title: "Claude Cowork Pricing 2026: Plans, Real Limits, Opus 5" slug: "claude-cowork-pricing-and-agent-ecosystem-2026" date: "2026-08-05" author: "O-mega Team" category: "AI Tools & Pricing" excerpt: "Verified August 2026 Claude Cowork pricing: every plan and limit, Team seats from 2, the Opus 5 shift, and what your Claude subscription does not include." seoTitle: "Claude Cowork Pricing 2026: Plans, Limits & Opus 5" seoDescription: "Verified August 2026 Claude Cowork pricing: every plan, Team seats from 2, real usage limits, the Opus 5 shift, and what your subscription does not include." tags:
- "Claude Cowork"
- "AI Pricing"
- "Claude Plans"
- "Opus 5"
- "2026 Guide"
Every Claude Cowork plan, every real limit, and what changed with Opus 5: verified against Anthropic's live pages on August 5, 2026
Claude Cowork is included in every paid Claude plan, with no separate fee, starting at the $20/month Pro plan. Here is every tier, verified against Anthropic's live pricing page on August 5, 2026:
| Plan | Monthly | Annual | Cowork Access | What the Tier Buys |
|---|---|---|---|---|
| Free | $0 | - | No | Chat only, basic limits |
| Pro | $20/mo | $17/mo ($200 upfront) | Yes | Code, Cowork, Design, Science, Research, Microsoft 365 |
| Max | from $100/mo | - | Yes | Choose 5x or 20x more usage than Pro |
| Team Standard | $25/seat | $20/seat | Yes | Teams of 2 to 150, more usage than Pro per seat |
| Team Premium | $125/seat | $100/seat | Yes | Teams of 2 to 150, 5x Standard usage per seat |
| Enterprise (self-serve) | Custom | Custom | Yes | Online plan creation, org admin controls |
| Enterprise (sales-assisted) | Custom | Custom | Yes | SSO, custom retention, HIPAA-ready, Claude Security |
Three things in that table changed since most pricing pages (including the July version of this one) were written. Team plans now start at 2 seats, not the 5-seat minimum that older coverage still lists. The Max card now reads "From $100, choose 5x or 20x more usage than Pro" rather than printing two separate prices. And the model doing the work changed on July 24, 2026, when Claude Opus 5 became the default on Max and the strongest model on Pro - Anthropic. Everything below unpacks what those numbers actually buy: the shared quota mechanics, the weekly caps, the Fable 5 carve-outs, the Sonnet 5 price cliff on August 31, and where the competition sits. This is the pricing and limits reference; for a ground-up product introduction, our Cowork starter guide covers the interface and first sessions, and our top 10 Cowork alternatives guide covers the full competitive field.
Contents
- Every Claude Plan, Verified August 2026
- What Your Subscription Does Not Include
- How the Shared Quota Actually Meters You
- The Opus 5 Shift: What Changed on July 24
- The Model Price List Behind the Subscription
- Pay-Per-Use and the Paused Credit Overhaul
- Permission Modes: Manual, Auto, Skip
- Where Cowork Runs Now, and What July Added
- Reliability Per Dollar: OSWorld-Verified vs Vendor Numbers
- What Cowork Competes Against on Price
- Which Plan to Buy: The Decision Framework
1. Every Claude Plan, Verified August 2026
Pricing is where stale articles do the most damage, because the numbers look plausible long after they stop being true. Third-party pages that rank for this query still describe a macOS-only product, a $30 Team plan, and a 5-seat minimum, all of which are now wrong. Every figure in this section was read directly off claude.com/pricing on August 5, 2026, and where the page is ambiguous, this guide says so instead of guessing.
The entry point is unchanged: Pro at $20/month, or $17/month billed annually as a $200 upfront payment. The pricing page lists "Includes Claude Cowork" as one of Pro's additions over Free, which means the old rule still holds: Cowork requires at least Pro, and there is no Cowork trial on the free tier. What the $20 buys has quietly kept widening. The Pro card now bundles Claude Code, Claude Cowork, Claude Design, Claude Science, unlimited projects, Research, access to more Claude models, and the Claude for Microsoft 365 integration in one subscription. Measured per bundled capability, Pro delivers several times what the January version of the same $20 delivered, which is the practical result of Anthropic's capacity expansion covered in section 3.
Max is the individual power tier, and its presentation changed. The card now reads "From $100 per month" with a choice of 5x or 20x more usage than Pro; the old practice of printing $100 and $200 as two separate cards is gone from the page. The 20x option still exists in checkout, but since the public page no longer prints its price, budget for "Max from $100 with a 20x tier above it" and confirm the exact 20x figure at purchase. Max also carries higher output limits and early access to new features, which mattered concretely in July: the Cowork web and mobile beta and the Opus 5 default both reached Max subscribers first.
