v2.0.3
This release introduces Anthropic prompt caching, a deliver_artifact tool for sandboxed agents, a FinalAnswerFilterMiddleware for ReAct streams, state versioning and optimistic concurrency primitives for agent state stores, an AgentProtocolEventBus for pluggable SSE event handling, and a console transcript overhaul, and includes a broad set of reliability fixes across the core reasoning loop, harness, sandbox, and AG-UI protocol layers.
Quick links: Quickstart | V1 Migration Guide | Going to Production
Core / Agent
- Propagate
ToolResultBlock.metadatathrough fine-grained v2 tool-result events (ToolResultTextDeltaEvent/ToolResultDataDeltaEvent/ToolResultEndEvent) so event-stream consumers can access tool-specific context (#2315) - Introduce
AgentProtocolEventBusfor pluggable SSE event handling in the agent-protocol layer (#2634) - State versioning and optimistic concurrency primitives —
VersionedState,ConflictPolicy, andConcurrentSessionModificationException— enablingAgentStateStoreimplementations to detect and reject stale writes
Middleware
FinalAnswerFilterMiddleware— an opt-in filter that buffers text events per model call, suppresses intermediate reasoning-round text when a tool call is produced, and emits only the final user-facing answer (#2926, #2872)
Model Providers
- Anthropic prompt caching: set
cache_controlbreakpoints on tools, system, and the last message; surfacecache_read_input_tokensandcache_creation_input_tokensin usage (#2350, #2223) - Anthropic + Gemini
ResponseParserreadcachedTokensinto usage (#2568) - Explicit no-cache semantics:
CACHE_CONTROL=falsemetadata maps to{"type":"no_cache"}for OpenAI and DashScope converters, so a single message can opt out of caching (#2685, #2684)
Harness / Tools
deliver_artifacttool for sandboxed agents — anArtifactDeliveryTargetSPI + tool that lets an agent inside a sandbox hand out produced files; the workspace prompt now references it when a target is configured, and states plainly that no cross-boundary mechanism exists otherwise (#2667, #2663)- MCP server registration results — an optional
McpServerRegistrationListenerwithSUCCESS/FAILED/SKIPPEDterminal states, so host services can identify and retire unhealthy MCP configurations (#2877, #2875) descriptionfield onSubagentFactoryEntryso the orchestrator gets useful subagent selection context instead of a bare name (#1506, #1504)- Public
ToolkitAPI to assign an already-registered tool to an additional group (#2836, #2835) - Stream ranged file reads in
ReadFileTool— positive line ranges are read incrementally and stop at the requested end line, avoiding loading the full file into memory (#2402)
AG-UI
- CopilotKit + AG-UI full-stack example covering threads, shared state, generative UI, A2UI workbench, and HITL flows end-to-end (#2554)
- Configure agent interruption on AG-UI disconnect (#2719, #2715)
Console
- Transcript overhaul — one bubble per user question, with text and tool calls rendered as ordered content blocks in chronological order;
react-markdownrendering, syntax-highlighted tool I/O cards, SSE auto-reconnect with exponential backoff, andsession.errorrendering (#2640)
Examples
- User binding preferences CRUD API for the DataAgent example (#2711)
- v2 application-layer RAG example (#2794)
- Move
AguiRuntimeContextRequest/AguiRuntimeContextResolver/AguiRequestBodyParserdown from the example layer into theextensions-aguiprotocol layer (#2822) - Replace the Java service control plane with the Go
aistiodcontrol plane, keeping the Java gateway, data, and scheduler planes; theagentscope-builderexample is promoted to the top-levelagentscope-servicemodule - Isolate HITL sessions by user — key
ThreadSessionManager/AgentResolverby(userId, threadId)sohasMemoryand agent reuse no longer mix tenants, and unwrap harness/stop interrupts viaAguiUtil.asReActAgentso demostopThreadand processor interrupts target the live session (#2856, #2855)
Core / Agent
- Propagate
ChatResponse.metadatatoMsg.metadatainReasoningContext(#2931) - Propagate agent state load failures instead of silently replacing conversation state with a fresh session on backend / I/O / decoding errors (#2760)
- Preserve caller-supplied permission context when loading legacy v1 session state, so 1.x → 2.0 migration does not silently downgrade to
DEFAULTpermission mode (#2769, #2768) - Retry empty final responses instead of finishing silently when a reasoning model emits its answer into
