Google ADK Review 2026: Free Framework, Real Runtime Costs, and Three Security Disclosures Worth Knowing About
If your mental model of Google's Agent Development Kit is "the free agent framework Google shipped in 2025," that's true but incomplete on three fronts: ADK 2.0 rebuilt its execution model around a graph engine in May 2026, the Vertex AI platform it deploys into was renamed Gemini Enterprise Agent Platform two months earlier, and three real, disclosed vulnerabilities hit ADK's own tooling surface between June and August 2026. This review covers what actually changed, what it costs once you deploy for real, and whether the security record should give a production team pause.
| Framework price | $0, Apache 2.0 |
| Current version (Python) | google-adk 2.9.2 |
| Languages | Python, Go, Java, TS, Kotlin |
| GitHub stars (live) | 21,583 |
| 2026 security disclosures | 3, real & dated |
ADK is genuinely serious engineering. "Free" is true of the framework, not of what running it actually costs.
"ADK is one of the more technically credible agent frameworks available in 2026 — free, Apache-licensed, model-agnostic despite the Gemini branding, and the only major framework here with native support for both MCP and the A2A protocol at once. But the moment you deploy for real, you're paying Google's usage-based Agent Runtime plus separate model-token costs, and you're trusting a fast-moving SDK that had three real, disclosed vulnerabilities against its own tooling in 2026. Neither fact is a dealbreaker by itself. Together, they mean ADK deserves a more careful look than 'it's free and Google made it.'"
The distribution story is straightforward: ADK is Google's default on-ramp for anyone building agents on Gemini or Google Cloud, and it now speaks two open, multi-vendor protocols (MCP and A2A) natively, so you're not locked into Google's ecosystem the way you might expect. What's changed since launch is that ADK graduated from "interesting April 2025 announcement" into production-shaped infrastructure — with a production-shaped attack surface and a production-shaped bill to match.
A code-first framework, a graph-based runtime, a local dev UI, and four ways to deploy.
ADK is not a hosted product you sign into — it's a library you pip install (or the Go/Java/TypeScript/Kotlin equivalent) and write agents against directly in code. You define agents, the tools they can call, and how they hand off work to each other; ADK's Workflow Runtime executes that as a graph of nodes — agents, tools, and functions — rather than a single linear chat loop. A built-in local web UI (adk web) lets you chat with your agent and inspect every tool call and reasoning step while you build.
The practical read: ADK is infrastructure, not a product with a login screen. That's exactly why the pricing and security questions later in this review matter more than they would for a SaaS tool — you're the one who decides where it runs and who's accountable when something goes wrong.
The real signal isn't seats — it's who else is building on the same protocol.
adk-python, live on GitHub, Sep 22, 2026.
adk-python, live, Sep 22, 2026.
pypistats.org direct read, Sep 22, 2026.
Linux Foundation governance, incl. AWS, Microsoft.
| Date | What happened |
|---|---|
| Apr 9, 2025 | ADK and the A2A protocol announced at Google Cloud NEXT 2025 |
| May 2025 | Python ADK reaches v1.0.0 stable at Google I/O 2025 |
| Jun 23, 2025 | A2A donated to the Linux Foundation; vendor-neutral governance begins |
| Feb 27, 2026 | ADK Tools & Integrations Ecosystem announced (GitHub, Jira, MongoDB, 5 observability platforms) |
| Apr 22, 2026 | Vertex AI renamed Gemini Enterprise Agent Platform; Agent Engine renamed Agent Runtime |
| May 19, 2026 | ADK 2.0 GA: graph-based Workflow Runtime + Task API replace the hierarchical executor |
| Jun 30, 2026 | Go ADK reaches v2.1.0 GA |
| Jun-Aug 2026 | Three real security disclosures against ADK's tooling surface; publicly confirmed fixed Aug 4, 2026 |
The evidence base here is genuinely thin — and that itself is worth knowing.
"ADK feels like a serious framework for people who want to build real agents, not just quick demos" — but "may be more framework than you need for a simple chatbot or one-off automation."
The orchestrator-worker multi-agent pattern "became the pattern the rest of the industry converged on," and ToolConfirmation is "the difference between an agent you can ship to production and one you cannot."
A model he built against (gemini-2.0-flash-exp) was deprecated within the year: "anything you publish about a specific model name has a fixed shelf life."
The framework is $0. Where you run it is where the real bill starts.