The Team plan correction is the single most consequential fix in this refresh. Older coverage, and at least two pages currently outranking this one, list Team at roughly $30/user with a 5-user minimum. The live page says "For teams of 2 to 150" with two seat types: Standard at $20/seat annual ($25 monthly) for more-than-Pro allocation, and Premium at $100/seat annual ($125 monthly) for 5x Standard usage per seat. The 2-seat floor changes who can buy this: a two-founder company can now get centralized billing, admin controls, and per-seat quota for $40/month on annual billing, where the old floor forced five seats or individual Pro accounts with no shared administration. For a 10-person team, the math runs $2,400/year on annual Standard against $12,000/year on annual Premium: a 5x spread inside the same "Team plan" label, which is exactly why the quota mechanics in section 3 matter more than the sticker price.
The annual-versus-monthly choice deserves more thought than it usually gets, because the mechanics differ by tier. On Pro, annual billing is a $200 upfront payment that works out to $17/month: a 15% discount purchased with a one-year commitment to a product category where, as this guide documents repeatedly, the value of a plan changes monthly. In Cowork's case every mid-cycle change so far has favored the subscriber (limits doubled, Opus 5 landed, platforms widened, all at constant price), so the annual commitment has been free money in hindsight. The forward-looking version of that judgment: the main risk to an annual Claude commitment is not the product getting worse, it is the metering framework returning (section 6) in a form that changes what heavy users get for the flat fee. Anthropic has committed to advance notice for that change, and existing subscription terms would run their course, so the practical exposure on a $200 annual Pro is low. On Team plans the same logic applies per seat, with the added wrinkle that the pricing page notes mid-term seat additions, so growing teams are not locked to their signup headcount.
To make the tiers concrete, price the realistic configurations for a year. A solo operator on annual Pro pays $200 flat. A serious individual practitioner on Max 5x pays $1,200. A two-founder company on annual Team Standard pays $480, and gets admin controls and centralized billing that two separate Pro accounts never provide for $80 less. A ten-person operations team pays $2,400 on annual Standard or $12,000 on annual Premium. Against those numbers, the thing being bought: if Cowork absorbs even two hours per person per week of report assembly and data wrangling, the ten-person Standard team recovers roughly 1,000 hours a year for $2,400, about $2.40 per recovered hour, two orders of magnitude under loaded knowledge-work cost. The arithmetic is so lopsided that the subscription fee is never the binding question. The binding questions are whether your workflows actually surrender those hours to an agent that completes tasks at the verified rates in section 9, and whether anyone does the process mapping to find them, which is why this guide spends more words on limits and failure modes than on prices.
Above Team, the structure gained a rung. Enterprise now splits into self-serve and sales-assisted paths: the self-serve variant can be created online like a Team plan, while the sales-assisted variant carries the traditional enterprise stack of SSO, custom data retention, network-level access control, IP allowlisting, a HIPAA-ready offering, and Claude Security (beta), Anthropic's security product line that now appears as a plan feature. There is also a separate Education plan for university-wide deployments covering students, faculty, and staff. The existence of a self-serve Enterprise tier is worth noticing as a signal: it means the demand for org-level controls is arriving faster than a sales team can process it, which matches what the adoption data in section 11 shows about who is actually using Cowork.
Deciding between Team and the Enterprise tiers is less about headcount than about which controls are load-bearing for you. Anthropic's own pricing page now runs a short recommendation flow that routes buyers needing "a tailored approach and enterprise security features" to the sales-assisted Enterprise plan, while everything else lands on Team or self-serve Enterprise - claude.com/pricing. The feature comparison beneath it is the honest sorting device: Team and self-serve Enterprise share the full product surface (Chat, Code, Cowork, Design, Science, @Claude), while the sales-assisted column exclusively carries single sign-on, custom data retention, network-level access control, and IP allowlisting. The clean rule that falls out: if your security review will ask for SSO or retention controls, start the sales conversation now, because no amount of Team seats gets you there; if it will not, the self-serve tiers deploy today. For universities, the separate Education plan covers an institution's students, faculty, and staff in one agreement, a structure that did not exist when this article first published in January and that signals where Anthropic expects the next adoption wave.
2. What Your Subscription Does Not Include
No pricing page leads with what you do not get, so this section exists because the gaps are where budgets go wrong. The comparison table at the bottom of Anthropic's own pricing page contains the answers, and they are more consequential than the headline prices - claude.com/pricing.
