Build on the SDK with a budget and a boundary
You will pick the right integration layer, define tool access and keep authentication in the sanctioned path. Outputs are illustrations.
Agent SDK and quickstart sources checked September 30, 2026 describe Python and TypeScript libraries that run the Claude Code agent loop in your process, with tools, hooks, subagents, MCP, permissions, sessions, skills and plugins. The SDK is a library, so your code owns the guardrails.
Pick the layer for the job
Interactive daily work belongs in the CLI. A product feature that calls an agent belongs in the Agent SDK. Direct API calls with your own tool loop belong in the Client SDK. Long-running hosted agents belong in Managed Agents. For another language, run the CLI as a subprocess with -p and --output-format json.
We want a tool that checks course chapters against their sources on demand.
Compare CLI script, Agent SDK and Managed Agents for this job.
Assume a small team, one language, no always-on requirement.
Return one recommendation with the deciding factors.
Illustrative decision:
Chosen: Agent SDK (TypeScript) behind an internal script.
Why: programmatic control, sessions resume, runs on demand.
Not chosen: Managed Agents (no always-on need), CLI wrapper (needs structured state).
Tools and permissions are your code's job
The SDK loads .claude/ and ~/.claude/ like the CLI unless you configure otherwise, so an agent in production can inherit personal hooks, MCP servers and memory. Set explicit configuration for a shipped tool: allowed tools, working directory and model, not whatever the developer's machine has.
Define the permission callback deliberately. Auto-approving everything is a product decision about your users' data; prompting through a callback that no one answers is a hang.
Authentication has a sanctioned shape
Anthropic does not allow third-party developers to offer claude.ai login or subscription rate limits in their products, including SDK agents. Use API key authentication as the quickstart describes. A product that quietly burns the developer's subscription is outside the terms and breaks when the developer leaves.
Branding and terms
Reference Claude honestly: "Powered by Claude" style naming is allowed; do not present your tool as "Claude Code" or mimic its branding. Commercial terms govern SDK use in products you give customers. A legal and naming review is part of shipping, not an afterthought.
Graded practice
Easy: layer
Match four needs to CLI, Agent SDK, Client SDK, Managed Agents. Success: deciding factor named.
Intermediate: config hygiene
List what .claude/ auto-loading could leak into production. Success: explicit config plan.
Challenging: auth
Explain why claude.ai login is not an option for your product. Success: sanctioned API-key path.
Troubleshooting
Agent behaves differently in prod: check inherited config from developer machines.
Run hangs: permission callback never resolves.
Cost spike: scope tasks and models; track per-run usage.
Works locally only: subprocess CLI path or missing API key in deployment.
Branding question: rename before shipping, not after a complaint.