reasoning_contentwith emptycontent(#2755, #2750) - Persist the current turn's user input and safe context on model call failure so a resumed session can see the last question (#2799)
- Reconcile dangling
tool_useblocks on interrupt before persistingAgentState, fixing a window between reasoning and acting where pending tool calls were left unmatched (#2410, #2409) - Return suspended results for external tools instead of converting them to generic errors; emit
RequireExternalExecutionEventfor suspended tool calls (#1668, #1582) - Emit
ExternalExecutionResultEventwhen external tool results resume (#2605) - Restore event emitter for detached tool calls (#2483)
- Include field path in tool validation error messages (#2718)
- Simplify
ReActAgentpending tool and error result handling (#2666) - Normalize model-call tools in middleware to avoid duplicate or malformed tool definitions (#2756)
- Avoid event-loop blocking in
WorkspaceContextMiddleware#onSystemPrompt(#2632) - Use call-scoped
AgentStateforReActAgentshutdown retry recovery so theshutdownInterruptedflag is checked and cleared against the per-session state for the current(userId, sessionId)call, instead of the default session state (#2712, #2708)
Model Providers
- Gemini: apply
ModelUtils.applyTimeoutAndRetryto response streams so configured timeout and retry settings take effect (#2356) - RAGFlow: preserve final retry response body so callers can read error details (#2631)
- RAGFlow: type
rerankIdasStringto match the RAGFlow API (#2776)
Harness / Tools / Sandbox
- Stop skill-cache orphan GC from deleting live directories (#2840, #2787)
- Make Nacos skill source paths Windows-safe (#2921)
- Make memory flush fire-and-forget to unblock conversation completion; add
HarnessBackgroundTaskQuiescenceExtensionso tests drain background flush before@TempDirteardown (#2777, #2935) - Handle
SIGTERMin Docker keep-alive to avoid 30s stop delay (#2885) - Bound filesystem search tool output size (#2832)
- Isolate sandbox binding per call to fix concurrent corruption (#2675)
- Make concurrent sandbox uploads safe — unique hydrate temp names and native transfer for relative paths (#2762)
- Fix Windows Docker sandbox session file upload via tar stream (#2557)
- E2B: preserve zero exit code in JSON stream (#2609); reject incomplete process streams without exit code (#2828); reset projection state when recreating sandbox (#2586)
- Kubernetes sandbox: bump fabric8 to 7.8.0 to fix watch NPE with Jackson 2.19+ (#2766); follow redirects so file API downloads survive gateway 307 (#2748)
- Keep persisted snapshot id when resume falls back to fresh create (#2775)
- Add reply IDs to subagent lifecycle events (#2680)
- Inherit memory config in subagents (#2611)
- Make orphan sweep timeout boundary inclusive (#2619)
- Do not downgrade a user-interrupted session to a compaction failure (#2659)
AG-UI
- Assign per-tool result message ids (#2908)
- Emit frontend tool args from fragment deltas (#2874)
- Isolate HITL sessions by user (#2856)
- Emit AG-UI interrupt for permission-type HITL tool confirmation (#2495, #2437)
- Parse request bodies with Jackson 2 codec for Boot 4 / multimodal
MessageContent(#2638) - Suppress
ReActAgenthandshake events in AG-UI converters (#2639) - Stop emitting
RUN_FINISHEDafterRUN_ERRORby default (#2646) - Cancel MVC subscription on disconnect (#2786)
Protocol
- Clear task submit context before publishing terminal status to close an
awaitrace inAgentProtocolTaskStore(#2802)
Storage
- MySQL: remove path-separator check from
MysqlAgentStateStoresession id validation (#2022)
Console / Frontend
v2.0.2
- feat(agent-protocol): route tasks through AgentFactory by @chickenlj in https://github.com/agentscope-ai/agentscope-java/pull/2590
- feat(harness): RuntimeContext force-sync for agent_spawn by @chickenlj in https://github.com/agentscope-ai/agentscope-java/pull/2592
- feat(harness): stamp parentSessionId on remote subagent events by @chickenlj in https://github.com/agentscope-ai/agentscope-java/pull/2593
- feat(agent-protocol): pass caller context attributes into task runs by @chickenlj in https://github.com/agentscope-ai/agentscope-java/pull/2595
- feat(channel): allow callers to pass RuntimeContext into Gateway by @chickenlj in https://github.com/agentscope-ai/agentscope-java/pull/2604
