Skip to content
Agents tracked: 258 Downloads (7d): 219M up 6.1% GitHub stars: 5.5M VS Code installs: 148M Releases (7d): 293 Agent status: 2 with issues Updated Oct 7, 2026

Claude Agent SDK changelog: what's new each month

Every stable Claude Agent SDK release summarised by month: the highlights, new features, improvements, fixes and anything you need to act on. 3 months covered; the current month updates daily.

October 2026 · so far

1 release: 0.2.164

October brought security improvements to CI/CD workflows and updated compatibility with the latest Claude CLI, along with test fixes to support newer versions.

Highlights

  • Enhanced CI/CD security with egress firewalling and network allow lists for GitHub Actions
  • Updated bundled Claude CLI to version 2.1.292
  • Fixed end-to-end tests for thinking deltas with newer CLI versions

Improved

  • CI workflows now enforce stricter permission modes and security controls for Claude API calls
  • Increased PyPI per-file upload limit to 250 MiB

Fixed

  • Thinking-deltas end-to-end test compatibility with Claude CLI 2.1.287 and later

September 2026

13 releases: 0.2.150 → 0.2.163

September brought refinements to system prompt handling and message delivery options, along with stability fixes for multi-turn conversations involving subagents. The bundled Claude CLI was updated throughout the month to track upstream improvements.

Highlights

  • System prompt snapshots can now be recorded in sessions for better reproducibility.
  • New verbatimprompts option lets you send user messages to the CLI without automatic file expansion.
  • Fixed follow-up turns failing when subagents completed just before message processing.
  • Improved docstring accuracy and formatting across the SDK.

New

  • SystemPromptCustom typed dict for custom system prompt definitions.
  • snapshot field on SystemPromptPreset to enable session-level prompt recording.
  • ClaudeAgentOptions.verbatimprompts flag to disable automatic @path file expansion in user messages.

Improved

  • Docstrings aligned with actual code implementation.
  • CI wheel compression and PyPI upload handling for larger distributions.
  • Test infrastructure pinned to specific models to avoid CI failures from upstream default changes.

Fixed

  • Follow-up turns now succeed after background subagents complete their work.
  • stdin closure timing issue during multi-turn queries with hooks or MCP servers.
  • Docstring formatting inconsistencies corrected throughout the codebase.

August 2026

21 releases: 0.2.129 → 0.2.149

August brought significant enhancements to session management, subagent integration, and error handling, alongside important security fixes for skill validation and expanded protocol support.

Highlights

  • Added conversation reset detection and message origin tracking to help applications understand turn context.
  • Implemented session resumption with checkpoint control via resumesessionat and resumedropsturn options.
  • Extended MCP support to version 2.x while maintaining backward compatibility with 1.x.
  • Added forwardsubagenttext option to stream subagent text and thinking blocks for full nested conversation rendering.
  • Fixed skill name validation to prevent injection attacks through the CLI's allowedTools parameter.

New

  • ConversationResetMessage dataclass surfaces when conversations are cleared or reset.
  • Message origin field on UserMessage and ResultMessage indicates why a turn was initiated.
  • resumesessionat and resumedropsturn options for truncating and validating session resumption.
  • forwardsubagenttext option to forward subagent text and thinking blocks in the message stream.
  • ResultError exception with structured error payload for terminal CLI errors.
  • canusetool callback support for query() and string prompts with stdin kept open.
  • Recovery of parenttooluseid when reading subagent transcripts via getsubagentmessages().
  • MCP 2.x support for in-process SDK MCP servers using in-memory transport.

Improved

  • Skill name validation now prevents characters that could cause injection through CLI parameters.
  • Session resumption now seeds settings.json and coworksettings.json into temporary config directories.
  • Error messages for failed resume operations are now more descriptive for pending control requests.
  • Bundled Claude CLI updated throughout the month to version 2.1.252 with cumulative improvements.

Fixed

  • Skill names containing parentheses, commas, control characters, wildcards, or leading slashes are now validated.
  • Skill name validation prevents --allowedTools injection via unchecked characters in ClaudeAgentOptions.skills.
  • Session resumption now properly surfaces CLI rejection errors to pending control requests like initialize().

Summaries are written automatically from the official release notes (full changelog ↗); check the original notes before relying on a detail. Claude Agent SDK: pricing, features and alternatives · All changelogs