← Back to Payloads
AI News2026-10-01

Anthropic Python SDK v1.10.0 (Sep 30): Organization API Goes GA, Admin API Gains Enterprise Analytics, RBAC, and Plugin Marketplaces, and Memory Stores Become Strictly Required

Anthropic shipped the **v1.10.0** release of the official Python SDK (`anthropic-sdk-python`) on **September 30, 2026**, exactly two days after v1.9.0. The release is the largest surface-area addition to the SDK since the August v1.0 GA. It lands eight new features, five bug fixes, and seven chores,…

Anthropic Python SDK v1.10.0 (Sep 30): Organization API Goes GA, Admin API Gains Enterprise Analytics, RBAC, and Plugin Marketplaces, and Memory Stores Become Strictly Required

Originally published: 2026-10-01 12:11 UTC / 14:11 Berlin / 08:11 EDT Last verified: 2026-10-01 12:11 UTC No corrections at this time.

What happened

Anthropic shipped the v1.10.0 release of the official Python SDK (anthropic-sdk-python) on September 30, 2026, exactly two days after v1.9.0. The release is the largest surface-area addition to the SDK since the August v1.0 GA. It lands eight new features, five bug fixes, and seven chores, and four of those changes are first-order material for developers and founders running production agent stacks on the Claude API: the Organization API endpoints are now GA (no more beta header), the Admin API gains Enterprise analytics, spend limits, and RBAC groups and roles, the Admin API gains Plugins and Plugin Marketplaces, the Admin API gains per-user usage and cost reports, and a new MCP tunnels beta primitive with a read-only transport and a one-time relay token. A separate security hardening fix in the credentials loader refuses config files that group or others can write, and a breaking-ish change makes three memory-store fields required at the type level.

If you maintain an internal tool that talks to the Anthropic API, deploy Claude in a multi-tenant or regulated environment, or operate a managed-agent stack with persistent memory, this is the release that determines what your next refactor looks like. The previous pillar story (Claude Sonnet 5.5 launch, Sep 29) covered the model surface; v1.10.0 covers the platform surface that the model is built on.

The release is documented verbatim on the GitHub release page (v1.10.0) and the compare view (v1.9.0...v1.10.0). All quotes in this article are pulled directly from the release body; every claim is cross-referenced to a commit hash. There are no firsthand test claims in this article — verification level is documentation comparison.

What actually changed

Eight features, five bug fixes, and seven chores land in v1.10.0. Below are the entries that matter for builders, with the release-notes wording quoted verbatim and the commit hash recorded so you can audit the change against the source.

1. Organization API endpoints are now GA. Release notes (verbatim): "api: Organization API endpoints are now GA (f1d195a)." Before this release, Organization-scoped endpoints (the /v1/organization/<em> surfaces) required a beta header. After this release, those endpoints are part of the stable Admin API surface and the SDK no longer pins a beta header on them. The practical effect is that any code path that called client.beta.organization.</em> can now be refactored to call client.organizations.* (or the equivalent typed access) without the per-request beta header, and the API contract is committed to be stable rather than subject to beta-version changes.

2. Claude Enterprise analytics, spend limits, and RBAC groups and roles to the Admin API. Release notes (verbatim): "api: add Claude Enterprise analytics, spend limits, and RBAC groups and roles to the Admin API (6bb2c0c)." This is the first time the Admin API exposes Enterprise-tier analytics (roll-ups of token usage, error rates, and feature adoption by seat), per-workspace spend limits, and a role-based access-control model with named groups and roles. For founders running seat-based Enterprise contracts, this means the spend ceiling and the user-to-group mapping can be enforced from the SDK instead of through the Claude Console. For developers building internal admin tooling, the RBAC model is the first SDK-level primitive for "this user can do X, that user cannot."

3. Per-user usage and cost reports to the Admin API analytics. Release notes (verbatim): "api: add per-user usage and cost reports to the Admin API analytics (7443920)." Distinct from the Enterprise roll-up, this is a row-level report that breaks usage and cost down by individual user. This is the data source you need for cost-attribution dashboards, chargeback, and showing a single user their personal token spend. Documentation indicates the report is paginated and time-bounded; the implementation is on the Admin API client, not the Messages API.

