
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
@langchain/langgraph-sdk
Advanced tools
@langchain/langgraph-sdkThe JavaScript / TypeScript SDK for talking to a LangGraph API server. Use it to create and manage assistants, threads, runs, cron schedules, and the KV store โ and, most importantly, to stream graph executions in real time.
๐ Full documentation
pnpm add @langchain/langgraph-sdk @langchain/core
# or: npm install @langchain/langgraph-sdk @langchain/core
# or: yarn add @langchain/langgraph-sdk @langchain/core
import { Client } from "@langchain/langgraph-sdk";
const client = new Client({ apiUrl: "http://localhost:2024" });
// Open a thread-centric stream (the recommended way to stream).
const thread = client.threads.stream({ assistantId: "my-agent" });
await thread.run.start({
input: { messages: [{ role: "user", content: "hello" }] },
});
for await (const message of thread.messages) {
for await (const token of message.text) {
process.stdout.write(token);
}
}
console.log(await thread.output);
await thread.close();
With no apiUrl, the SDK points at http://localhost:2024 (the
default langgraph dev URL).
| Sub-client | Purpose | Docs |
|---|---|---|
client.threads | Create threads, manage state, and stream runs. | Threads ยท Streaming |
client.assistants | CRUD for assistants (schemas, graphs, versions). | Assistants |
client.runs | Trigger / join / cancel runs without streaming. | Runs (legacy) |
client.crons | Schedule recurring runs. | Crons |
client.store | Namespaced KV + semantic store. | Store |
client.threads.stream(...) returns a ThreadStream
with typed, lazy projections for every aspect of a run:
thread.messages / thread.toolCalls โ assembled chat output.thread.values / thread.output โ graph state and final answer.thread.interrupts / thread.interrupted โ human-in-the-loop.thread.subgraphs / thread.subagents โ nested / deep-agent work.thread.extensions.<name> โ typed custom server projections.thread.audio / thread.images / thread.video / thread.files
โ media.Deprecated. The generator-based streaming APIs on
client.runs.*(stream,joinStream) andclient.threads.joinStreamare preserved for backwards compatibility only. New code should useclient.threads.stream(...). See Runs (legacy) for migration guidance.
Streaming defaults to Server-Sent Events (SSE) over HTTP. You can
switch to WebSocket per-call or globally, or plug in a custom
AgentServerAdapter:
const thread = client.threads.stream({
assistantId: "my-agent",
transport: "websocket",
});
See Transports for full details.
If you're building a UI, use the framework-specific packages that wrap this SDK:
@langchain/langgraph-sdk/react@langchain/langgraph-sdk/vue@langchain/langgraph-sdk/svelte@langchain/langgraph-sdk/angularUse the SDK directly when you need low-level control, run it from a non-browser environment (Node.js server, edge workers, scripts), or integrate into a framework that does not yet have a first-party adapter.
The client code is organized into sub-client modules under
src/client/:
| Path | Module |
|---|---|
client/assistants/ | AssistantsClient |
client/threads/ | ThreadsClient (includes the v2 stream(...) primitive) |
client/runs/ | RunsClient (legacy streaming + CRUD) |
client/crons/ | CronsClient |
client/store/ | StoreClient |
client/stream/ | ThreadStream, assemblers, transports |
client/base.ts | BaseClient, shared config & helpers |
client/index.ts | Main Client class & re-exports |
See CHANGELOG.md.
FAQs
Client library for interacting with the LangGraph API
The npm package @langchain/langgraph-sdk receives a total of 2,539,799 weekly downloads. As such, @langchain/langgraph-sdk popularity was classified as popular.
We found that @langchain/langgraph-sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago.ย It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.