NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #4482 most downloaded on npm
Last release 4 days ago
30 Sep 2026
Ships on a steady schedule
a new release about every 8 days
Some releases are documented
notes for 33 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
2 years old
637 releases · first in 2024
c35458e: fix(anthropic): preserve invalid toolset calls
### Patch Changes - Updated dependencies [8c65988] - Updated dependencies [527a163] - @ai-sdk/provider@4.0.21 - @ai-sdk/provider-utils@5.0.53
One column per month.
ede5b89: chore: migrate package builds from tsup to tsdown
c2511c1: fix: use standards-compliant User-Agent header
e361d39: feat(anthropic): add Claude Sonnet 5.5 support
e361d39: feat(anthropic): add Claude Sonnet 5.5 support
claude-sonnet-5-5 model ID to @ai-sdk/anthropic and @ai-sdk/google-vertex, anthropic.claude-sonnet-5-5 and us.anthropic.claude-sonnet-5-5 to @ai-sdk/amazon-bedrock, and anthropic/claude-sonnet-5.5 to @ai-sdk/gatewaybetween_tools thinking type (thinking: { type: 'between_tools' }), the lowest thinking setting on claude-sonnet-5-5; xhigh and max effort are lowered to high with a warning because the API rejects them with between_toolsclaude-sonnet-5-5 rejects disabled thinking: thinking: { type: 'disabled' } is replaced with between_tools thinking (with a warning), reasoning: 'none' maps to between_tools thinking, and budget-based thinking is converted to adaptive thinkingclaude-sonnet-5-5 rejects forced tool use: required and named tool choices fall back to auto, and structuredOutputMode: 'jsonTool' falls back to native structured outputs, each with a warning8373a22: Normalize dangling programmatic tool caller references in conversation history after pruning. Before a subsequent user message, omit caller metadata whose source code execution call is missing and emit a warning, preserving the retained tool calls and results. Keep caller metadata unchanged for active tool continuations.
### Patch Changes - Updated dependencies [e3605f6] - Updated dependencies [525efc5] - @ai-sdk/provider-utils@5.0.50 - @ai-sdk/provider@4.0.19
### Patch Changes - Updated dependencies [af9597b] - Updated dependencies [bc49f78] - @ai-sdk/provider-utils@5.0.49
154221f: feat(anthropic): support on-demand compaction and preserve signed compaction blocks
771e74b: chore: enable dead code lint rules
3733d6e: fix(anthropic): omit empty compaction blocks from replay
49295bb: feat(anthropic): add Claude Opus 5.5 support
49295bb: feat(anthropic): add Claude Opus 5.5 support
claude-opus-5-5 model ID to @ai-sdk/anthropic and anthropic/claude-opus-5.5 to @ai-sdk/gatewayclaude-opus-5-5, claude-fable-5, claude-fable-5-1) no longer receive thinking: { type: 'disabled' } or budget-based thinking; the provider drops the unsupported setting, maps reasoning: 'none' to effort: 'low', and emits a warningclaude-opus-5-5, claude-fable-5-1) fall back to auto tool choice for required and named tool choices, and to native structured outputs when structuredOutputMode: 'jsonTool' is requested, each with a warningcomputerToolset_20260801 computer use tool (computer_toolset_20260801), which is required for computer use on claude-opus-5-5mid-conversation-output-config-2026-07-01 beta header for per-message effortf7b7b2a: feat(provider/anthropic): add safeguards provider option and safeguardResults provider metadata (dangerous tool use classifier)
safeguards provider option and safeguardResults provider metadata (dangerous tool use classifier)### Patch Changes - Updated dependencies [2973485] - Updated dependencies [a4db5ea] - Updated dependencies [2937ea2] - @ai-sdk/provider-utils@5.0.45
