All concepts

Claude Agent SDK

Anthropic's agent harness — the gather → act → verify loop behind Claude Code, plus computer use.

Agentic AI · Advanced · ~8 min

In plain English

A toolkit for building agents on Claude — the loop, tool use, permissions and context handling already wired, so you write the tools and the rules.

Why it's worth your time

It packages the parts that are tedious and easy to get subtly wrong: the loop bounds, the permission gates and the context handling.

If you remember three things

  • The agent loop and tool execution come built in
  • Permission and approval hooks are first-class, not bolted on
  • You still own the tool design and the evals

Overview

The Claude Agent SDK (formerly the Claude Code SDK) is Anthropic's framework for building autonomous agents on Claude — the same harness that powers Claude Code. Its core is a simple loop: gather context, take an action with tools (bash, file edit, code execution), then verify the result and repeat until the task is done. It adds MCP for external tools and data, subagents for isolated parallel work, context management as the window fills, and permission controls that gate side-effectful actions. Computer use extends the same loop to a GUI: Claude gets a screenshot, reasons, and returns mouse and keyboard actions.

How it works

  1. Start: Gather context The model pulls in the files, state, and tool results it needs.
  2. Gather context -> Act with tools Run bash, read/write/edit files, execute code.
  3. Act with tools -> MCP tools External systems plug in over a standard protocol.
  4. MCP tools -> Verify Tests and linters feed back so the agent self-corrects.
  5. Verify -> Computer use From a screenshot, return click/type actions; loop.
  6. Computer use -> Done Permissions gate irreversible actions; every step is logged.

In an interview

It's Anthropic's SDK for building agents on Claude, the harness behind Claude Code. The agent runs a loop — gather context, act with tools like bash and file edit, verify, repeat — until the task is done. It connects external systems via MCP, spins up subagents for isolated work, compacts context when the window fills, and gates risky actions behind permissions. Computer use lets it drive a GUI from screenshots by returning click and type actions.

Production defaults

Tools
verbs, few of them, actionable errors — the design rules don't change with the SDK
Permissions
gate side effects explicitly. Reads free, writes confirmed
Evals
your own golden set, in your repo, run on every prompt or model change

What breaks

  • The agent does more than you expected — The permission surface is wider than intended. Scope tools and credentials per task.
  • Works locally, not in CI — Interactive auth and interactive approvals don't exist headless. Design a non-interactive path deliberately.

Watch it explained

Claude Agent Skills Explained — Anthropic, 3:14

Related