Skip to content
Agents tracked: 258 Downloads (7d): 219M up 6.1% GitHub stars: 5.5M VS Code installs: 148M Releases (7d): 293 Agent status: 2 with issues Updated Oct 7, 2026

Agno changelog: what's new each month

Every stable Agno release summarised by month: the highlights, new features, improvements, fixes and anything you need to act on. 9 months covered; the current month updates daily.

October 2026 · so far

2 releases: 3.1.0 → 3.1.1

October brought significant infrastructure improvements to Agno, with new user management and authorization capabilities, enhanced filesystem support, and major improvements to knowledge synchronization reliability and reporting.

Action needed
  • Filesystem table (agnofs) is now keyed by (namespace, userid, path) instead of previous schema.
  • MCP default tools and lifecycle tools now default to False — explicitly list tools in MCPConfig(tools=[...]) to enable them.

Highlights

  • Added role-based access control (RBAC) to AgentOS with user management, scope policies, audit logging, and admin tools.
  • Introduced a new AgentOS filesystem backed by a database with dedicated routes for file operations.
  • Made MCP default and lifecycle tools opt-in, giving you explicit control over which tools are published.
  • Improved page synchronization with live progress tracking, detailed failure reporting, and automatic retry with backoff.
  • Added new AI/ML API toolkit for image, video, speech, and transcription capabilities.

New

  • Role-based access control (RBAC) system with role store, scope policy, and audit log.
  • DbFileSystem backed by agnofs table with /filesystem routes for file management.
  • AIMLAPITools for image, video, speech, and transcription via the AI/ML API.
  • Live progress tracking and cancellation support for knowledge page synchronization.
  • Detailed page sync failure reporting with failed page names and causes (capped at 20 failures).
  • AgentOS lifecycle support for Knowledge page synchronization.

Improved

  • MCP tools are now opt-in — only listed tools in MCPConfig(tools=[...]) are published.
  • Page synchronization retries transient fetch failures with backoff on large corpora.
  • Complete page sync support for large Mintlify-style sites with nested indexes and MDX code.
  • OpenAI response recovery when the chained previous response is unavailable.
  • HITL paused run continuation with background and stream no longer duplicates history.

Fixed

  • Page synchronization now completes for Mintlify-style sites that were previously marked as partial.
  • Transient connection failures during page fetches are now retried with backoff instead of failing immediately.
  • HITL background and stream continuation no longer creates duplicate entries in paused run history.
  • OpenAI responses now recover gracefully when the previous chained response is gone.

September 2026

7 releases: 3.0.5 → 3.0.11

September brought major improvements to knowledge retrieval, embedding reliability, and deployment flexibility. The month focused on surfacing errors transparently, enabling stateless scaling, and expanding vector database and model provider support.

Action needed
  • AWS Bedrock embedding failures now raise EmbeddingError instead of ModelProviderError; update exception handlers.
  • Vector database search() raises EmbeddingError on failure instead of returning empty array.
  • RemoteAgent.role and RemoteTeam.role changed from methods to properties; use .role not .role().
  • skipifexists=True no longer skips content marked as failed or partial; incomplete content will be re-embedded.

Highlights

  • Embedding failures are now reported instead of masked, with a new partial status for incomplete content that gets re-embedded on retry.
  • Stateless MCP serving allows multi-instance deployments without session affinity, reducing infrastructure costs.
  • Knowledge retrieval pipeline with MMR and recency rerankers balances relevance and diversity, preventing duplicate results.
  • Page storage system atomically publishes metadata, text and vectors with revision preservation on failure.
  • Added Elasticsearch vector database with vector, keyword and hybrid search capabilities.

New

  • Partial content status for files where some chunks embedded successfully and others failed.
  • Optional embedding retry during ingestion with configurable max retries and backoff.
  • GandrTools text-to-speech toolkit for Gandr TTS API.
  • Public surface serving for selected agents, teams and stateless MCP with shared quotas and CORS.
  • PageFileSystem bounded read-only toolkit for lazy page access with sync and async execution.
  • Complete page reads via Knowledge.readfullpage returning entire published pages from single SQL queries.
  • Elasticsearch vector database with vector, keyword and hybrid search.
  • Azure OpenAI Responses API support and Y-API as OpenAI-compatible model provider.