- feat(harness): forward the full remote subagent event stream by @chickenlj in https://github.com/agentscope-ai/agentscope-java/pull/2613
- feat(agent-protocol): decouple TaskStore from execution WorkspaceManager by @chickenlj in https://github.com/agentscope-ai/agentscope-java/pull/2615
v2.0.1
AgentScope Java 2.0.1 is the first maintenance release after 2.0.0 GA. It expands the model-provider ecosystem, hardens Harness subagent / HITL / permission behavior, and fixes a set of production-critical issues. Quick links: Quickstart | V1 Migration Guide | Going to Production
Core / Agent
- Middleware execution ordering via
MiddlewareBase.order()(higher values wrap outer);ReActAgent.Builder.build()stably sorts descending after all registrations (#2532, #2449) - Session context clear API on
ReActAgent/HarnessAgentto clear model-visible conversation context without creating a new session (#2499, #2496) - Expose
ReActAgentstate-cache cleanup APIs for long-lived instances (#2572) - Emit
UserConfirmResultEventwhen resuming permission HITL, correlatable with the priorRequireUserConfirmEventviareplyId(#2511) - Anthropic: support configuring
disable_parallel_tool_use(#2257)
Model Providers
- Add OpenAI-compatible extension package as a shared base for third-party compatible vendors (#2208)
- Add DeepSeek as a first-class model provider (
deepseek:<model>,DEEPSEEK_API_KEY) (#2307, #2211) - Add GLM (Zhipu AI) provider and dedicated formatters (#2316)
- Add Kimi (Moonshot AI) provider and dedicated formatters (#2320, #2213)
- Add MiniMax OpenAI-compatible provider (#2299)
Harness / Tools
- Remote subagent event streaming and HITL resume (#2559)
- Wait for async tool results by
taskId(#2529) - Default workspace via
AGENTSCOPE_WORKSPACEenv var for image packaging (#2310)
AG-UI
- Upgrade AG-UI module event mechanism (#2306, #2202)
- Introduce typed
MessageContent/InputContentfor multimodal AG-UI messages (#2518, #551)
Spring Boot Starters
- Change Toolkit default execution mode to parallel and improve related docs (#2558, follow-up of #2529)
- Abstract session metadata storage to decouple builders from concrete store implementations (#2258, #2068)
- Rebase Kubernetes sandbox store on agent-sandbox CRDs / controllers, with the cluster owning sandbox lifecycle and warm pools (#2308)
Core / Agent
- Prevent pending recovery from consuming HITL approvals (#2109, #2534)
- Apply transformed
onModelCalltext deltas to the final message so native structured-output parsing does not see stale text (#2469, #2385) - Repair null streaming tool args from complete raw JSON (#2451, #768)
- Unbind state-saver on
ReActAgent.close()to prevent graceful-shutdown registry growth / OOM (#2322, #2321) - Unbind
ShutdownStateSaveronReActAgent.close()to fix a memory leak (#2384) - Mark user interrupts with interrupted reason (#2260)
- Handle malformed Unicode when writing agent state files (
UnmappableCharacterException) (#2255, #2204) - Forward reasoning middleware events (e.g.
InboxMiddlewareHintBlockEvent) tostreamEvents()(#2179, #2160) - Mark
ToolResultBlock.erroras a structured error (#2174, #2157, #2111)
Model Providers
- DashScope: route
qwen3.8-maxto the multimodal endpoint (#2553) - DashScope: preserve SSE error response body so callers can read
request_id(#2278, #2197) - OpenAI: wrap streaming branch in
Flux.deferso retries re-issue HTTP requests (#2079) - OpenAI: terminate stream on
[DONE]sentinel (#2104) - OpenAI: drop non-chunk summary event messages to avoid content duplication (#2367)
- OpenAI: sanitize
namefield inOpenAIMessageConverter(#2346) - OpenAI AutoConfiguration: make api-key optional (#2175)
- DeepSeek formatter: preserve
systemrole (#2189, #2168) - Ollama: honor
streamflag inOllamaChatModel(#2415) - Anthropic: map
ToolChoice.Noneto disable tools (previously incorrectly forced tool use) (#2232, #2221) - Model provider optimizations and compatibility tweaks (#2474)
Harness / Tools / Sandbox
- Stamp
taskIdon remote subagent forwarded events (#2575) - Gate memory prompt guidance on disable flags (#2565)
- Emit subagent end before parent completion to avoid dropped events (#2544)
- Close subagent event stream when the parent is cancelled (#2481, #2480)
- Enforce parent DENY rules for spawned subagents (#2477)
- Preserve
RuntimeContextduring skill promotion (#2465) - Enforce Plan Mode for subagents (#2377)
- Reject workspace path traversal (e.g.
