes.

Highlights

  • Step-through execution feature (runiter and rungroupchatiter) lets you pause and step through agent workflows event-by-event.
  • Group chat cost tracking now accurately reports costs across all agents, not just the manager or last agent.
  • AWS Bedrock client now includes exponential backoff and retries to resolve throttling issues.
  • Added support for OpenAI's GPT 5.2 Codex models and GPT 5.1 shell tool capabilities.
  • New RemyxCodeExecutor for research paper execution workflows.

New

  • Step-through execution orchestration (runiter and rungroupchatiter) for pausing and stepping through workflows.
  • AWS Bedrock support for additionalModelRequestFields, enabling Claude 3.7 Sonnet's Thinking Mode and other provider-specific parameters.
  • OpenAI GPT 5.2 Codex models support for enhanced coding capabilities.
  • Shell tool support in the Responses API for command-line interactions.
  • RemyxCodeExecutor for research paper execution.
  • HuggingFace Model Provider integration guide and documentation.
  • Google Vertex AI deployment guide.
  • Python 3.14 development environment support via devcontainer.json.

Improved

  • AWS Bedrock client reliability with built-in exponential backoff and retries.
  • Group chat cost tracking now captures costs across all participating agents.

Fixed

  • Orchestrations basic concepts documentation.
  • Multiple security vulnerabilities (CVE-2026-23745, CVE-2026-23950, CVE-2026-24842).

December 2025

2 releases: 0.10.2 → 0.10.3

December brought major expansions in structured outputs and reasoning capabilities across multiple AI providers. AG2 added support for the latest models from OpenAI, Google, and Anthropic while improving tool calling and reasoning trace capture.

Highlights

  • OpenAI GPT-5.2 support including new xhigh reasoning effort level for complex tasks
  • Structured outputs now supported across Anthropic, Bedrock, and OpenAI platforms
  • Extended thinking and reasoning configuration to Google Gemini models
  • OpenAI applypatch tool for structured code editing across multiple files

New

  • Support for Anthropic's Structured Output API with schema-guaranteed responses
  • Bedrock structured outputs via responseformat API
  • OpenAI GPT-5.2 models and xhigh reasoning effort level
  • Applypatch tool support in OpenAI Responses API for code refactoring
  • ThinkingConfig support for Google Gemini models
  • Thought signatures for Gemini 3 models in functions
  • A2A client interceptors

Improved

  • ThinkingBlock now extracts text from reasoning traces for Anthropic clients
  • Event logging now routes through the logging system for better debugging control
  • Pydantic structured outputs for OpenAI Completions v2
  • Gemini FunctionDeclaration now uses proper Schema objects for better reliability

Fixed

  • Anthropic Beta API tool formatting issues
  • Bedrock structured outputs tool choice handling
  • Documentation fixes for DocAgent and table formatting

November 2025

1 release: 0.10.1

November brought foundational improvements to AG2's client architecture and expanded capabilities for directing agent interactions. The month focused on modernizing how the system handles multi-modal messages and reasoning.

Highlights

  • New OpenAI Client Architecture (V2) provides foundation for multi-modal messages and access to thinking/reasoning tokens.
  • FunctionTarget in group chats lets you use a function to determine message targets.
  • Support added for OpenAI GPT-5.1.
  • Various A2A (agent-to-agent) updates and fixes.
  • Security and bug fixes throughout the codebase.

New

  • OpenAI V2 client architecture for multi-modal message support
  • Access to OpenAI thinking and reasoning tokens
  • FunctionTarget feature for group chats
  • GPT-5.1 model support

Improved

  • A2A (agent-to-agent) communication updates and refinements

Fixed

  • Empty A2A message handling

Summaries are written automatically from the official release notes (full changelog ↗); check the original notes before relying on a detail. AG2: pricing, features and alternatives · All changelogs