Improved

  • Embedding errors now raise EmbeddingError consistently across all embedders and providers like AWS Bedrock.
  • Agent dependency callables can now receive runinput and session alongside agent and runcontext.
  • MCP protocol negotiation with protocolmode selection between legacy and auto modes.
  • Bedrock model and embedder now accept custom async clients.
  • Anthropic replay assistant preserves thinking blocks instead of rejecting them.
  • Gemini image MIME type resolved dynamically instead of hard-coded.
  • RemoteAgent and RemoteTeam role are now properties instead of bound methods.
  • Slack event deduplication uses eventid instead of dropping retries.

Fixed

  • GET /knowledge/content/{id}/status now returns 404 for missing or non-owned content instead of 200.
  • Session data integrity in SQLite: bulk upsertsessions() now applies owner checks like single-row operations.
  • Public MCP validates tools are actually exposed in configuration.
  • Preserved Control Plane access with public surfaces.
  • Startup logs cleaned and durable queue storage initialized properly.

August 2026

7 releases: 2.8.7 → 3.0.4

August brought major architectural changes to Agno, including a complete overhaul of run storage, media handling, and knowledge base management. The month culminated in version 3.0 with substantial performance improvements and new integrations.

Action needed
  • MCP tool entrypoints no longer allow call-time toolname override.
  • KnowledgeManagementTools constructor flags renamed: enableingest/enableremove replaced by ingesturl, ingesttext, ingestpath flags.
  • KnowledgeManagementTools import moved from agno.tools.knowledgemanagement to agno.tools.knowledge.
  • agno.tools.file and agno.tools.knowledge are now packages; verify import paths.

Highlights

  • Runs now get their own database table with queryable columns, enabling direct access to run history and filtering by session, status, or agent.
  • Tool result and media offloading writes large outputs to external storage (AgentFS, S3, GCS) to keep messages lean.
  • CodeMode lets models write and execute Python code directly against tools as awaitable handles within a persistent IPython kernel.
  • Knowledge base ingestion redesigned: websites, folders, and files now create per-page or per-file rows with full CRUD operations.
  • Performance: tool schemas now cached across runs, and session history loads incrementally so conversations stay fast as they grow.

New

  • AdvisorTools for requesting feedback from advisor models.
  • OpenRouteService toolkit for accurate routing.
  • StudioRunnerTools identity-aware dispatch toolkit separate from StudioTools.
  • FinanceTools unified finance toolkit with swappable data providers.
  • Ramp Router model provider support.
  • WaveSpeedTools for image and video generation.
  • SerplyTools for web, news, and scholar search.
  • Synthorai model provider over OpenAI-compatible endpoint.

Improved

  • Cohere models now respect explicit zero values for sampling parameters.
  • StudioTools gained component-aware schedule tools and history parameters.
  • FileSystemTools allows overriding the toolkit name.
  • listcomponents command now accepts a name filter.
  • Team HITL paused runs persist across session reloads.
  • Toolkit instructions preserved during rehydration.
  • MCP configuration renames for clarity (mcp, MCPConfig, defaulttools as new spellings).
  • AtomicMail caches auth handshake and parallelizes proof-of-work.

Fixed

  • Persisted components now correctly rehydrate toolkit-qualified tools.
  • HITL confirmation propagates to tool execution on requirement deserialization.
  • Team.load crash on SQLite with unexpected keyword argument.
  • A2A stream client dropping task-level metadata on status updates.
  • Workflow WebSocket now honors selected workflow version.
  • MCP tools no longer allow call-time toolname override.

July 2026

14 releases: 2.6.21 → 2.8.6

July brought major infrastructure upgrades to Agno, including a new CLI tool, filesystem primitives for agents, and comprehensive evaluation and scoring capabilities. The month also saw significant expansion of integrations and performance improvements across the platform.

Action needed
  • StudioTool renamed to StudioTools (backward-compatible alias provided).
  • File operations now restricted to targetdirectory by default; set restricttobasedir=False to restore previous behavior.

Highlights

  • Introduced agnoctl, a new CLI for discovering AgentOS instances, provisioning tokens, and connecting to coding agents in one command.
  • Added FileSystem, a durable agent filesystem with pluggable backends and per-user isolation for persistent state.
  • Launched agno.scorer and agno.environments for building evaluation suites with code scoring, LLM judges, and isolated task rollouts.
  • Expanded integrations with new tools for TwelveLabs, Sofya, SearchAPI, Redmine, Superserve, Plivo, and others.
  • Added ValkeyDB as an in-memory database option with vector and keyword search support.