The first gap is context window size. The consumer plans table lists a 200k-token context window on Free, Pro, and both Max tiers. The API versions of the same frontier models run 1M-token context windows with 128k output on the current top tier - Anthropic model docs. That 5x difference is invisible until the day you feed Cowork a folder whose contents exceed what a 200k window can hold at once, and it is the honest answer to why some workloads behave differently on the API than in the app. If your use case is genuinely long-context (large codebases, discovery-scale document sets), the subscription is not where that workload lives.
What a 200k ceiling looks like in practice is worth one concrete scenario, because the failure is silent rather than loud. Point Cowork at a quarter's worth of supplier PDFs and ask for a reconciliation, and the agent does not refuse: it works in passes, reading, summarizing, and re-reading as its window fills, which costs quota (every re-read is metered draw under section 3's rules) and occasionally costs fidelity, because a detail summarized out in pass one cannot be recovered in pass three. The same job against the API's 1M window, which Anthropic's docs equate to roughly 555k words of text, holds the entire corpus in context at once - Anthropic model docs. Neither behavior is wrong; they are different products at different prices. The budgeting rule that falls out: if your recurring workload's working set exceeds a few hundred pages, price it on the API side of section 5 rather than assuming the subscription absorbs it.
The second gap is frontier model access. Anthropic's top model, Claude Fable 5, is not part of the ordinary subscription pool. The pricing page's models table shows Fable on Pro as "Usage credits", meaning you buy separate metered credits to use it, while Max 5x and Max 20x get Fable at 50% of weekly limits: you can route half of your weekly allocation through the frontier model, and no more. This is a meaningful change from earlier in the summer, when Fable required usage credits on every subscription tier, and it makes Max materially more valuable for frontier-model work than Pro. It has also been genuinely unstable ground: Anthropic paused and restored Fable 5 access around July 1 after a jailbreak-severity review, announcing the redeployment publicly - Anthropic. Our Fable 5 and Mythos 5 benchmark breakdown covers what the model does; the budgeting point here is that frontier access is metered or capped everywhere, and any plan that assumes unlimited Fable is wrong on every tier.
Third, some of the ecosystem is simply not for sale to individuals. Claude Mythos 5, the safeguards-lifted sibling of Fable, remains restricted to cyberdefenders and infrastructure providers through the invitation-only Project Glasswing program, with no self-serve signup - Anthropic model docs. And several governance features that enterprises will assume are standard (custom retention, IP allowlisting, the HIPAA-ready configuration) live exclusively on the sales-assisted Enterprise tier.
What the subscription does include, as of this writing, keeps growing at the edges: the plan feature lists now carry Claude for Chrome and Claude for Microsoft Outlook alongside the Microsoft 365 integration, plus desktop extensions, voice mode, and incognito chats - claude.com/pricing. Those two browser and mailbox entries deserve a sentence each, because they change where Cowork's agent loop reaches. Chrome access is what lets a Cowork session operate the web like a user (clicking, typing, form-filling) rather than just fetching pages, which is the capability that separates a research assistant from an office agent. The Outlook integration extends the Microsoft 365 write path (drafting and sending mail, managing calendars) to organizations whose mail lives in Outlook rather than the broader 365 surface. Both being listed as plan features rather than paid add-ons continues the bundling pattern section 8 documents: capability lands inside existing prices.
The practical reading of this section for a buyer: the subscription is a bounded consumer product with a 200k window, capped frontier access, and app-surface features, while the API is the unbounded product priced per token. The two are complements, not substitutes: the subscription's job is to make agent work cheap enough to discover which of your workflows are worth automating, and the API's job is to run the ones that outgrow it. Teams that understand this graduate workloads deliberately instead of hitting walls by surprise, and section 5 prices the side you graduate to.
3. How the Shared Quota Actually Meters You
The subscription's real unit of account is not messages, and any article still quoting "225 messages per window" is describing a system that died in May 2026. The current mechanics, per Anthropic's documentation: one shared quota covers Claude chat, Claude Code, and Cowork together, with Cowork drawing substantially more per task than chat - Claude help center. Enforcement runs through a 5-hour session window plus weekly limits on every paid plan - Claude usage docs. On May 6, 2026, Anthropic doubled the five-hour limits across Pro, Max, Team, and Enterprise and removed peak-hour throttling for Pro and Max - Anthropic.
The shared-pool design is the single most important thing to understand before picking a tier. Your subscription is a compute budget that three products drain at different rates. A chat question is a sip. A Claude Code session is a glass. A Cowork task that spins up parallel sub-agents, browses the web, and iterates on a spreadsheet for forty minutes is a jug. Anthropic's own fine print adds that it may manage capacity through "weekly and monthly caps or model and feature usage limits," which is the pricing page's quiet acknowledgment that the meter has more than one layer - claude.com/pricing. The Fable carve-out from section 2 (50% of weekly limits on Max) is the clearest example of a model-level limit living inside the plan-level one.