../) (#2358) - Support Windows local shell execution (working-directory commands and charset decoding) (#2304, #2268)
- Isolate static subagent registries by runtime context to prevent multi-tenant crosstalk (#2371, #2328)
- Retain prior summaries in chained compaction to preserve user intent (#2360)
- Preserve skill isolation and tool result history (#2319)
RemoteFilesystemrecursive glob matches files at the search root (#2343)- Mark optional FilesystemTool params as
required=false(#2227) - Optimize shell-execute
working_directoryparameter and tool usage hints (#2107) - Declared subagents inherit parent
modelExecutionConfig/toolExecutionConfig(#2252) - Correct
sessionIdparameter description (#2195)
Storage / Transport
v2.0.0
AgentScope Java 2.0.0 is now Generally Available. This is the first production-ready release of the 2.0 line, marking a milestone in AgentScope Java's evolution into an enterprise-grade harness framework.
Quick links: Quickstart | V1 Migration Guide | Going to Production
AgentScope Java 2.0 is a systematic upgrade centered on one goal: enabling agents to reliably complete tasks. Here is an overview of its core design:
Dual-Layer Agent Architecture
- ReActAgent: A stateless reasoning core providing the "reason → tool call → respond" ReAct loop. In 2.0, agent instances are fully stateless — all per-call mutable state is propagated via Reactor Context, allowing a single instance to safely serve multiple
(userId, sessionId)combinations concurrently - HarnessAgent: Extends ReActAgent through Middleware and Toolkit channels, adding workspace, memory, sandbox, subagents, skills, and plan mode as engineering infrastructure — the core reasoning loop is preserved, only augmented
Message & Event Stream
A unified ContentBlock message model (TextBlock / DataBlock / ToolUseBlock / ToolResultBlock / HintBlock, etc.) paired with streamEvents() emitting 28 typed AgentEvent types, making agent execution observable, interactive, and interruptible. Front-end UIs can follow text deltas, tool calls, user confirmations, and other lifecycle events in real time
Permission System
A new PermissionEngine establishes a three-state decision mechanism for tool calls: allow / require user approval / deny. Decisions are based on static rules, tool type, and input content analysis. Sensitive operations automatically enter a HITL approval flow
Middleware Extension Mechanism
A five-stage onion + pipeline hybrid model (onAgent / onReasoning / onActing / onModelCall / onSystemPrompt), providing flexible extension points for logging, tracing, security checks, business policies, and context injection while keeping the core framework stable
Context Engineering
Structured compaction preserves task objectives, current state, key findings, and next steps. Oversized tool results are automatically offloaded to disk with only placeholders in the context. File tools enforce a "read before edit" policy with built-in caching to reduce redundant IO
Workspace Abstraction
Decouples "what the agent does" from "where it executes." Local filesystem, Docker, Kubernetes, and E2B cloud sandbox backends are unified behind a single interface. A built-in warm-up pool supports parallel RL rollout scenarios
Model Fault Tolerance
A unified Credential + ModelRegistry abstraction covering Qwen / OpenAI / Anthropic / Gemini / DeepSeek / Ollama. Configurable max retries and fallback model — automatic failover when the primary model is unavailable
Enterprise Distributed Deployment
One-line DistributedBackend configuration (Redis / OSS / MySQL / PostgreSQL / COS). AgentStateStore auto-partitions by (userId, sessionId). Cross-replica session recovery, sandbox state snapshots, and subagent cross-replica routing
Protocol Interoperability
Built-in A2A (Agent-to-Agent) and MCP (Model Context Protocol) support, plus AG-UI protocol adaptation, covering standardized inter-agent communication and front-end rendering needs
Multi-Agent Orchestration
Declarative subagent specs (YAML / Markdown), runtime agent_spawn / agent_send with synchronous blocking and background delegation modes. Subagent event streams can be forwarded to the parent's streamEvents() in real time
Skill System
Four-layer skill composition (Classpath / FileSystem / Nacos / Marketplace) + SkillFilter fine-grained filtering + self-learning closed loop (propose → curate → promote)
The following are incremental changes between 2.0.0-RC5 (2026-07-07) and the GA release.