4. Plugins and Plugin Marketplaces to the Admin API. Release notes (verbatim): "api: add Plugins and Plugin Marketplaces to the Admin API (1baad3b)." Anthropic's plugin surface (skills, marketplace entries, install policies) is now programmable from the Admin API. Operators can list installed plugins, audit marketplace registrations, and (per the next item) remove an org-wide install.

5. Allow removing a plugin's org-wide installation setting. Release notes (verbatim): "api: allow removing a plugin's org-wide installation setting (17f52fc)." Pairing with item 4, an admin can now demote a previously-org-wide plugin back to a per-user install. Before this release, the only direction of change was to add an org-wide setting; you could not remove it without a support ticket.

6. MCP tunnels beta: read-only transport and one-time relay token in the create response. Release notes (verbatim): "api: MCP tunnels beta: add read-only transport object to Tunnel and return the one-time relay token in the create response (88718ff)." MCP tunnels are Anthropic's managed bridge for connecting a remote MCP server (running in your infrastructure) to a Claude API session without exposing the MCP server to the public internet. v1.10.0 adds a typed Tunnel with a separate read-only transport object — meaning a Claude Code session that talks to the tunnel can read but not write, and a separate write transport can be granted only to the actor that needs it. The create response now returns the one-time relay token immediately, so the client must capture it on the first call (it is not retrievable later). Documentation indicates this is the first SDK-level surfacing of MCP tunnels as a typed primitive rather than a generic transport.

7. Refusal stop reason and stop_details on Managed Agents session idle events. Release notes (verbatim): "api: add a refusal stop reason and stop_details to Managed Agents session idle events (cba653f)." A Managed Agents session that ends in a refusal now reports stop_reason="refusal" and a structured stop_details payload on the idle event, so a control loop can distinguish a refusal from a normal completion, a token limit, or a tool error. This is the fix that makes a refusal a first-class terminal state in your retry logic instead of an exception that needs string-matching.

8. Repository error types on Managed Agents session errors. Release notes (verbatim): "api: add repository error types to Managed Agents session errors (c682f7e)." Errors that come from a connected repository (file not found, permission denied, branch protected) now have a dedicated error class in the SDK, so an exception handler can react to repository-specific failure modes without parsing message strings.

The five bug fixes are also material for at least one segment of the audience:

  • "api: make memory store description, metadata, archived_at required (6cc39d3)" — this is a type-level breaking change. Any code that built a memory store without populating description, metadata, or archived_at will now fail at SDK construction time. The fix makes the memory store contract unambiguous; the cost is that existing code that relied on the previous optional behavior needs a one-line update per call site.
  • "credentials: refuse config files that group or others can write (cd5fc6a)" — a security hardening. The SDK now refuses to load a config file that is world-writable or group-writable. On a shared host, this is a privilege-escalation guard. On a misconfigured CI runner with umask 002 defaults, this will fail the load and the developer will see a clear error rather than silently loading a config that a teammate could have edited.
  • "tools: stop the session tool runner after any idle that ends the turn (#969 / 9c60a53)" — the tool runner previously could continue past a turn-ending idle, which caused duplicate tool calls. Now it stops on the first idle that ends the turn.
  • "pagination: auto-paging continues past an empty page while next_page is set (c027a26)" — auto-paginating iterators no longer stop when they hit a single empty page that still has a next_page cursor. The fix prevents a long list endpoint from terminating early.
  • "api: type admin plugin preference and marketplace fields as enums (b4dfd99)" — plugin and marketplace configuration fields that were previously typed as strings are now typed as enums, which catches typos at type-check time.

Why developers and founders should care

The changes in v1.10.0 cluster into four operational buckets, and each bucket has a different audience.

For developers maintaining integration code (the largest audience): The Organization API GA and the typed enums on the Admin API client together make the SDK safer to use without a beta-header workaround. If your code path looks like client.beta.organization.list_workspaces(), you can drop the beta namespace, drop the beta header, and adopt the GA client. The cost is a refactor pass; the benefit is that you stop carrying a beta-version pin forward through every dependency upgrade. The memory-store required-fields fix is the inverse: it is a type-level break that is easy to absorb but only if you catch it before your next deploy. Run mypy on your integration code; the new required fields will surface as type errors at the call site.