Apache 2.0. No tiers, no seats, ever.
Runs on your laptop; adk web for local debugging.
Self-managed; you already know this bill if you use GCP.
Free under 50 vCPU-h + 100 GiB-h/mo/account.
Source: github.com/google/adk-python (license), pypi.org/project/google-adk (version), cloud.google.com/vertex-ai/pricing (Agent Runtime rates, page itself now uses "Agent Runtime"/"Gemini Enterprise" naming), verified Sep 22, 2026. Full breakdown of Agent Runtime line items in the Economics section below.
Pick a deployment path by how "managed" you want the bill to be, not by the framework price.
Run it on your laptop with
adk web. That's genuinely $0 beyond your own machine.Deploy there — same code, standard compute pricing you already understand.
Agent Runtime: $0.085/vCPU-h + $0.009/GiB-h, with a real monthly free tier.
Read the Security section below before you wire ADK's own CI/tooling patterns into your pipeline, not just before you trust the agents it produces.
Worth comparing against LangGraph before committing — see Alternatives.
ADK 2.0 rebuilt agent execution around a graph, not a chat loop.
Through 2025, ADK ran agents through a hierarchical executor: a root agent that could delegate to sub-agents, evaluated roughly in sequence. ADK 2.0, GA around May 19, 2026, replaced that with a graph-based Workflow Runtime: agents, tools, and functions are all nodes in a graph, wired together with explicit routing, fan-out/fan-in, loops, retries, and human-in-the-loop checkpoints. A companion Task API adds structured agent-to-agent delegation — multi-turn task mode, single-turn controlled output, and mixed delegation patterns — so one agent can hand a task to another with a defined contract instead of an open-ended chat message.
- Graph execution makes routing, retries, and loops explicit instead of implicit in prompt text — easier to reason about and test.
- ToolConfirmation gives you a real human-approval checkpoint before a sensitive tool call fires, not just a logging line.
- The same graph code is what ADK now ships to Cloud Run, GKE, or Agent Runtime — no rewrite between dev and deploy.
- This is a genuine architectural rewrite (hierarchical executor to graph engine) less than a year old — expect rough edges relative to a framework that's been graph-based for years.
- Named-model references in your code have a real shelf life, per the one-year retrospective above — plan for model-deprecation maintenance, not a "write once" agent.
From a defined problem to a reviewed output, with an explicit human checkpoint.
Not applicable — and that's a deliberate scope boundary, not a gap.
NOT_APPLICABLE: ADK is a code-first backend framework for building agents, not a browser-automation or computer-use product, and it has no native browser/UI-automation surface of its own. An ADK agent can reach browser automation the same way it reaches any other capability — by calling an MCP tool that wraps a browser-automation server — but that's a composed capability, not something ADK ships. Documented here explicitly rather than silently dropped.
The only framework in this comparison set with both protocols natively.
ADK's McpToolset implements the client side of the Model Context Protocol, so an agent can call tools and read resources from any MCP-compliant server over stdio, SSE, or streamable HTTP — and ADK can expose its own tools as an MCP server for other developers or agents to consume. Separately, the A2A protocol (which Google introduced alongside ADK and donated to the Linux Foundation in June 2025) lets an ADK agent hand work to an agent built on a completely different framework, using a shared, vendor-neutral message format. On Feb 27, 2026, Google expanded ADK's curated integrations ecosystem well beyond Google's own stack.
| Category | Curated integrations added Feb 27, 2026 |
|---|---|
| Code platforms | GitHub, GitLab |
| Project management | Jira, Linear, Asana, Notion, Atlassian |
| Data stores | MongoDB, Pinecone, Chroma |
| Observability | Arize, MLflow, AgentOps, Datadog, plus OpenTelemetry-native telemetry across 5 platforms |
Official Google Cloud Tech video covering the Feb 2026 integrations expansion referenced directly above.
Published by the official "Google Cloud Tech" YouTube channel (youtube.com/@googlecloudtech).
Three cost lines, not one, once you're actually running agents.
| Cost line | Rate | Free allowance |
|---|---|---|
| Agent Compute (Agent Runtime) | $0.085 / vCPU-hour | 50 vCPU-hours / month / account |
| Agent Memory (Agent Runtime) | $0.009 / GiB-hour | 100 GiB-hours / month / account |
| Agent Search | ~$1.50-$4.00 / 1,000 queries | None disclosed |
| Sessions / Memory Bank storage | ~$0.30 / GiB-month | None disclosed |
| Model tokens (Gemini, or others via LiteLLM) | Priced separately per model | Depends on model/provider |
Three real vulnerabilities were found and fixed in 2026 — worth reading before you wire ADK into your own CI.