The window mechanics reward a little arithmetic literacy. The 5-hour window is a session window, not a calendar day: it opens with your first activity and resets five hours later, so a heavy burst at 9 a.m. stops constraining you by early afternoon, and the worst pattern is stacking every heavy job into the same stretch. This is why scheduling is a quota tool and not just a convenience: recurring jobs distributed across the day (or into hours you are asleep, now that cloud sessions run with no device online) draw from windows your interactive work never touches. The weekly cap is the backstop that keeps window-spreading from becoming unlimited usage, and the pricing page's fine print reserves monthly caps and model-level limits on top - claude.com/pricing. None of these numbers is published as a message count anymore, deliberately: Anthropic stopped quoting message equivalents because a "message" spanning a one-line chat reply and a forty-minute multi-agent Cowork session was a meaningless unit, and any budgeting you do should be in tasks and hours, not messages.
Budgeting therefore works backward from task volume. The pattern that holds across heavy users we have compared notes with while building O-mega's own agent workforce on top of these same models: a Pro plan sustains a handful of substantive Cowork tasks per day mixed with chat and light Code use, but one ambitious afternoon of parallel jobs can exhaust a five-hour window. Max at 5x fits daily multi-hour agent work without watching the meter. The 20x option exists for near-continuous sessions, parallel jobs, and overnight scheduled tasks. The tier question compresses to "how many hours per day is an agent working for you": under one, Pro; one to three, Max 5x; more than that, the 20x tier or Team Premium. Techniques for stretching any tier are the same ones in our LLM cost-efficiency guide: batch related steps into one well-specified session, constrain output formats, schedule heavy recurring jobs into off-peak personal hours so they spread across more windows, and treat parallel sub-agent fan-out as a deliberate spend rather than default ambition.
The value math that justifies any of these tiers deserves to be run explicitly once, because it anchors every later judgment. Suppose Cowork saves a marketing operations manager six hours a month on reporting alone. At even $50/hour of loaded cost, that is $300 of recovered time against a $20 or $100 subscription, and the May doubling means the same dollar buys roughly twice the January window capacity. The economics fail in exactly one way: task failure. An agent that burns a jug of quota producing a spreadsheet you must redo is negative ROI at any tier, which is why the reliability data in section 9 belongs inside a pricing decision rather than beside it. It is also why the single highest-leverage quota skill is not a trick but a habit: specify tasks completely. An agent told exactly which folder, which output format, and which edge cases to flag completes in one pass; a vague prompt buys a clarification loop that re-spends context on every retry. In our own agent operations this one discipline routinely halves effective consumption, more than any tier change would.
Hitting a cap is not a hard stop. Paid plans can enable extra usage, which continues work at metered rates once the subscription pool is exhausted: an overflow valve for deadline weeks, and a preview of the metering question section 6 takes head-on. The supply side of all this is worth one paragraph because it predicts the next price move better than any pricing page: the May 6 generosity was announced alongside Anthropic's deal for all compute at SpaceX's Colossus 1 data center, more than 300 megawatts and over 220,000 NVIDIA GPUs dedicated to serving Claude - Anthropic. Capacity landed and limits loosened rather than prices rising. When you wonder whether a $100/month agent plan stays a good deal, watch capacity announcements the way you watch pricing pages; in this market the former moves the latter by about a quarter.
4. The Opus 5 Shift: What Changed on July 24
The biggest Claude event since this article's last revision is one the July version could not have covered: Claude Opus 5 launched on July 24, 2026, priced at $5 per million input tokens and $25 per million output tokens, explicitly "the same as Opus 4.8" - Anthropic. It is available in Claude Cowork, Claude Code, and the claude.ai apps, and on the API as claude-opus-5. For subscription buyers the operative line in the announcement is this one: Opus 5 is "the new default model on Claude Max, and the strongest model on Claude Pro." The engine inside every paid plan just changed, at zero change in price.
Anthropic's positioning is unusually concrete about where Opus 5 sits: a model that "comes close to the frontier intelligence of Claude Fable 5 at half the price." The vendor-reported numbers behind that claim: on Frontier-Bench v0.1, Opus 5 is state of the art and more than doubles Opus 4.8's performance at a lower cost per task; on CursorBench 3.2 at max effort it lands within 0.5% of Fable 5's peak score at half the cost per task; on ARC-AGI 3 its score is three times the next-best model; and on OSWorld 2.0, Anthropic's computer-use evaluation, it "surpasses Fable 5's best result at just over a third of the cost" - Anthropic. Every one of those is a vendor benchmark, and section 9 explains precisely which of them has independent verification and which does not. But even discounted for source, the shape is clear: the Opus tier absorbed most of the frontier tier's capability while keeping the mid-frontier price, which is why Anthropic's developer docs now open model selection with "start with Claude Opus 5" - Anthropic model docs.