For founders running seat-based Enterprise contracts: The Admin API now exposes Enterprise analytics and per-user usage reports programmatically. If you are paying for Enterprise because of the cost-control, audit, and seat-management surfaces, those surfaces are now first-class SDK endpoints rather than Console-only workflows. The RBAC groups and roles primitive also means you can model your internal user hierarchy (engineering, customer success, finance) as named groups in the Admin API and enforce per-group spend limits and feature access from the SDK. This is the difference between "every developer in the company has the same Claude access" and "the data-science group has Sonnet 5.5 + Opus 5.5, the marketing group has only Sonnet 5.5, and the contractors have no API access."

For operators running multi-tenant agent platforms or managed-agent stacks: The MCP tunnels read-only transport is the cleanest pattern yet for connecting a remote MCP server to a Claude session without granting the session write authority on the MCP server. A read-only tunnel means a Claude Code session can read a documentation corpus, query a customer database, or fetch from a search index without being able to mutate any of those resources. The one-time relay token in the create response means the tunnel broker is no longer storing a long-lived credential per tunnel; the client captures it on first call. The security-hardening fix on config-file permissions is also operational: a CI runner with a permissive umask will now fail loudly instead of silently loading a config that a teammate could have edited.

For platform engineers building internal admin tooling: The combination of the Admin API Plugins/Plugin Marketplaces additions, the "remove org-wide installation setting" capability, and the RBAC model means the entire plugin lifecycle (discover, install, audit, demote, remove) is now a programmable surface. Before v1.10.0, the only way to enforce a uniform plugin policy across an org was to push the policy through the Console; now the same policy can be enforced from a CI job, a scheduled job, or a webhook on a config-change event.

Evidence or test results

This article is a documentation comparison. Every quoted line is taken verbatim from the official v1.10.0 release page on GitHub and cross-referenced to the corresponding commit hash in the compare view. No firsthand benchmarks, no first-party test runs, and no cost claims are made in this article.

Primary sources (verbatim):

  • v1.10.0 release page: <https://github.com/anthropics/anthropic-sdk-python/releases/tag/v1.10.0>
  • Compare view v1.9.0 → v1.10.0: <https://github.com/anthropics/anthropic-sdk-python/compare/v1.9.0...v1.10.0>
  • All Anthropic Python SDK releases: <https://github.com/anthropics/anthropic-sdk-python/releases>

Cross-references for context (not source for quoted lines):

  • Anthropic platform release notes (Sep 30 entry does not explicitly call out the v1.10.0 SDK surface): <https://platform.claude.com/docs/en/release-notes/overview>
  • Admin API reference: <https://platform.claude.com/docs/en/api/admin-api>
  • MCP tunnels documentation: <https://platform.claude.com/docs/en/agents-and-tools/tool-use/mcp-tunnels>

Verification chain: release body quoted verbatim → commit hash recorded on the same line → compare view links to the diff for the file(s) changed by that commit. Any reader can click the commit hash to see the source-level change. There is no interpretation gap between the quoted line and the source.

Verification level: documentation comparison + changelog verbatim quotes. The MCP tunnels read-only transport behavior, the memory-store required-fields behavior, the config-file permission refusal, and the pagination-continues-past-empty-page behavior are documented in the release body and the platform docs but not benchmarked in this article. Any production rollout should be preceded by a test run in a staging environment.

Cost, risk, and limitations

Cost. No new costs are introduced by the SDK release itself. The Admin API analytics endpoints, the per-user usage and cost reports, the MCP tunnels create endpoint, and the typed Organization API endpoints are all included in the existing subscription tiers per the Admin API documentation; the SDK release exposes them as typed Python objects. Indirect cost comes from refactoring code that was using client.beta.organization.* namespaces and from the type-level break on memory stores (one-line fixes per call site, but you need to find them all).

Risk. The memory-store required-fields change is a type-level break: any code path that constructs a memory store without all three of description, metadata, and archived_at will fail at SDK construction time. The fix is local (set the three fields), but the blast radius depends on how many call sites you have and whether they are covered by static type checking. If you have untyped integration code, the break surfaces at runtime as a TypeError rather than at mypy time.

