Claude Agent SDK changelog: what's new each month
Every stable Claude Agent SDK release summarised by month: the highlights, new features, improvements, fixes and anything you need to act on. 3 months covered; the current month updates daily.
October 2026 · so far
1 release: 0.2.164
October brought security improvements to CI/CD workflows and updated compatibility with the latest Claude CLI, along with test fixes to support newer versions.
Highlights
- Enhanced CI/CD security with egress firewalling and network allow lists for GitHub Actions
- Updated bundled Claude CLI to version 2.1.292
- Fixed end-to-end tests for thinking deltas with newer CLI versions
Improved
- CI workflows now enforce stricter permission modes and security controls for Claude API calls
- Increased PyPI per-file upload limit to 250 MiB
Fixed
- Thinking-deltas end-to-end test compatibility with Claude CLI 2.1.287 and later
September 2026
13 releases: 0.2.150 → 0.2.163
September brought refinements to system prompt handling and message delivery options, along with stability fixes for multi-turn conversations involving subagents. The bundled Claude CLI was updated throughout the month to track upstream improvements.
Highlights
- System prompt snapshots can now be recorded in sessions for better reproducibility.
- New verbatimprompts option lets you send user messages to the CLI without automatic file expansion.
- Fixed follow-up turns failing when subagents completed just before message processing.
- Improved docstring accuracy and formatting across the SDK.
New
- SystemPromptCustom typed dict for custom system prompt definitions.
- snapshot field on SystemPromptPreset to enable session-level prompt recording.
- ClaudeAgentOptions.verbatimprompts flag to disable automatic @path file expansion in user messages.
Improved
- Docstrings aligned with actual code implementation.
- CI wheel compression and PyPI upload handling for larger distributions.
- Test infrastructure pinned to specific models to avoid CI failures from upstream default changes.
Fixed
- Follow-up turns now succeed after background subagents complete their work.
- stdin closure timing issue during multi-turn queries with hooks or MCP servers.
- Docstring formatting inconsistencies corrected throughout the codebase.
August 2026
21 releases: 0.2.129 → 0.2.149
August brought significant enhancements to session management, subagent integration, and error handling, alongside important security fixes for skill validation and expanded protocol support.
Highlights
- Added conversation reset detection and message origin tracking to help applications understand turn context.
- Implemented session resumption with checkpoint control via resumesessionat and resumedropsturn options.
- Extended MCP support to version 2.x while maintaining backward compatibility with 1.x.
- Added forwardsubagenttext option to stream subagent text and thinking blocks for full nested conversation rendering.
- Fixed skill name validation to prevent injection attacks through the CLI's allowedTools parameter.
New
- ConversationResetMessage dataclass surfaces when conversations are cleared or reset.
- Message origin field on UserMessage and ResultMessage indicates why a turn was initiated.
- resumesessionat and resumedropsturn options for truncating and validating session resumption.
- forwardsubagenttext option to forward subagent text and thinking blocks in the message stream.
- ResultError exception with structured error payload for terminal CLI errors.
- canusetool callback support for query() and string prompts with stdin kept open.
- Recovery of parenttooluseid when reading subagent transcripts via getsubagentmessages().
- MCP 2.x support for in-process SDK MCP servers using in-memory transport.
Improved
- Skill name validation now prevents characters that could cause injection through CLI parameters.
- Session resumption now seeds settings.json and coworksettings.json into temporary config directories.
- Error messages for failed resume operations are now more descriptive for pending control requests.
- Bundled Claude CLI updated throughout the month to version 2.1.252 with cumulative improvements.
Fixed
- Skill names containing parentheses, commas, control characters, wildcards, or leading slashes are now validated.
- Skill name validation prevents --allowedTools injection via unchecked characters in ClaudeAgentOptions.skills.
- Session resumption now properly surfaces CLI rejection errors to pending control requests like initialize().
Summaries are written automatically from the official release notes (full changelog ↗); check the original notes before relying on a detail. Claude Agent SDK: pricing, features and alternatives · All changelogs
