Haystack
TL;DR
Haystack is deepset's open-source Python framework for LLM applications, built from components wired into pipelines with branches and loops. Its Agent component adds tool calling, lifecycle hooks and human confirmation of tool calls, and a coordinator agent can call specialist agents as tools. It suits teams building retrieval-heavy agents who want explicit data flow.
Key facts
| Type | Framework |
|---|---|
| Languages / SDKs | Python |
| License | Apache-2.0 |
| Pricing model | Open core |
| Orchestration pattern | Supervisor |
| GitHub stars | 26,632 (as of 2026-09-30) |
| GitHub forks | 3,208 |
| Last push | 2026-09-30 |
| Latest release | v3.2.0 |
| Repository | deepset-ai/haystack |
| Website | haystack.deepset.ai |
| Documentation | docs.haystack.deepset.ai |
| Last verified | 2026-09-30 |
Key features
- Pipelines connect components in a graph that can branch and loop, with visit counters and safety limits for cycles. (source)
- Agent component runs a tool-calling loop with a typed State shared by its tools. (source)
- Agent hooks (before_llm, before_tool, after_tool, on_exit and more) for guardrails, cost tracking and custom logic. (source)
- AgentTool wraps a specialist agent so a coordinator agent can delegate to it and receive only its final reply. (source)
- Human-in-the-loop ConfirmationHook lets a person confirm, reject or modify each tool call before it runs. (source)
- MCPTool and MCPToolset (mcp-haystack package) use tools from MCP servers over Streamable HTTP or stdio. (source)
- Pipeline breakpoints stop at a component, save a JSON snapshot, and resume from it. (source)
- Hayhooks serves pipelines and agents as REST endpoints, OpenAI-compatible chat endpoints or an MCP server. (source)
Architecture and orchestration pattern
Pattern: Supervisor
Everything is a component with typed inputs and outputs. A Pipeline connects components into a directed graph; a component reruns whenever all its required inputs arrive again, which is how loops and self-correction work, and routers add branching. The same Pipeline class runs synchronously, asynchronously or as a stream, and pipelines serialize to YAML.
The Agent component wraps a chat generator and tools and loops until an exit condition. For multiple agents, the documented pattern is a coordinator agent that calls specialist agents wrapped with AgentTool; the coordinator sees only each specialist's final reply. Agents can also sit inside larger pipelines.
Within one run, State holds typed values (messages, documents and custom fields) that tools read from and write to. Longer-term memory comes from integrations such as Mem0 memory stores and document stores, and compaction hooks trim long conversations. Pipeline breakpoints capture snapshots that can be edited and resumed.
Human in the loop
A ConfirmationHook registered under the Agent's before_tool hook point intercepts tool calls. A strategy (the built-in BlockingConfirmationStrategy) asks a person whether to confirm, reject or modify the call, a policy (AlwaysAskPolicy, AskOncePolicy, NeverAskPolicy) decides when to ask, and the built-in UIs are console prompts. Rejections are fed back to the model. Pipelines can also be paused with breakpoints and resumed from an edited snapshot; since 3.0, pausing inside an Agent is no longer supported.
Protocols
| Protocol | Support | Note |
|---|---|---|
| MCP | Yes evidence | Client via MCPTool/MCPToolset in the deepset-maintained mcp-haystack integration; Hayhooks can also expose pipelines and agents as an MCP server. |
| A2A | Unknown | Searched the full docs llms.txt, README, GitHub code search in haystack and haystack-core-integrations (hits were hex strings) and issues for a2a / agent2agent; nothing official found. |
| AG-UI | Unknown | Searched docs llms.txt, README, code search in haystack, haystack-core-integrations and hayhooks for ag-ui, and the AG-UI integration list; Haystack is not listed. |
Best for
- Retrieval-heavy agents where you want to control exactly what context reaches the model.
- Agents whose risky tool calls must be confirmed, rejected or edited by a person.
- Pipelines that loop for validation or self-correction and need step-level debugging with snapshots.
