Introducing Claude Sonnet 5

Jun 30, 2026

Claude Sonnet 5 is built to be the most agentic Sonnet model yet. It can make plans, use tools like browsers and terminals, and run autonomously at a level that, just a few months ago, required larger and more expensive models.

For many developers, the agentic AI era began with Sonnet-class models: Claude Sonnet 3.5, 3.6, and 3.7 were the first models that showed impressive skills in coding and tool use. More recently, though, the clearest gains in agentic capabilities have been in our Opus-class models.

Sonnet 5 narrows the gap: its performance is close to that of Opus 4.8, but at lower prices. It’s a substantial improvement over its predecessor, Sonnet 4.6, on important aspects of agentic performance like reasoning, tool use, coding, and knowledge work.

Our safety assessments found that Sonnet 5 shows an overall lower rate of undesirable behaviors than Sonnet 4.6, and is generally safer to use in agentic contexts. Evaluations also show that it has a much lower ability to perform cybersecurity tasks than our current Opus models.

From today, Claude Sonnet 5 is available across all plans: it is the default model for Free and Pro plans, and is available to Max, Team, and Enterprise users. It’s also available in Claude Code and on the Claude Platform, where it launches with introductory pricing of 10 per million output tokens through August 31, 2026, after which it will be priced at 15 per million output tokens. Developers can use claude-sonnet-5 via the Claude API.

Working with Claude Sonnet 5

Sonnet 5 (orange line) is a strict improvement over Sonnet 4.6 (gray line) and covers a much wider range of cost-performance options than Opus 4.8 (yellow line). It provides substantially improved cost efficiency at medium effort; its higher-effort performance can match Opus 4.8 on some tasks.

Early access partner feedback highlights that Sonnet 5 finishes complex tasks where previous Sonnet models would stop short, checks its own output without being asked, and does agentic work at an attractive price point. Deployments cited include Rakuten (multi-step software engineering), Zapier (end-to-end Salesforce and email automation), Lovable (safety refusals), Zed (unprompted bug reproduction and fix), Factory (sustained coding in complex codebases), and others.

Safety evaluations

On agentic safety, the model is better at refusing malicious requests and resisting hijack attempts in prompt injection attacks. The model shows lower rates of hallucination and sycophancy than Sonnet 4.6. On automated behavioral audit testing misaligned behaviors, Sonnet 5 scored lower (safer) overall than Sonnet 4.6, though somewhat higher than Mythos Preview and Opus 4.8.

Anthropic did not deliberately train Sonnet 5 on cybersecurity tasks. On Firefox 147 exploit development evaluations (developed with Mozilla), Sonnet 5 never developed a full working exploit (0.0% success) but showed a slightly higher partial success rate (13.2%) than Sonnet 4.6, attributed to general intelligence gains rather than cyber-specific training.

Sonnet 5 ships with cyber safeguards enabled by default — the same as Claude Opus 4.7 and 4.8, less strict than Fable 5 safeguards.

Availability and pricing

Claude Sonnet 5 is available everywhere today at an introductory price of 10 per million output tokens through August 31, 2026. Standard pricing thereafter: 15 per million output tokens. Rate limits increased across Chat, Cowork, Claude Code, and the Claude Platform.

Sonnet 5 uses an updated tokenizer (similar to Opus 4.7), so the same input can map to roughly 1.0–1.35× more tokens depending on content type. Introductory pricing is set so the transition is roughly cost-neutral.

Benchmark highlights from system card: SWE-bench Pro 63.2%, Terminal-Bench 2.1 80.4% (vs Sonnet 4.6 at 58.1% and 67.0%; Opus 4.8 at 69.2% and 82.7%).