### Patch Changes - Updated dependencies [0455398] - @ai-sdk/provider-utils@5.0.44
d4d96bf: Add anthropic.evaluationModel() for experimental Choice, Score, and Boolean evaluations through Messages structured output, with exact labels
anthropic.evaluationModel() for experimental Choice, Score, and Boolean evaluations through Messages structured output, with exact labels, validated score bounds, and prompted Boolean P(true) estimates validated to be in [0, 1]. Boolean estimates are not guaranteed to be calibrated; application code chooses thresholds.132bdae: feat(anthropic): add 20260318 web search and web fetch tools with response inclusion controls
### Patch Changes - Updated dependencies [5c0054d] - Updated dependencies [39535af] - @ai-sdk/provider@4.0.15 - @ai-sdk/provider-utils@5.0.41
5ec21a6: fix: reject unsupported batch request types
prefix_mismatch_behavior: 'error'5a7e647: feat(anthropic): add batch cancellation and listing
### Patch Changes - Updated dependencies [912fb01] - @ai-sdk/provider@4.0.12 - @ai-sdk/provider-utils@5.0.38
a4ba394: feat: support per-request models in batch
65397d7: fix(anthropic): recognize dated Google Vertex Claude 4 model IDs when selecting model capabilities
4d25a08: feat(anthropic): add fable 5.1 support
5190b67: feat(provider): extend the FilesV4 interface with optional getFileMetadata, downloadFile (streaming), and deleteFile operations, plus abortSi
getFileMetadata, downloadFile (streaming), and deleteFile operations, plus abortSignal/headers call options and a { type: 'stream' } upload data variant; upload results now expose byteSize, createdAt, and expiresAt (also surfaced by the core uploadFile() helper, which now forwards abortSignal/headers); add postMultipartStreamToApi (streaming multipart uploads with deterministic part ordering and failure-path stream teardown), deleteFromApi, and createBinaryStreamResponseHandler to provider-utilsaa45741: fix(provider/anthropic): preserve native message batch request counts in provider metadata and support the full language-model option surface
### Patch Changes - Updated dependencies [90192f1] - @ai-sdk/provider-utils@5.0.33
### Patch Changes - Updated dependencies [3e125ba] - @ai-sdk/provider-utils@5.0.32
591d25b: feat: add batch completion webhooks. experimental_startTextBatch accepts a webhookUrl, and the gateway provider registers it through the batc
experimental_startTextBatch accepts a webhookUrl, and the gateway provider registers it through the batch callbackUrl contract and exports typed async-job metadata. Direct Anthropic and OpenAI batch providers return an unsupported warning when the option is provided.### Patch Changes - Updated dependencies [b74971f] - @ai-sdk/provider-utils@5.0.29
### Patch Changes - Updated dependencies [e6087c9] - @ai-sdk/provider-utils@5.0.28
4579b08: Preserve Anthropic server-tool caller metadata in multi-turn conversations.
### Patch Changes - Updated dependencies [7fbfc6d] - @ai-sdk/provider-utils@5.0.27
### Patch Changes - Updated dependencies [401a4ba] - @ai-sdk/provider-utils@5.0.26
### Patch Changes - Updated dependencies [ad6a650] - Updated dependencies [81cd026] - @ai-sdk/provider@4.0.7 - @ai-sdk/provider-utils@5.0.25
### Patch Changes - Updated dependencies [1937bef] - @ai-sdk/provider-utils@5.0.24
e6415bd: feat(anthropic): add text batch support
### Patch Changes - Updated dependencies [3469d0c] - @ai-sdk/provider@4.0.6 - @ai-sdk/provider-utils@5.0.23
8b96941: Reject spliced Anthropic generations while allowing duplicate message start events for the active message.
### Patch Changes - Updated dependencies [1bec07d] - @ai-sdk/provider-utils@5.0.21
### Patch Changes - Updated dependencies [160ccdb] - @ai-sdk/provider-utils@5.0.20
9337ecd: Preserve Anthropic prompt-cache matches by replaying complete code-execution transcripts in their original wire shape.