New

  • agnoctl CLI with agno connect, agno tokens, agno create, and lifecycle commands (up, down, restart, status).
  • FileSystem primitive for persistent, namespace-isolated agent storage with pluggable database backends.
  • agno.scorer module with CodeScorer, JudgeScorer, and ToolCallScorer for evaluation.
  • agno.environments for running isolated task rollouts with fresh state and controlled caching.
  • OAuth support for the AgentOS MCP endpoint.
  • Service Accounts and per-client Personal Access Tokens (PATs) for secure token management.
  • GET /info discovery endpoint for AgentOS capability detection.
  • ValkeyDB vector store with vector and keyword search capabilities.

Improved

  • Toolkit timeout support extended across more toolkits with configurable HTTP timeouts.
  • ModelResponse.createdat now stamped per instance instead of at import time.
  • Fallback model responses now persist in session history.
  • FileSystemKnowledge and path traversal prevention added to multiple tools.
  • Google Calendar and other Google tools now support timezone-aware dates and pagination.
  • agno connect enhanced with multi-target select, disconnect, and restart hints.
  • Tool wrapping performance improved by caching Pydantic version lookups (6x faster in benchmarks).
  • POST /metrics/refresh no longer blocks uvicorn workers on large datasets.

Fixed

  • Sync session methods no longer silently break when used with async database.
  • MCP tools prevented from silently disappearing in Registry.
  • Path traversal vulnerabilities closed in AirflowTools and ClickHouse deletebymetadata.
  • Google Drive download filenames constrained.
  • DuckDbTools derived table names sanitized and full-text search fixed.
  • SQL injection eliminated in ClickHouse metadata operations.

June 2026

11 releases: 2.6.10 → 2.6.20

June brought significant expansion to Agno's capabilities with four new model providers, enhanced streaming and checkpointing features, and improved integrations across multiple platforms. The month focused on resilience, observability, and extending AgentOS as a configuration and extension platform.

Action needed
  • ParallelBackend migrated to parallel-web >= 1.0 GA API; floor version pinned to >=1.0.
  • Call-site dependencies behavior changed: now merge with configured dependencies instead of replacing them.

Highlights

  • Four new model providers added: Inception Labs, Xiaomi MiMo, MiniMax, and Cloudflare AI Gateway.
  • Sub-agent event streaming now flows from context providers through to parent runs.
  • Checkpointing added at tool batch level with unified continue endpoint for regenerate and run forking.
  • AgentOS registry now auto-populates from agents, teams, and workflows with full CRUD support.
  • ClickHouse support added for high-volume trace ingest and OLAP scans.

New

  • YouTools integration for You.com Search API.
  • DOCX and HTML file generation support.
  • Parallel Web Task API and Monitor API tools.
  • Manifest for per-entity AgentOS UI metadata configuration.
  • Socket support for human-in-the-loop workflows.
  • StudioTool toolkit for dynamic agent, team, and workflow composition.
  • Scavio search toolkit integration.
  • Slack app manifest for AgentOS interface.

Improved

  • WhatsApp Graph API upgraded to v25.0.
  • MiniMax default model upgraded to M3.
  • AgentOS MCP server now a real extension point with custom, scoped, identity-aware tools.
  • JSON schema handling improved for Optional dataclass fields with no declared type.
  • Slack HITL now supports user tokens for searchmessages alongside bot tokens.
  • FileTools now return forward-slash paths on all platforms.
  • LiteLLM now supports native structured outputs and JSON schema outputs per provider.
  • OpenAI web-search citations now surfaced on response.citations.

Fixed

  • Thread-safety race condition in Gemini cleanup under concurrent usage.
  • Call-site dependencies now properly merge with configured dependencies instead of replacing them wholesale.
  • DB approval records now resolved on approve/reject to prevent orphaned rows in Slack HITL.
  • Registry tools now deduplicated structurally so re-instantiated toolkits collapse.
  • Whitespace preservation in tool arguments.
  • Content hashing now includes metadata so duplicate document upserts no longer collapse.