The generational turnover is complete and dated. Opus 4.8 has moved to the Legacy models table in the docs, with the migration guide pointing from 4.8 to Opus 5. And Claude Opus 4.1 retires August 5, 2026, today as this refresh publishes: the docs list claude-opus-4-1-20250805 as deprecated with retirement dated to today and migrations directed to Opus 5, so anything still pinned to it fails outright from now on rather than degrading politely - Anthropic model docs. The July version of this article called that retirement a this-month deadline; it is now a completed fact, and the lesson generalizes: model pricing and availability are a moving schedule, and any per-MTok figure or model ID older than a quarter should be re-verified before it touches a budget. Our Opus 5 vs Opus 4.8 comparison runs the two generations head-to-head, and the Opus 4.8 benchmark guide remains the reference for the outgoing model.
Two operational details from the launch matter for anyone budgeting API-side work. First, Fast mode: Opus 5 is offered in a mode that runs around 2.5 times the default speed, priced at twice the base rate ($10/$50) on the Claude Platform and through usage credits in Claude Code - Anthropic. Fast mode is a latency product, not a capability product, and the honest buying advice is that agent workloads running unattended (the Cowork scheduled-task pattern) should almost never pay it, while interactive sessions where a human is waiting sometimes should. Second, the effort parameter: Anthropic's docs note that on Opus 4.8 effort defaulted to high on all surfaces, while on Opus 5 and Sonnet 5 it defaults to high on the Claude API and Claude Code specifically - Anthropic model docs. Effort is the dial that trades tokens for thoroughness, and the vendor benchmarks above were reported at specific effort levels (CursorBench at max effort, for instance), so replicating headline numbers on your workload means checking what effort your integration actually runs. Launched alongside the model in beta: mid-conversation tool changes without invalidating the prompt cache, and automatic fallbacks on the API, both small line items that reduce real agent operating costs.
One honest wrinkle belongs in any Opus 5 summary: the model's safety classifiers are stricter in cybersecurity domains, and Anthropic states that in claude.ai, Claude Code, and Cowork, flagged requests fall back to Opus 4.8 by default, with the same fallback available on the API - Anthropic. For office workloads this is invisible; for security teams it means the "default model" is conditional, and the Glasswing program from section 2 is the sanctioned route for the work Opus 5 declines. What the shift means for the pricing decision this page exists to answer: the $20 Pro plan's strongest model and the Max default both improved a full generation on July 24 at constant subscription prices, which resets any plan-value comparison you made before that date, including against the competitors in section 10.
5. The Model Price List Behind the Subscription
Subscriptions abstract the meter away, but the API price list is where the real economics live, and two of its numbers carry dates that should be in your calendar. Here is the current Claude lineup with verified per-million-token pricing - Anthropic model docs:
| Model | Input / Output per MTok | Position | Notes |
|---|---|---|---|
| Claude Fable 5 | $10 / $50 | Frontier flagship | 1M context, 128k output, adaptive thinking always on |
| Claude Opus 5 | $5 / $25 | Daily-driver frontier | New default on Max; same price as retired-to-legacy Opus 4.8 |
| Claude Sonnet 5 | $3 / $15 (intro $2 / $10 through Aug 31) | Mid-tier agentic | 1M context; intro pricing ends in 26 days |
| Claude Haiku 4.5 | $1 / $5 | Efficiency tier | 200k context, 64k output, cheapest current Claude |
The first dated number is the Sonnet 5 introductory price. The docs footnote is explicit: $2/$10 applies through August 31, 2026, after which Sonnet 5 reverts to $3/$15 - Anthropic model docs. That is 26 days from this article's publication date. Anyone running API-side agent pipelines on Sonnet 5 should benchmark workloads now, at the discounted rate, and re-price them at $3/$15 before committing to architectures: a pipeline validated at intro pricing costs 50% more per token in September. Whether the reversion actually happens on schedule is itself the cleanest public signal of competitive pressure in the mid-tier, and this page will be updated after September 1 to record what occurred. Our Sonnet 5 practical guide covers the model itself.
The second dated fact already landed: Opus 4.1's August 5 retirement, covered in section 4. Between the two, the deeper budgeting lesson is a tokenizer detail that no competing pricing page mentions, buried in a docs tooltip: Claude Fable 5 uses the tokenizer introduced with Opus 4.7, and compared to models before Opus 4.7, the same text produces roughly 30% more tokens - Anthropic model docs. A team that migrated an old pipeline onto current models and kept its per-token math is silently underestimating cost by nearly a third before any price change happens. Token counts, not just token prices, move between generations.