- Fire
AllToolsDeniedEventhook when HITL denies all tool calls, enabling application-level handling of full-denial scenarios (#2083) - Add guardrails for
wait_async_resultsto prevent repeated long blocking waits (#2093) - Add
PostgresDistributedStorefor PostgreSQL-backed distributed HarnessAgent state (#2054) - Add builder customizers for OpenAI, DashScope, and Anthropic models in Spring Boot starters (#2045)
Core / Agent
- Make
seedSystemMsgreactive to avoidblock()on NIO threads (#2086) - Include ASKING ToolUseBlocks in PERMISSION_ASKING result message (#2082)
- Activate SkillToolGroup via
activateOnSkillfield (#2057) - Save agent state on user interrupt to prevent session loss (#1970)
Model Providers
- Anthropic: split parallel tool calls into alternating messages to comply with API requirements (#2090)
- OpenAI: make
nativeStructuredOutputconfigurable (#2069)
Harness / Tools / Sandbox
- External tool execution now correctly produces a suspended result (#2071)
- Allow SkillLoadTool in Plan Mode by promoting
isReadOnlyto the AgentTool interface (#2067) - Interrupt orphan subagents when AgentSpawnTool parent subscription cancels (#2064)
- Remove unnecessary ReActAgent type restriction in MemoryFlushMiddleware (#2078)
- Resolve leading
/paths relative to workspace in ROOTED mode (#2049) - Pre-stage marketplace skills before workspace projection (#2059)
- Treat null exit code as success in Kubernetes
hydrateWithArchive(#1915) - Use updated WorkspaceSpec when resuming from persisted state (#1928)
- Support nested JSON and banner prefix in AgentRun MCP response (#1930)
- Use resolved workingDir for Docker workspaceRoot (#2033)
Channel
- Include PeerKind in OutboundAddress to fix group message routing (#2060)
A2A
- Merge streaming text chunks to avoid fragmentation (#2058)
v2.0.0-RC5
This release completes the model-provider modularization (all providers extracted from agentscope-core into independent agentscope-extensions-model-* modules), adds unified multimodal DataBlock support across all providers, introduces native structured output for tool calls, and includes 30+ bug fixes spanning agent lifecycle, sandbox, tracing, A2A, and subagent propagation.
- Model provider modularization: OpenAI, Gemini, Anthropic, DashScope, and Ollama model providers have been moved from
agentscope-coreinto separateagentscope-extensions-model-*extension modules. Applications must add the corresponding extension dependency. (#1890, #1916, #1947, #1972)
- Unified
DataBlocksupport in all provider message converters (OpenAI, DashScope, Gemini, Anthropic), covering single-agent, multi-agent, and tool-result paths (#1933) - Native structured output handling with tools — models that support structured output can now enforce JSON schema constraints alongside tool calls (#1904)
- Native structured output support for DashScope models (#1935)
httpRequestCustomizersupport inMcpClientBuilderfor dynamic token injection (e.g. OAuth refresh) (#1992)- Align
AguiEventwith the AG-UI protocol spec — add missing event types (#1862) - Optional skill allowlist filter for subagents (#1873)
knownSkillNamessupport inNacosSkillRepository(#1853)CosAgentStateStore,CosBaseStoreandCosDistributedStorefor Tencent Cloud COS-backed state persistence (#1857)- Expose cached prompt tokens in
ChatUsage(#1868)
- Persist agent state on user interrupt recovery (#2008)
- Wire fallback model into
ReActAgent(#1851) - Fix
ReActAgentstream event block end ordering (#1829) - Update
ToolResultBlockstate before adding to agent context (#1886) - Reuse classpath skill JAR file systems to avoid resource leaks (#1981)
- Resolve
serializeOnKeygate leak inFlux.createcallbacks (#1796)
- Map
thinkingBudgetto OpenAI-compatible API request (#2028) - Fix Anthropic stream thinking event handling (#1943)
- Preserve
executionConfiginOllamaOptionsfromOptions/toBuilder(#2011) - Degrade forced tool choice in DashScope thinking mode (#1882)