May 2026

5 releases: 2.6.5 → 2.6.9

May brought major expansions to multimodal capabilities, external agent integrations, and enterprise features. The month focused on Google API support, workflow reliability, and security hardening.

Highlights

  • Added native support for Google's Antigravity and Gemini Managed Agents (Deep Research) through AgentOS with streaming and session management.
  • Introduced GeminiInteractions model class for Google's stateful interactions API, enabling richer conversation patterns.
  • Expanded context providers with Gmail, Calendar, and Notion Database backends for richer agent knowledge.
  • Added per-user data isolation layer in AgentOS for enhanced multi-tenant security.
  • Launched comprehensive data labeling cookbook with 18 self-contained workflows for text, image, audio, video, and document labeling.

New

  • Gemini Multimodal File Search now supports multimodal capabilities in the File Search API.
  • GmailContextProvider and CalendarContextProvider follow existing provider patterns for email and calendar integration.
  • Scheduler support for Mongo and AsyncMongo databases to run agents, teams, and workflows on cron schedules in AgentOS.
  • AntigravityAgent and AntigravityExternalAgent for Google's Antigravity API with native sessions and streaming.
  • GeminiInteractions support for Google's Deep Research managed agent with autonomous research, citations, and background streaming.
  • NotionDatabaseBackend added to wiki context provider.
  • Download file and upload file tools added for file operations.
  • Per-user data isolation layer for AgentOS authenticated endpoints.

Improved

  • SlackContextProvider now has enablemediatools flag (default: False) to control file download and upload.
  • LLMsTxt Tools and Knowledge Readers now include allowedhosts parameter to restrict fetches to trusted hosts.
  • Condition workflow step now handles errors in sub-steps with configurable onerror handling.
  • Slack Interface now supports HITL multi-row approvals with all pause types.
  • Path safety centralized into new agno.utils.pathsafety module with improved hardening across file and Slack tools.
  • Approvals can now be read in post-hooks with full resolved approval record details.
  • PgVector prefix matching now actually works through proper query routing instead of being silently ignored.
  • Claude variants now properly honor temperature, topp, and topk parameter values of 0.

Fixed

  • Fixed agetlastrunoutput returning None when agent.id is auto-generated during arun().
  • Fixed /continue endpoint to properly forward dependencies and metadata via getrequestkwargs.
  • Fixed LearningMachine context injection into Team system prompt.
  • Fixed trace parent session/agent/team IDs being overwritten by child agent spans when sharing trace IDs.
  • Fixed workflow HITL continue path to use async function in async contexts.
  • Fixed duplicate sparse encoder calls in Qdrant asyncinsert operations.

April 2026

10 releases: 2.5.13 → 2.6.4

April brought major expansions to Agno's capabilities with new context providers, team-level features, and multi-framework support. The month saw significant improvements to human-in-the-loop workflows, prompt caching, and local tooling.

Action needed
  • SlackContextProvider factory methods forbotread(), forassistantsearch(), and forwrite() removed in favor of explicit flags.
  • OpenAI model string prefix 'openai:' now maps to OpenAIResponses instead of OpenAIChat; use 'openai-chat:' for legacy OpenAIChat.

Highlights

  • Team human-in-the-loop and approvals now available with AgentOS integration.
  • New context providers added: Workspace, Wiki, and Parallel MCP for natural-language access to filesystems, repositories, and web search.
  • Claude prompt caching now supports multiple cached blocks per request with per-block TTL control.
  • Agents and teams can now be created dynamically at runtime using factories for multi-tenant scenarios.
  • Agent/team background runs can now reconnect and resume in case of interruption.

New

  • Skills support added to Team.
  • Nested workflow support—workflows can now be used as workflow steps.
  • LLMs.txt standard support for LLM-friendly documentation indexes.
  • Salesforce CRM tools.
  • Azure AI Foundry Claude model provider.
  • Workspace toolkit with read/write/delete/shell access gated by human confirmation.
  • WorkspaceContextProvider and WikiContextProvider for project-aware and wiki-backed contexts.
  • SlackContextProvider with simplified configuration and public channel fallback.

