Download Latest Version v1.1.2 source code.zip (3.8 MB) Google Add to Preferred Sources
Home / v1.1.0
Name Modified Size InfoDownloads / Week
Parent folder
README.md 2026-09-24 4.0 kB
v1.1.0 source code.tar.gz 2026-09-24 2.7 MB
v1.1.0 source code.zip 2026-09-24 3.6 MB
Totals: 3 Items   6.3 MB 3

v1.1.0

TypeSafe Jev support! — decision-only agents

AG2 now supports TypeSafe's Jev, a model that doesn't generate text. You send it state and a typed question, and it answers — yes or no, which option, what score — with a probability distribution attached.

A decision agent is an ordinary agent, and the response schema you ask for is the question:

:::python
router = Agent("router", config=TypeSafeConfig(), response_schema=Department)
reply = await router.ask("Our webhook integration has been returning 502s since Monday.")

A bool becomes a yes/no, an Enum of strings becomes a choice, an IntEnum with described levels becomes a score. Anything else raises locally, before a request goes out. The probabilities and confidence land on ModelMessage.metadata, so you can branch on how sure the model was rather than only on what it picked. Tools are rejected — Jev decides, it doesn't call things — and streaming isn't supported.

pip install "ag2[typesafe]"

Thanks to @stepacool for building the provider.

Security

Reserved context variables no longer cross the wire. ConversationContext.variables held framework control-plane state — approval bypasses, context IDs, tenant overrides — alongside your own data, and four transports synced that dictionary with remote peers. A caller able to write a reserved key could therefore pre-approve a gated tool, and the human was never asked. The reserved ag: and a2a: prefixes are now stripped in both directions across A2A, AG-UI, A2UI and NLIP: inbound, dropped keys are logged as a warning; outbound, they are removed before transmission.

Also in this release

  • MessageEnqueued — ConversationContext.enqueue() now announces a transient event after appending to an agent's inbox, so a live session can react between model responses. The calling API is unchanged.
  • MCP errors follow the spec. Prompts with required arguments are validated before rendering, and protocol-level failures return the prescribed JSON-RPC codes instead of a generic error or a tool result flagged isError.
  • A shared event descriptor could retarget under concurrency, leaving a tool awaiting a result that never matched. Seen as intermittent worker-thread hangs on Windows CI.
  • Provider payloads are built from the SDKs' own param types, with the remaining mappers under strict mypy. SDK drift — a renamed, removed or narrowed field — now fails in CI rather than arriving as a provider 400 in front of a user.

What's Changed

Full Changelog: https://github.com/ag2ai/ag2/compare/v1.0.6...v1.1.0

Source: README.md, updated 2026-09-24