The tokenizer fact compounds with a quieter capability detail that changes output-side budgets. The table's 128k max output applies to the synchronous Messages API, but the docs note that Opus 5, Opus 4.8, Sonnet 5, and their recent siblings support up to 300k output tokens on the Message Batches API via the output-300k-2026-03-24 beta header - Anthropic model docs. For agent pipelines that generate large artifacts (full reports, datasets, codebases), the batch path is both the cheaper and the roomier one, and knowing it exists prevents the common architecture mistake of chunking output through repeated synchronous calls, each of which re-bills input context. Output tokens price at 5x input across the entire Claude lineup in the table above, so every avoided re-generation is the most expensive kind of token you can save.
For context against the other major API price list, here is the cross-vendor picture. OpenAI's GPT-5.6 lineup, in limited preview a month ago, is now on the public API price list - OpenAI pricing docs:
Read across the chart and the convergence is striking: Opus 5 at $5/$25 against gpt-5.6-sol at $5/$30 (with cached input at $0.50), Sonnet 5 at $3/$15 against gpt-5.6-terra at $2/$12, and below the chart's range, Haiku 4.5 at $1/$5 against gpt-5.6-luna at $0.20/$1.20 - OpenAI pricing docs. The two vendors have priced their tiers within striking distance of each other at every level, which means model choice for agent workloads is decided by capability per dollar and workload fit rather than headline rates. That comparison is the entire subject of our GPT-5.6 vs Claude Opus 5 agents comparison, and the GPT-5.6 benchmark guide profiles OpenAI's lineup in depth.
Why an API price list belongs in a subscription pricing guide: the API is the reference price of the compute your subscription abstracts. When section 6's metering question resurfaces, the credits will be denominated against these rates; when you outgrow the app, these are the prices you graduate to; and when you evaluate whether a subscription is generous or stingy, tokens-at-API-rates is the only neutral yardstick. Keep the two price lists mentally linked, because Anthropic certainly does.
6. Pay-Per-Use and the Paused Credit Overhaul
Is Claude pay-per-use? The August 2026 answer has three layers, and older articles that flatly say "no metering" are describing the system one near-miss ago. The core Cowork experience remains flat-fee within window and weekly caps. Frontier-model access is already metered or capped (Fable via usage credits on Pro and the 50% weekly mechanic on Max, per section 2). And high-volume headless automation sits under a framework that was announced, scheduled, and paused the day it was due to take effect.
The sequence is worth keeping precise because it is the best public window into the economics under these subscriptions. On May 14, 2026, Anthropic announced that Agent SDK and headless usage would move to separately metered dollar credits effective June 15, with subscription plans receiving monthly credit grants and overflow billed like API usage. On June 15, hours before the switch, Anthropic shelved the entire overhaul, with the surrounding analysis reporting that subscriptions had been subsidizing agent usage at roughly 15-30x API rates, heavy users extracting an estimated $300-600 of monthly compute on a $20 plan - Digital Applied. Anthropic committed to advance notice before any successor proposal. As of August 5, 2026, that is where it still stands: we checked Anthropic's newsroom this run, and every announcement since the Opus 5 launch is non-pricing (a policy hire, cybersecurity incident research, an open-weights position paper, partnerships). No reversal, no successor framework, no date.
The first-principles reading of the pause has held up for seven weeks and is worth restating because it predicts the sequel. The subsidy functions as customer acquisition spend in a market share war: every heavy user extracting hundreds of dollars of compute for $20 is also embedding workflows, scheduled tasks, and habits into Anthropic's ecosystem, and those switching costs compound monthly. Metering them mid-land-grab, while OpenAI ships agents to free users, risks handing rivals exactly the users most worth keeping; tolerating them gets cheaper every quarter that capacity like Colossus (section 3) comes online. A subsidy running at 15-30x is unsustainable as a permanent price and entirely rational as a time-limited land grab. Nothing about the pause repealed the underlying arithmetic, so the sensible planning assumption for 2027 budgets remains that metered agent credits return in some form once the competitive window closes, with advance notice as promised.
The Fable episode from section 2 belongs in this ledger too, because it demonstrated a second kind of pricing risk that contracts rarely name: availability risk. On July 1, Anthropic publicly restored access to Fable 5 and Mythos 5 on subscription plans after a safety-driven pause, proposing an industry-wide jailbreak-severity framework alongside the redeployment - Anthropic. Subscribers lost access to the top model for a period with no pricing recourse, because subscriptions promise a service level, not a specific model. For most users this was a non-event; for anyone whose workflow was tuned to a single model's behavior, it was an outage. The planning lesson generalizes beyond Anthropic: in 2026, model access is operationally revocable for safety, capacity, or legal reasons, and resilient agent architectures treat the model as a swappable component. That is the design stance our own platform took from the start, and the Opus 5 launch's automatic-fallback beta suggests Anthropic is now building the same assumption into its own API surface.