Improved

  • Workflow HITL now supports post-execution human review on Step, Loop, and Router with consolidated HumanReview config.
  • Sessions API now returns additional metadata fields including userid, agentid, teamid, workflowid, and metrics.
  • Claude models now automatically inject trailing user messages for versions that don't support assistant message prefill.
  • Slack interface adds automatic card overflow rotation to new messages when content exceeds threshold.
  • ChromaDB implements dynamic batch splitting for large upsert and query operations.
  • Model provider defaults updated to newer, actively supported versions to prevent deprecations.
  • Tool ordering made deterministic across all providers to improve prompt cache hit rates.
  • SessionSummaryManager now supports lastnruns and conversationlimit parameters.

Fixed

  • Workflow continuerun now correctly pauses at Condition, Loop, and Router HITL steps.
  • LearningMachine fixed to filter non-conversational messages from learning extraction.
  • OpenAI transient 400 errors under concurrent usage resolved by removing shared HTTP/2 client injection.
  • AGUI interface now emits reasoning events correctly and stores current user input instead of message history.
  • Workflow file path images now handled correctly during step conversion.
  • Knowledge tables now read from contentsdb instead of agent.db.

March 2026

7 releases: 2.5.6 → 2.5.12

March brought significant expansions to Agno's integrations, interfaces, and developer experience. The month focused on new tools, improved authentication options, and enhanced observability across agents and teams.

Highlights

  • Human-readable IDs replace UUIDs for simpler debugging and monitoring.
  • WhatsApp Interface V2 adds media support, interactive messages, and team workflows.
  • New Google toolkits for Slides and unified authentication simplify document and calendar work.
  • Session search lets agents and teams browse and reference previous conversations.
  • Extended observability with MLflow provides full trace tracking for agent operations.

New

  • GitHub App Authentication for knowledge sources as alternative to personal access tokens.
  • OpenAI-Like Embedder for providers with OpenAI-compatible embedding endpoints.
  • Human-readable identifiers for agents and teams (e.g., brave-falcon-7x3k).
  • GitLab and Perplexity search toolkits with read-focused integrations.
  • Docling Reader for processing multiple document file formats.
  • Followup suggestions built into Agent and Team.
  • Parallel AI Search support for Vertex AI.
  • Telegram Interface and SchedulerTools for agent-driven schedule management.

Improved

  • WhatsApp Interface now supports media, interactive messages, and /new command for fresh conversations.
  • Team Task Mode provides structured task data for frontend rendering in events.
  • Session previews now show per-run user/assistant pairs instead of flattened history.
  • Google Calendars and Gmail tools extended with service account authentication.
  • ChromaDB and LanceDB deduplication prevents duplicate content in search results.
  • AgentOS deployment simplified with environment variable fallbacks for host and port.
  • Tool parameter descriptions no longer include (None) prefix.
  • Custom datetime formatting support with strftime patterns for context rendering.

Fixed

  • Slack Interface now correctly propagates user ID.
  • OpenAI Responses API fixed for mixed external execution and regular tools.
  • MySQL engine now properly handles JSON data with serializer.
  • PostgreSQL session retrieval fixed to prevent data loss when session types change.
  • Human-in-the-loop now supports multi-round conversations with history context.
  • Claude conversation history preserves server tool blocks.

February 2026

1 release: 2.5.5

February brought significant improvements to Agno's integrations and real-time capabilities. Slack users now see live streaming responses, while support expanded across multiple AI platforms and media generation tools.

Highlights

  • Slack responses now stream in real-time with live progress cards showing tool calls, reasoning, and workflow steps.
  • Multiple bots can run on the same Slack server, each with its own authentication token and signing secret.
  • ModelsLab integration extended to support text-to-image generation, completing the full media suite.
  • Improved compatibility with Gemini and AWS Bedrock APIs through bug fixes and message handling.

New

  • Image generation capability via ModelsLab's text-to-image API.
  • Real-time streaming progress cards in Slack showing tool calls and reasoning steps.
  • Support for multiple bot instances per Slack workspace with independent authentication.

Improved

  • AWS Bedrock now merges consecutive toolResult blocks into single user messages for cleaner handling.
  • Workflows can now handle raw image bytes in the convertimageartifactstoimages step.
  • Knowledge filters now serialize FilterExpr objects in agent and team API responses.

Fixed

  • Gemini API requests no longer fail when conversations contain empty message parts.
  • Fixed issue preventing proper serialization of filter expressions in API responses.

Summaries are written automatically from the official release notes (full changelog ↗); check the original notes before relying on a detail. Agno: pricing, features and alternatives · All changelogs