### Patch Changes - Updated dependencies [5fc7da5] - Updated dependencies [93b2acd] - @ai-sdk/provider-utils@5.0.18
dc0c28e: Return visible summarized reasoning when generic reasoning enables adaptive thinking.
d8210b6: chore: centralize record type guards in provider-utils
### Patch Changes - Updated dependencies [1659cd5] - Updated dependencies [6a5bdff] - @ai-sdk/provider-utils@5.0.15
### Patch Changes - Updated dependencies [0c464d9] - Updated dependencies [c49380c] - @ai-sdk/provider-utils@5.0.14
### Patch Changes - Updated dependencies [1e2f324] - @ai-sdk/provider@4.0.4 - @ai-sdk/provider-utils@5.0.13
e29788d: fix(anthropic): report thinking tokens as reasoning token usage
cbdc990: feat (provider/anthropic): support fallbacks 'default' mode, which routes safety classifier refusals to Anthropic's recommended fallback mode
01a596a: fix (provider/anthropic): use current-generation capability defaults for unrecognized Claude model IDs while retaining conservative defaults
97de198: Warn when an unknown model uses the default 4096 max output token limit.
b72fc7c: fix(amazon-bedrock): sanitize unsupported JSON Schema constraints in native Anthropic structured output
afcf19c: fix(provider/anthropic): preserve web search citations when replaying assistant messages
### Patch Changes - Updated dependencies [31c7be8] - @ai-sdk/provider-utils@5.0.10
4be62c1: fix(provider-utils): validate provider-response URLs in getFromApi
4be62c1: fix(provider-utils): validate provider-response URLs in getFromApi
getFromApi now has a validateUrl flag. It is optional so existing callers keep compiling (omitting it behaves like false, i.e. no validation), but all AI SDK provider packages set it explicitly at every call site so each one makes a visible trust decision. When true, the URL is routed through fetchWithValidatedRedirects — the same guard used by downloadBlob — which rejects private/loopback/link-local targets, re-validates every redirect hop, strips proxy/metadata/cookie request headers, and drops all caller headers except the user-agent on cross-origin redirects (custom API-key headers must not follow a redirect off-origin any more than Authorization may); blocked URLs throw DownloadError. It is enabled at the image/video/audio download and polling call sites where the URL comes from a provider response body; URLs built from developer-configured endpoints pass validateUrl: false and are unaffected.
A new optional credentialedOrigin withholds caller headers unless the URL is same-origin with it, so the API key is not sent to a response-supplied host on a different origin.
A new optional trustedOrigin exempts URLs (and redirect hops) that are same-origin with the developer-configured provider endpoint from target validation, so self-hosted and localhost deployments whose response URLs point back at the configured host keep working; all other hops are still validated.
Also closes range gaps in validateDownloadUrl (IPv4 224.0.0.0/4 multicast and the TEST-NET documentation ranges 192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24; IPv6 documentation ranges 2001:db8::/32 and 3fff::/20), and follows only the fetch-spec redirect status codes (301/302/303/307/308) — a Location header on any other status is not followed. This guard performs string/literal checks only and does not resolve DNS; hostnames that resolve to private addresses and DNS rebinding remain out of scope and must be constrained at the network layer (or by injecting a Node fetch that pins the resolved IP at connect time) for server deployments handling untrusted URLs. See contributing/secure-url-handling.md.
cd12954: Reject empty OpenAI, Anthropic, and Replicate base URLs with a helpful AI SDK invalid argument error.
Updated dependencies [4be62c1]
Updated dependencies [7805e4a]
Updated dependencies [cd12954]
308a519: chore: enforce consistent imports from zod/v4 instead of zod
zod/v4 instead of zod### Patch Changes - Updated dependencies [0f93c57] - @ai-sdk/provider@4.0.3 - @ai-sdk/provider-utils@5.0.7
### Patch Changes - Updated dependencies [ac306ed] - @ai-sdk/provider-utils@5.0.6
2e45d9c: fix(anthropic): wrap invalid tool input in object
0aa0ff3: fix(anthropic): forward thinking: { type: 'disabled' } to the API instead of stripping it
0aa0ff3: fix(anthropic): forward thinking: { type: 'disabled' } to the API instead of stripping it
Previously, setting providerOptions.anthropic.thinking = { type: 'disabled' } (or top-level reasoning: 'none') was accepted by the schema but silently dropped from the outgoing request. For models that default thinking on (e.g. Sonnet 5), this left thinking enabled and could consume a small max_tokens budget entirely. The disabled value is now sent to the Anthropic Messages API.
Your coding agent can read these notes before it upgrades. Set up the MCP server →