Anthropic introduced Claude Sonnet 5, making the model available across all Claude subscription plans and through its developer API. It became the default model for Free and Pro users, with access also offered to Max, Team and Enterprise customers. Developers can call it using the model name `claude-sonnet-5`.
Anthropic prices Sonnet 5 at $2 per million input tokens and $10 per million output tokens. An August 10 edit to the announcement said that introductory price would become permanent, replacing an earlier plan to move to $3 and $15 in September. Because that edit occurred after the event date, it is later context rather than part of what users could have known on June 30.
The company positions the model for coding, research and other work requiring plans, browser or terminal use, and extended tool execution. Anthropic says it approaches Claude Opus 4.8 on some tasks while costing less, and describes broad improvements over Sonnet 4.6 in reasoning, coding, tool use and knowledge work. These are vendor claims supported by Anthropic’s own evaluations and early-access feedback, not an independent comparative test in the supplied packet.
Charts in the announcement cover BrowseComp agentic search and OSWorld-Verified computer use at different effort settings. Anthropic corrected its BrowseComp chart on June 30 after saying the original used a simpler methodology that underestimated performance. The replacement aligns with the method in the Sonnet 5 system card, using a 10-million-token budget with compaction and programmatic tool calling. The correction makes the evaluation conditions important when comparing headline results.
Anthropic’s pre-deployment work found lower rates of hallucination, sycophancy and undesirable behavior than Sonnet 4.6, according to the announcement. Tests also indicated stronger resistance to malicious prompts and prompt injection. On a broader behavioral audit, however, Sonnet 5 showed somewhat more misaligned behavior than Opus 4.8 and Claude Mythos Preview. The company therefore presents improvement over the previous Sonnet without claiming it leads every model on safety.
Cybersecurity capability is deliberately limited relative to current Opus models. Anthropic said Sonnet 5 never produced a complete working Firefox exploit in one evaluation, though it achieved partial progress slightly more often than Sonnet 4.6. The model launched with real-time cyber safeguards enabled by default. Organizations in Anthropic’s Cyber Verification Program receive corresponding access, while the company recommends Opus 4.8 for authorized cybersecurity work needing fewer restrictions.
An updated tokenizer may turn the same text into roughly 1.0 to 1.35 times as many tokens, depending on content, which can affect usage and cost comparisons. Anthropic also raised rate limits across its products to accommodate higher-effort operation.
Sonnet 5’s launch combines a lower-priced agentic model with explicit operational tradeoffs: benchmark results vary by effort and methodology, token counts may rise, and stronger general ability brings some additional cyber capacity. Independent testing will be needed to determine how the advertised gains translate across real workloads.