- Running on local models or self-managed infrastructure, with an optional paid managed platform.
Not for
- Teams that need a TypeScript or JVM SDK.
- Designs that need to pause and resume in the middle of an Agent's own loop (removed in 3.0).
- Peer-to-peer agent swarms without a coordinator.
Quickstart
pip install haystack-ai from haystack.components.agents import Agent
from haystack.components.generators.chat import OpenAIChatGenerator
from haystack.dataclasses import ChatMessage
from haystack.tools import AgentTool, tool
@tool
def word_count(text: str) -> int:
"""Count the words in a piece of text."""
return len(text.split())
editor = Agent(chat_generator=OpenAIChatGenerator(model="gpt-5.4-mini"), tools=[word_count],
system_prompt="Tighten drafts and report their word count.")
lead = Agent(chat_generator=OpenAIChatGenerator(model="gpt-5.4-mini"),
tools=[AgentTool(agent=editor, name="editor", description="Shortens a draft and counts words")],
system_prompt="Delegate editing to the editor, then summarize the result.")
result = lead.run(messages=[ChatMessage.from_user("Shorten: 'We are very, very happy to announce the release.'")])
print(result["last_message"].text)
Common pitfalls
- The package is
haystack-ai; Haystack 1.x (farm-haystack) is end of life. OpenAIChatGeneratorreadsOPENAI_API_KEYfrom the environment.- Optional features raise an ImportError that names the missing dependency to install (for example
pypdf). - MCP tools need the separate
mcp-haystackpackage. - 3.0 removed
ToolInvoker,AsyncPipelineand the legacy non-chat generators, and moved HITL tohaystack.hooks.human_in_the_loop; follow the migration guide. - Anonymous telemetry is on by default; set
HAYSTACK_TELEMETRY_ENABLED=Falseto opt out.
Pros
- Explicit, traceable data flow: retrieval, routing, memory and generation are separate components you wire yourself. (source)
- Breakpoints and editable JSON snapshots make it possible to debug and resume long pipelines. (source)
- Tool-level human review with confirm, reject and modify options and pluggable ask policies. (source)
- MCP works in both directions: MCPTool consumes servers and Hayhooks exposes pipelines as an MCP server. (source)
- Specialist agents can be serialized with the coordinator to YAML and loaded back. (source)
Cons
- Version 3.0 brought breaking changes: ToolInvoker, AsyncPipeline and the legacy generators were removed and HITL APIs moved. (source)
- Agent-level breakpoints were removed in 3.0, so execution can no longer pause and resume inside an Agent. (source)
- Anonymous usage telemetry is enabled by default and must be switched off explicitly. (source)
- MCP support is not in the core package; it requires the separate mcp-haystack integration. (source)
- Built-in human confirmation UIs are console prompts; web or chat UIs need a custom strategy or UI. (source)
Alternatives
FAQ
Does Haystack support MCP?
Yes. MCPTool and MCPToolset from the mcp-haystack integration connect agents to MCP servers over Streamable HTTP or stdio, and Hayhooks can serve Haystack pipelines and agents as an MCP server. A2A and AG-UI support were not found.
Is Haystack free?
The framework is Apache-2.0. deepset also sells the Haystack Enterprise Platform (managed or self-hosted) and Haystack Enterprise Starter support, with a free Studio tier and custom enterprise pricing on its pricing page.
How does Haystack build multi-agent systems?
A coordinator Agent receives specialist Agents wrapped with AgentTool as tools; it sends each specialist a task and gets back only the final reply.
Can a human approve Haystack agent actions?
Yes. A ConfirmationHook on the before_tool hook point lets a person confirm, reject or modify each tool call, with policies that decide when to ask.
What changed in Haystack 3.0?
The Agent gained a hooks system and owns tool execution; ToolInvoker, AsyncPipeline and legacy generators were removed, HITL moved to haystack.hooks.human_in_the_loop, and agent-level breakpoints were dropped.