- Restore remote snapshot state deserialization — re-inject
RemoteSnapshotClientafter Jackson round-trip (#2013) - Fix THROTTLED memory save mode losing state when recreating instances per request (#1788)
- Propagate
userIdthrough wakeup dispatch (#2001) - Run message bus heartbeat on
boundedElasticinstead ofparallelscheduler (#1974) - Avoid duplicating
GracefulShutdownMiddlewareinfromAgent(#1952) - Escape spaces in skill paths returned by
ShellPathPolicy(#2031) - Fallback to simple key-value extraction when YAML parsing fails (#2027)
- Report sandbox file sizes in
ls(#1838) - Normalize Windows
list_filespaths (#1892) - Normalize
\r\nto\nfor file content inLocalFilesystem.edit()(#2020) - Treat
"."as root equivalent inCompositeFilesystem(#1830) - Validate
working_directoryto prevent namespace escape (#1834) - Fall back to
LocalFilesystemSpecwhen no distributedAgentStateStoreis configured (#1841) - Fix WebSocket race in Kubernetes
hydrateWithArchivecausingexit=null(#1903) - Tolerate wrapped sandbox base64 downloads (#1866)
- Remove
AgentRunsandbox API version prefix (#1891) - Add connect JSON codec support for E2B sandbox (#1844)
- Fix orphan spans in
OtelTracingMiddlewareby reading parent OTel Context from ReactorContextView(#1940) - Fix child spans not seeing correct parent spans in
OtelTracingMiddleware(#1909) - Propagate Reactor context to chunk event hooks (#1923)
- Propagate parent
RuntimeContextto child agents (#1833) - Propagate parent middleware to subagents (#1843)
- Handle streaming backpressure (#1734)
- Preserve AgentScope message roles across A2A conversion (#1995)
- Propagate run input and frontend tools (#1895)
- Wrap
doFlushinMono.deferto prevent premature evaluation (#1880)
- Nacos auto-configurations should be opt-in (
matchIfMissing=false) and fix A2A server-addr override (#1709) - Add
ObjectMapperbean forMarketContributionServicein DataAgent (#1993)
- Clarify stream event
blockIdsemantics (#2016) - Improve model provider documentation (#1986)
- Remove invalid
ChatResponse.isLastreferences (#1921) - Fix multi-replica Redis example — declare jedis dependency and add
stateStore(#1869) - Fix
MemoryCompactionExampleto show memory files and fire compaction (#1978)
v2.0.0-RC4
This release introduces async tool execution and notification support for the agent harness, adds a persistent spawn registry for subagent session recovery, and includes some critical bugfixes.
- Agent harness now supports async tool execution and notifications, including message bus, async tool registry, and scheduled wakeup dispatching (#1802)
- Added String/Message convenience overloads for agent calls; all formatters now support HintBlock (#1802)
- Persistent spawn registry in tool context state enables subagent cross-replica routing and session recovery (#1817)
- DynamicSkillMiddleware implements ToolkitAware to receive the resolved toolkit dynamically (#1828)
- Kubernetes sandbox now supports injecting environment variables into pods (#1789)
- Fixed SIGKILL race condition in Kubernetes file uploads by using two-phase archive strategy (#1826)
- Fixed resource leak where timed-out sub-agents were not interrupted on retry (#1784)
- Fixed typed attributes being lost when copying RuntimeContext (#1813)
- Fixed JdbcStore table initialization failure under MySQL utf8mb4 charset (#1781)
- Made session JSONL offload idempotent to prevent duplicate writes (#1774)
- Fixed OpenTelemetry context propagation in TelemetryTracer (#1799)
- Fixed NPE in OllamaChatModel when options are null during tool choice retrieval (#1803)
- Added missing Jackson annotations to LocalSandboxSnapshot for proper serialization (#1825)
- Fixed sandbox glob not supporting
**/recursive patterns (#1684) - Fixed SkillFilter matching using composite ID instead of skill name (#1771)
- Allow custom default vision model in MultiModalTool (#1701)
v2.0.0-RC3
Please check the documentation for more details.