The practical implications sort cleanly by usage pattern. If your workload is interactive Cowork sessions, the paused overhaul explicitly did not target you, and every 2026 pricing change so far has moved in your favor. If your workload is scripted, headless, high-volume agent runs on a consumer subscription (the pattern our Agent SDK deep dive covers), treat current pricing as borrowed time: model the workload at the API rates in section 5 before building a business process on it, because that is the yardstick any returning credit system will use. And if you need contractual price stability for agent capacity, that is structurally what Team and Enterprise agreements are for, or what workforce-priced platforms like O-mega sell: agent output at a plan price, rather than metered tokens whose rules can change with thirty days notice. Flat fees survive where usage is bounded by human attention; autonomous agents remove that bound, so expect the metering pressure to keep returning exactly where usage becomes autonomous.
7. Permission Modes: Manual, Auto, Skip
An agent that reads folders, sends email, and fills forms is a different risk object than a chatbot, and the July version of this article described a permission system that no longer exists. Cowork now has three permission modes, not two, and the middle one changes the autonomy trade-off enough to be a plan-selection factor - Claude help center.
Manual (formerly "Ask before acting") pauses and requests approval for actions: you review each request and choose Allow or Deny. Auto is the new middle mode: Claude keeps working without stopping at every step, but reviews each action for safety (the documentation names data exfiltration and prompt injection checks explicitly) and decides for itself on write and delete operations, while read-only tools are approved automatically. Skip approves everything except tools you have explicitly blocked. The critical fine print: Auto mode is "currently available for Pro and Max plans only", and on Team and Enterprise plans, organization settings may enforce per-task approval for write-capable connector tools regardless of a user's preferences - Claude help center. Individual plans currently get a middle-autonomy option that team plans constrain by policy, which is the correct default direction for governance but worth knowing before you assume your desktop workflow transfers to a Team seat unchanged.
Permission modes interact with per-connector settings: each connector tool can be set to Always allow, Needs approval, or Blocked, and the mode determines how those settings resolve. Blocked stays blocked in every mode, which is the invariant to build on: the reliable way to keep an agent out of a system is to block the connector, not to trust a mode. Beneath the modes sit the platform-level protections that carried over from the earlier design: grant-based folder access (the agent sees what you mount, not your disk), prompt injection screening over files and web content the agent encounters, and mandatory approval before permanent file deletion regardless of mode.
A walkthrough makes the mode-times-connector matrix concrete. Say a session uses three connectors: a folder mount set to Always allow, a Microsoft 365 email tool set to Needs approval, and a payments connector set to Blocked. In Manual, the folder reads proceed after your first approval pattern, every email draft waits for an explicit Allow, and the payments tool is invisible to the agent. In Auto, folder reads flow freely, and when the agent wants to send the email it makes its own safety judgment: the documentation says Claude reviews the action for signs of data exfiltration or prompt injection and decides, which in practice means routine sends proceed and anomalous ones surface to you. In Skip, the email sends without ceremony, and the payments connector still does nothing, because Blocked is absolute. The design insight worth internalizing: the modes govern how much judgment is delegated, while connector settings govern what exists to be judged. Teams that get burned are almost always teams that tuned the former and ignored the latter.
For a team deploying this month, the governance sequence that works compresses into a week of discipline. Sort candidate workflows by blast radius: read-only analysis first, file-writing automation second, anything that sends communications or touches external systems last. Grant folder and connector access per workflow, not per person. Run every new workflow in Manual for its first ten executions, reviewing action logs rather than just outputs, because the failure you are screening for is a plausible-looking wrong step. Promote proven workflows to Auto, and reserve Skip for workflows whose whole tool surface you have deliberately constrained. The riskiest combination, web browsing plus write access to email or files, deserves standing review indefinitely: that is where prompt injection has real consequences, and screening it is not a solved problem anywhere in the industry. The gap that remains industry-wide is cross-agent governance: what happens when scheduled agents trigger other agents, or when the audit question is which of hundreds of agents touched a file and why. That layer is where purpose-built platforms compete on oversight rather than capability, O-mega among them, and it is the reason section 11's framework treats governance capacity as a real constraint rather than a checkbox.
8. Where Cowork Runs Now, and What July Added
Platform availability was Cowork's defining weakness for exactly one quarter, and it has been gone for four months, though pages claiming "macOS-only" still rank for this query. The compressed, dated record from Anthropic's release notes: January 12 research preview (Max, macOS), January 16 Pro access, February 25 scheduled tasks, April 9 general availability on macOS and Windows, May 6 limits doubled, July 7 web, iOS, and Android in beta with sessions executing in Anthropic's cloud - Anthropic release notes. The cloud sessions are the architecturally interesting part: sessions and files attach to your Claude account rather than your device, continue when the laptop closes, and scheduled tasks run with no device online at all. Our autonomous desktop guide covers the local-execution model this supersedes.