- Issued a real CVE (CVE-2026-79707) with a clear affected-version range and a fixed version, rather than a quiet patch.
- Removed the vulnerable CI workflows outright rather than attempting a partial in-place fix.
- Paid a bounty on the dev-assistant finding once researchers demonstrated real impact.
- Google's first response to the dev-assistant report was to dispute it — worth knowing if you're deciding how much to trust ADK's own security triage by default.
- Independent researchers frame the root cause (untrusted content crossing into privileged framework/CI logic) as a pattern also found in LangChain, LangGraph, and CrewAI in 2026 — not unique to ADK, but also not yet a settled, mature area industry-wide.
Teams already building multi-agent systems on Google's stack get the clearest win.
| Situation | Why ADK fits | Real cost consideration |
|---|---|---|
| Already on Google Cloud/Gemini, building multi-agent systems | Native Agent Runtime deploy path; graph engine built for orchestration | Usage-based Agent Runtime bill, not a flat price |
| Need both MCP tool access and cross-vendor A2A messaging | Only framework here with first-class native support for both | $0 framework cost either way |
| Polyglot engineering org, not just Python | 5 language SDKs (Python/Go/Java/TS/Kotlin) with real parity | Same Agent Runtime economics regardless of language |
| Regulated or security-conservative team | Apache 2.0, transparent CVE process, real incident timeline | Review the 2026 disclosure history before adopting ADK's own CI/tooling patterns |
| Solo dev building one simple chatbot | Probably more framework than you need — per the one review found | A lighter single-purpose tool may cost less time to learn |
Four real gaps, not manufactured ones.
One star-rated review (n=1) and a handful of long-form developer blogs is a real gap versus the deep G2/Capterra sentiment base commercial SaaS competitors carry — a direct consequence of ADK being free infrastructure, but a genuine limit on how confidently anyone can characterize "what users think" at scale.
Three real, disclosed vulnerabilities in one year against ADK's own tooling surface (not just theoretical risk in agents you build) — including one Google initially disputed before fixing. Not disqualifying, but worth weighing before trusting ADK's CI/dev-tooling defaults out of the box.
Framework price ($0) plus compute plus memory plus search plus storage plus separate model tokens is harder to budget upfront than a flat SaaS seat price — you need to actually model your usage before you know what you'll pay.
ADK 2.0's shift from a hierarchical executor to a graph-based Workflow Runtime (GA ~May 2026) is a real improvement, but it's young relative to graph-native frameworks like LangGraph that have run this model for years — plus named-model references in your code have a documented short shelf life.
If ADK's trade-offs don't fit, here's how to think about it.
| If you mostly need... | Compare ADK with... |
|---|---|
| The most battle-tested-at-massive-scale option today | LangGraph — read our review |
| The fastest path from idea to a working prototype | CrewAI — read our review |
| A framework matched to an all-Microsoft/Azure stack | Microsoft Agent Framework / Semantic Kernel (learn.microsoft.com) |
| The simplest option if you're fully committed to OpenAI models | OpenAI Agents SDK (platform.openai.com) |
No affiliate relationship shapes this review — there isn't one to have.
Google does not run a publisher affiliate program for ADK; it's free, open-source software. Every CTA here points to the official docs, the official repo, or Google's own official pricing page for the paid managed layer.
Go to the official docs or repo.
Open ADK DocsRead the alternative that matches your real question.
Choose the next articleADK makes the most sense measured against the frameworks and platforms it shares a decision budget with.
Questions people are actually searching right now
Is Google ADK free?
Yes — the framework itself is Apache 2.0 open source with no license fee, seat price, or usage cap. What costs money is the compute you deploy it on, and, if you use Google's managed layer, Agent Runtime's usage-based billing ($0.085/vCPU-hour, $0.009/GiB-hour, with a real monthly free tier), plus separate model-token costs.
What changed in ADK 2.0?
ADK 2.0 (GA around May 19, 2026) replaced the original hierarchical agent executor with a graph-based Workflow Runtime, where agents, tools, and functions are nodes in an explicit graph with routing, fan-out/fan-in, loops, and retries, plus a new Task API for structured agent-to-agent delegation.