- Agent result event — a new event is emitted with the final result immediately before agent-end, so
streamEvents()consumers can obtain the result directly from the event stream - Custom events — generic extensible event type for middleware to push application-level notifications (state changes, team updates, etc.) to front-end subscribers without modifying the core event enum
- Hint block events — one-shot event for delivering complete content such as team messages, background tool results, and user interruptions
- Workspace path normalizer — file paths are now automatically normalized to workspace-relative form based on the active filesystem mode, preventing cross-mode prefix collisions
- Tool name on all tool events — tool call delta, end, and result events now carry the tool name directly, so consumers no longer need to cache the name mapping from the start event
- Unified call / stream core —
call()andstreamEvents()now share a single implementation, ensuring the middleware chain fires consistently on all invocation paths. Legacy standalone call logic has been removed - Distributed state always fresh — when a state store is configured, agent state and permissions are reloaded from the store at the start of every call, preventing stale cache reads when sessions drift across machines
- Tool result eviction timing — eviction middleware moved to the correct lifecycle phase where tool results are already persisted, fixing a no-op issue in the previous phase
- Simplified file path resolution logic in local filesystem
v2.0.0-RC2
Please check the documentation for more details.
- Qwen 3.7 model support — added support for Qwen 3.7 series models (e.g.
qwen3.7-plus) - Direct subagent messaging — send messages directly to a spawned subagent and receive its response without going through the parent agent's reasoning loop
- Subagent event stream forwarding — child agent intermediate events (text deltas, tool calls, etc.) are now forwarded in real time, each carrying a source path identifying the originating agent
- Event source tracking — all agent events now carry a
sourcefield to distinguish main vs. subagent events within the same stream, enabling consumer-side demuxing - Custom model and prompt for Compaction / Memory — compaction and memory extraction now support dedicated lightweight models and custom prompts, independent of the agent's primary model
- Channel integration — new extension module family for IM platform integration (DingTalk, Feishu/Lark, WeCom, GitHub, GitLab), with a built-in ChatUI for an out-of-the-box conversational interface
- Unified distributed backend — new single-point configuration that consolidates all distributed storage components (state store, base store, sandbox snapshot) into one setup call. Built-in implementations for Redis, OSS, and MySQL
- Project-writable mode — when enabled, agent file writes are routed by path: workspace metadata goes to the workspace directory; everything else (code, configs) lands in the project directory. Designed for code-generation agents
- Runtime permission mode switching — dynamically adjust the permission mode per session at runtime
- Plan Mode improvements — improved plan file persistence and recovery, smoother tool-chain interaction, more robust approval flow
- Skill self-evolution enhancements — refined the propose → curate → promote closed loop, improved skill matching accuracy and cross-session reuse
- HTTP client timeout and retry policy adjustments
- Model resolution logic improvements
- Agent state records more running statuses
- Agent fully stateless — agents no longer hold mutable per-session state, a single agent instance can safely serve multiple concurrent sessions
- Unified state store — removed legacy session interfaces; unified on a new
AgentStateStoreabstraction with built-in in-memory, JSON file, Redis, and MySQL implementations, auto-partitioned by user and session - Base store package renamed — base store interfaces for RemoteFilesystem moved to a new package; update your import paths accordingly
- Extension module coordinates refactored — several extension Maven coordinates have been reorganized by capability (e.g.
agentscope-extensions-session-redis→agentscope-extensions-redis). Update<artifactId>in your POM - Sandbox implementations extracted — concrete sandbox backends (Docker, Kubernetes, E2B, Daytona, AgentRun) moved from harness core into standalone extension modules. Add the corresponding extension explicitly if you need sandbox support
- Fixed permission state losing context during cross-session restoration
- Fixed
agentscope-allmissing 4 sandbox extension modules
v2.0.0-RC1
AgentScope Java steps up from a "build an agent" toolkit toward a complete platform for running agents in production.
2.0 aims to preserve compatibility with 1.x where possible so that most users can upgrade smoothly — see the Migration Guide below.
