← Agentic Foundations
Foundations · Platforms

Anthropic Claude Agent SDK, explained

Separate the client API from the agent runtime, and assess tools, permissions and the environment you operate.

Anthropic offers several ways to build with Claude. Calling the model API and embedding an agent runtime are different choices. Identify who will execute tools and manage the task before selecting an approach.

This guide covers the Claude Agent SDK. It is an orientation and assessment guide, not a deployment tutorial or a product ranking.

Client library or agent SDK?

A client SDK provides direct API access. The Agent SDK embeds the tool loop and context-management capabilities behind Claude Code in Python or TypeScript applications you operate. Anthropic’s managed agent offering is a separate hosting approach. Claude Agent SDK overview.

Choose the distinction based on your application requirements. A bounded classification step may need only an API call. A task that investigates files and iterates on results needs execution logic somewhere in the system.

Work through a document task

For an illustrative prototype, give an agent a test directory containing approved, fabricated support records. Ask it to find the record matching one case and create a draft file.

Begin with a constrained directory and the smallest necessary tool set. Keep production credentials and outbound messaging outside this environment. Confirm exactly which files it reads and writes.

Introduce a misleading instruction inside a source document. The document is task data. It should not authorize reading an unrelated directory or contacting an external service.

Permissions and isolation differ

The SDK provides tool permission controls, including rules and runtime decisions. These need deliberate configuration. Claude Agent SDK permissions.

Your hosting environment also needs file, process and network boundaries. A tool permission check and an isolated runtime control different parts of execution. Evaluate both.

An approval should concern the proposed action and its actual target. Define what happens when no person is available to answer, rather than leaving unattended work waiting indefinitely.

Context is not an access policy

Instructions tell the agent how to approach the task. Loaded project files and reusable resources can also influence behavior. Decide which configuration your application loads and who may change it.

Do not rely on an instruction such as “never access private files” while making those files freely readable by the process. Restrict the environment and credentials themselves.

Record the prompt and configuration version used in a run. This makes an unexpected action easier to investigate.

Assess recovery and evidence

Check how a resumed task handles a draft already written. An execution history is useful only if you can distinguish completed changes from intended changes.

Compare final output with actual files. Confirm whether a failed command left a partial result. Decide what evidence to retain without collecting full sensitive contents unnecessarily.

You own the operating decisions for a process you run: resource limits, credential handling, updates, incidents and retention. Confirm the current deployment guidance for your environment.

Prototype checklist

  • Select API access or an agent runtime deliberately.
  • Constrain files, tools and network access.
  • Review loaded configuration and ownership.
  • Test permission denial and unavailable approval.
  • Inspect actual outputs and interrupted writes.
  • Keep a stop and recovery procedure.

Start with one narrow task before introducing additional tools or delegated work.

Continue reading

Securing and operating an agent ↗

Map identities and data, restrict actions, monitor failures and prepare a tested stop procedure.

Prepared with AI assistance and checked against the linked documentation. Examples and numerical limits are illustrative unless stated otherwise. These guides do not report independent product testing. Check current documentation before choosing a tool.

Search the publication

Find a story by title, topic, or keyword.

Press Escape to close