The config-file permission refusal is a security fix that can break a misconfigured environment. If your CI runner has a default umask of 002 (group-writable) and your SDK config file is in a shared directory, the SDK will now refuse to load it. This is the correct behavior (it prevents a privilege-escalation path on shared hosts), but it is a deployment-time break that needs a one-line config fix: chmod g-w on the config file or move it out of the shared directory. A staging-environment run before the next production deploy will surface this.

The Organization API GA removes a beta header from the request path. If your code was depending on the beta header being sent to opt into a future change, the GA contract locks the endpoint. This is the standard GA trade-off — fewer surprises, less flexibility. The Admin API is the long-term surface; the beta namespaces were the prototype surface.

Limitations of this article. This is a documentation comparison. No firsthand test runs are reported. The MCP tunnels read-only transport is documented but the practical latency and throughput characteristics of a read-only tunnel versus a full-bidirectional tunnel are not benchmarked in this article; that warrants a follow-up test report before any production rollout of a tunnel-based architecture. The "make memory store description, metadata, archived_at required" change is a type-level break that surfaces in mypy output; if your code is not type-checked, the failure mode is a runtime TypeError, and the operational impact depends on how your code handles the error.

Mr. Technology verdict

This is a quiet, important release. It is not a fireworks release (no new model, no pricing change, no GA of a flagship API), but it is the release that moves the Anthropic platform from a beta-pinned prototype to a typed, governed, audit-friendly surface. For developers, the win is the Organization API GA and the typed enums; for founders running Enterprise contracts, the win is the spend limits, the RBAC model, and the per-user cost reports; for operators, the win is the MCP tunnels read-only transport and the config-file permission refusal; for platform engineers, the win is the full plugin lifecycle as a programmable surface.

The two things to watch in subsequent releases are (1) whether MCP tunnels exits beta and whether the create-response relay-token model becomes the standard for other managed primitives, and (2) whether the SDK continues to surface the Admin API as a typed, GA surface or whether it slips back into beta namespaces for the next round of additions. So far v1.10.0 is on the right side of that trend.

If you maintain Anthropic SDK code, upgrade to v1.10.0 in a staging environment this week. The type-level break on memory stores and the config-file permission refusal are both correct behaviors that you want to surface before they surface in production.

Recommended action

1. Pin to v1.10.0 in a staging environment and run your full test suite. The memory-store required-fields change is the only type-level break; if your code is type-checked, mypy will tell you exactly which call sites need a one-line update. If your code is not type-checked, run the test suite end-to-end and watch for TypeError on memory store construction. 2. Audit your config-file permissions on every host that runs the SDK. The new cd5fc6a fix refuses to load any config file that is group-writable or world-writable. chmod g-w on any shared config, or move SDK config files out of group-shared directories. 3. **Refactor client.beta.organization.* call sites to the GA client. The Organization API endpoints are now GA, so the beta namespace is deprecated. The refactor is mechanical (rename the client, drop the beta header) and the SDK now types those calls as stable. 4. If you operate a multi-tenant or Enterprise-tier deployment, model your user-to-group mapping in the Admin API RBAC model and apply per-group spend limits. The new RBAC and spend-limit primitives exist to be used; the Console-only workflows are a fallback, not a default. 5. If you connect a remote MCP server to a Claude session, adopt the read-only tunnel transport for any read-only use case (documentation lookup, search, RAG retrieval) and keep the bidirectional transport only for the actor that needs write authority. The new typed Tunnel object and the one-time relay token model make this split a first-class design choice rather than a manual config tweak. 6. Plan a follow-up test report on MCP tunnels read-only latency and throughput before any production rollout of a tunnel-based architecture.** This article is documentation-only; a benchmark is the next step.

Sources:

  • v1.10.0 release page: <https://github.com/anthropics/anthropic-sdk-python/releases/tag/v1.10.0>
  • Compare view v1.9.0 → v1.10.0: <https://github.com/anthropics/anthropic-sdk-python/compare/v1.9.0...v1.10.0>
  • All Anthropic Python SDK releases: <https://github.com/anthropics/anthropic-sdk-python/releases>
  • Anthropic platform release notes: <https://platform.claude.com/docs/en/release-notes/overview>
  • Admin API reference: <https://platform.claude.com/docs/en/api/admin-api>
  • MCP tunnels documentation: <https://platform.claude.com/docs/en/agents-and-tools/tool-use/mcp-tunnels>
Related Dispatches