Full docs: docs/v2/en, docs/v2/zh · Full changelog: change-log.md
🧰 Harness engineering — the harness scaffolding for long-running tasks, layered on top of the ReAct core:
- Self-evolving Markdown skill repository under
workspace/skills/, shared across sessions - Layered memory: in-context conversation /
MEMORY.md/ append-only fact log, with auto-compaction - Sub-agents declared in Markdown, spawned sync or in background; completions pushed back via
system-reminder - Plan Mode + persistent
workspace/plans/to decouple intent from action - Workspace as the single on-disk source of persona, knowledge, skills, sub-agent specs
🏢 Enterprise-grade distributed deployment — stateless horizontal scaling out of the box:
session/user/agent/orgmulti-tenant isolation viaAbstractFilesystem- Sandbox execution (local / Docker / remote AgentRun) with snapshot & resume
- Three-state
PermissionEngine(allow / approve / deny) with HITL as a first-class concern Sessionabstraction (InMemory/JsonSession/ MySQL / Redis) for zero-downtime rolling deploys
⚙️ Foundation framework upgrade — leaner, more orthogonal core:
agent.streamEvents()→Flux<AgentEvent>covering 28 typed events (model calls, deltas, tool execution, HITL)- Unified
ContentBlockmessage model with role-strict construction - Five-stage
Middleware(onAgent/onReasoning/onActing/onModelCall/onSystemPrompt) replaces v1 hooks ModelRegistryresolves"provider:model"strings; Builder gains.maxRetries(int)/.fallbackModel(...)for auto-retry
<dependency>
<groupId>io.agentscope</groupId>
<artifactId>agentscope-harness</artifactId>
<version>2.0.0-RC1</version>
</dependency>
var agent = HarnessAgent.builder()
.name("coder")
.model("qwen-max")
.workspace(Paths.get(".agentscope/workspace"))
.filesystem(new DockerFilesystemSpec().isolationScope(IsolationScope.USER))
.build();
agent.call(msg, RuntimeContext.builder().sessionId("demo").userId("alice").build()).block();
ReActAgent.Builder.memory(...)/.statePersistence(...)removed →.session(...).sessionKey(...);Sessionauto save/load on everycall()io.agentscope.core.session.SessionManagerremoved → configureSession+SessionKeyon the builderio.agentscope.core.pipeline.*(Pipeline,SequentialPipeline,FanoutPipeline,MsgHub) removed → middleware + sub-agents + event streamio.agentscope.core.model.tts.*(14 files) removed → integrate upstream TTS SDK directlystatepackage restructure:AgentMetaState→AgentState;StateModule/StatePersistenceremoved;ToolkitStatemoved tosession.legacyMsgcontent is now validated againstroleat construction (USERallows only Text/Data/Image/Audio/Video;SYSTEMonly Text) → preferUserMessage/AssistantMessage/SystemMessage/ToolResultMessage
SkillBox→AgentSkillRepositoryviaBuilder.skillRepository(...)- Entire
io.agentscope.core.hookpackage →Middleware(old hooks bridged viaLegacyHookDispatcher) Memoryand all implementations →AgentState.getContext()+Session- All
Flux<Event> stream(...)overloads →streamEvents()returningFlux<AgentEvent>(aligns with Python 2.0'sreply_stream()) - RAG (
Knowledge/KnowledgeRetrievalTools/RAGMode) and long-term memory modules deprecated — being rewritten on the v2 architecture; don't depend on them in new code tool.coding.*/tool.file.*deprecated (no workspace/permission isolation) → use theagentscope-harnessequivalents
v1.1.0-RC2
- Harness subagents —
HarnessAgentcan delegate work to ephemeral child agents viaagent_spawn/agent_send. Declarations come fromSubagentDeclaration,workspace/subagents/*.md, built-ingeneral-purpose, or custom factories; remote HTTP subagents are supported. - Async subagents — Set
timeout_seconds=0to run subagent tasks in the background. Task state is persisted in the workspace and managed withtask_output,task_list, andtask_cancel. - Subagent streaming — When the parent uses
stream(), synchronous local subagents forward reasoning, tool, and result events into the parentFlux<Event>withEventSourcemetadata. Nested subagents are supported;call()keeps the previous blocking behavior. - Tool strict mode — Tools can be configured with strict JSON-schema validation for more reliable model tool calls.
- MCP protocol versions —
McpClientBuilderexposesprotocolVersionsfor explicit MCP protocol negotiation.
- DashScope multimodal tool results — Multimodal content parts in tool results are preserved instead of being dropped.
- OpenAI rate-limit retries — Non-standard rate-limit error payloads are parsed correctly so automatic retries can trigger.
- Subagent runtime context —
RuntimeContext(e.g.userId) propagates from parent tool calls into child agents for consistent isolation. - Glob matching — File globs match both workspace-root files and nested paths (e.g.
*.md,*.log.jsonl). - Skill state APIs — Added methods to set skill states programmatically.
- Improved model tool-call handling; E2E support for Qwen 3.5 series models; dependency bumps (PostgreSQL, Micronaut, OpenTelemetry semconv, zstd-jni).