What happened to Vertex AI and Agent Engine?
At Google Cloud Next 2026 (April 22, 2026), Google renamed Vertex AI to the Gemini Enterprise Agent Platform and folded in Agentspace; the managed agent-hosting layer, Agent Engine, was renamed Agent Runtime. Existing SDKs, APIs, and billing kept working with no breaking change.
Does ADK support MCP and A2A?
Yes, natively for both. ADK's McpToolset can consume any MCP-compliant server and can also expose ADK's own tools as an MCP server. A2A is the agent-to-agent protocol Google introduced alongside ADK and donated to the Linux Foundation in June 2025; it now has 100+ supporting companies, including direct cloud competitors like AWS and Microsoft.
Is Google ADK secure?
Three real vulnerabilities were disclosed against ADK's own tooling surface in 2026: a CVSS-8.7 path-traversal CVE in the builder endpoint (fixed in 1.22.0+), an unauthenticated dev-assistant endpoint Google initially disputed before bountying and partially fixing, and a CI/CD privilege-escalation bug fixed by removing three GitHub Actions workflows (confirmed fixed Aug 4, 2026). Independent researchers note the same defect pattern also hit LangChain, LangGraph, and CrewAI in 2026 — it's not unique to ADK, but it is real and recent.
How much does it cost to run an ADK agent in production?
There's no single number — it depends on where you deploy. Self-hosted on Cloud Run/GKE, you pay standard Google Cloud compute plus model tokens. On the managed Agent Runtime, you additionally pay $0.085/vCPU-hour and $0.009/GiB-hour (with monthly free allowances), plus metered Agent Search and Sessions/Memory Bank storage if you use them.
Is Google ADK better than LangGraph or CrewAI?
Different trade-offs: LangGraph is generally cited as more battle-tested at large production scale; CrewAI is faster for rapid prototyping with a role-based abstraction; ADK differentiates on native dual MCP+A2A protocol support, the broadest language coverage (5 languages), and a direct managed-deployment path into Google Cloud. See our LangGraph and CrewAI reviews for the direct comparisons.
What languages does ADK support?
Five, per official adk.dev documentation: Python, Go, Java, TypeScript, and Kotlin, with Python (google-adk on PyPI) as the most mature and most-downloaded implementation.
Where this came from, and when it was checked.
License, version, languages, repo stats: github.com/google/adk-python (GitHub), pypi.org/project/google-adk, and adk.dev — official, checked directly, Sep 22, 2026.
ADK 2.0 graph engine, Task API, release history: adk-python releases page and requesty.ai/zenml.io independent technical comparisons, cross-checked against official docs.
Vertex AI to Gemini Enterprise Agent Platform rebrand, Agent Engine to Agent Runtime: official Google Cloud Next 2026 coverage (hpcwire.com/aiwire) plus direct confirmation that cloud.google.com/vertex-ai/pricing and docs.cloud.google.com/gemini-enterprise-agent-platform/build/adk now use the new naming.
Agent Runtime pricing: cloud.google.com/vertex-ai/pricing, official, checked directly for Agent Compute ($0.085/vCPU-h) and Agent Memory ($0.009/GiB-h) line items, Sep 22, 2026; Agent Search and storage rates cross-checked via cloudzero.com, same date.
MCP support: google.github.io/adk-docs/mcp/ (redirects to adk.dev), official.
A2A protocol donation and governance: linuxfoundation.org official press release (Jun 23, 2025) and opensource.googleblog.com official one-year retrospective (Apr 2026).
Integrations ecosystem expansion: developers.googleblog.com official announcement, Feb 27, 2026.
2026 security disclosures: official CVE record for CVE-2026-79707 (app.opencve.io), google/adk-python GitHub issue #5603, thehackernews.com coverage of the CI-workflow removal with Google's own commit/verification timeline, and drel.ai independent security analysis.
User sentiment: slashdot.org software listing (1 verified review, disclosed as thin evidence) and benpoole.me independent one-year developer retrospective.
Real screenshots/media: raw.githubusercontent.com (logo, adk-web-dev-ui.png), storage.googleapis.com (Google Developers Blog banner and architecture diagram), avatars.githubusercontent.com (Google org avatar).
Official video: youtube.com/watch?v=nId1rrAIEx4, authorship confirmed on YouTube (author "Google Cloud Tech", channel @googlecloudtech).