Why the cloud pivot matters to a pricing page: it changed what a subscription hour of agent work is worth, without changing the price. Consider the three workloads that dominate real usage. The weekly report, the modal task in the session data cited in section 11, previously required a machine awake at report time; it now runs server-side on schedule with the finished spreadsheet waiting in your account, which is the difference between owning a tool and employing a service. The long research compilation that used to die at 70% when a laptop went into a bag now survives the commute and finishes. And the approval-gated workflow, where the agent drafts and a human signs off, becomes genuinely asynchronous: the agent works overnight, the approvals happen from a phone over coffee. None of these was impossible before July 7; all carried friction that quietly capped how much work people delegated, and removing that friction raises effective capacity more than any benchmark point. The honest counterweight: cloud execution means your session files sync to Anthropic's servers rather than staying local, a trust trade every organization should evaluate against section 7's controls before flipping recurring workloads to remote schedules.
The rollout status needs updating from what July coverage said, including ours. The help center now states the web and mobile beta covers "Max, Team, and Enterprise plans, and will be rolling out to Pro plans over the next several weeks" - Claude help center. So the accurate August picture: desktop Cowork is GA on every paid plan; cloud Cowork is in beta on Max, Team, and Enterprise, with Pro in progress. If you are on Pro and do not see Cowork on web or mobile, you are not misconfigured, you are queued.
July's release notes also shipped a cluster of quality-of-life and compliance features that a pricing evaluation should know about, because they change what the same subscription includes. On July 9, Claude gained a monthly recap (topics, most active day, peak hour) plus optional break reminders and quiet hours. On July 10, memory was reworked into individual, categorized entries that Claude reads and updates during conversations, replacing the daily summary model, which matters for Cowork because persistent structured memory is what lets a recurring agent task improve instead of restarting cold. On July 14, HIPAA configuration went self-serve for Claude Enterprise and the Claude API: an eligible admin can review the Business Associate Agreement and enable HIPAA-ready configuration without a sales cycle, and the same day Anthropic introduced Claude for Teachers - Anthropic release notes. And on July 24, Opus 5 landed in Cowork, Code, and claude.ai, as covered in section 4.
One more July release note matters specifically to organizational buyers: model entitlements for Enterprise plans entered beta on July 1, letting admins control which models their users can access - Anthropic release notes. Paired with the Opus 5 fallback behavior from section 4 and the Fable carve-outs from section 2, this completes a picture that did not exist in the spring: model access is now a governed resource inside a Claude organization, not a flat entitlement. For a compliance team this is a welcome control surface (pin users to approved models, keep experimental ones out of regulated workflows). For a budget owner it is a planning input: the models your users actually run determine how fast the shared quota drains, and entitlements are the first tool that lets an organization shape that centrally rather than by memo.
The pattern across seven months is the strategic fact buyers should price in. Anthropic expanded capability first (scheduling, sub-agents, Office formats, Microsoft 365 write access), platforms second (Windows, then web and mobile), compliance third (self-serve HIPAA, model entitlements for Enterprise admins), and price never: every expansion landed at constant subscription rates, with the only pricing motion (May 6) moving in the customer's favor. That ordering is the opposite of the classic playbook where new platforms arrive as upsell tiers, and it makes sense only in a land-grab phase where the scarce resource is user workflows rather than revenue per user. The reasonable inference: through at least the rest of 2026, expect Cowork's surface area to keep widening at today's prices, and expect monetization pressure to arrive through the metering side (section 6) rather than through feature gates.
9. Reliability Per Dollar: OSWorld-Verified vs Vendor Numbers
A pricing decision for an agent is really a reliability-per-dollar decision: quota spent on tasks you must redo is negative ROI at any subscription price. The independent yardstick for computer-use reliability is the OSWorld-Verified leaderboard, a 369-task real-computer benchmark with a 72.36% human baseline, and its top has been stable since early summer - OSWorld-Verified leaderboard.
The current standings: Claude Mythos Preview at 85.4%, Claude Mythos 5 and Fable 5 at 85.0%, Claude Opus 4.8 at 83.4%, Claude Sonnet 5 at 81.2%, and Sonnet 4.6 at 78.5%, with GPT-5.4 at 75.0% as OpenAI's listed entry. The leaderboard also surfaces rows most coverage misses: OSAgent at 76.26%, a reinforcement-learning system from TheAGI Company that outscores GPT-5.4 despite an October 2025 report date, Claude Opus 4.6 at 72.7% sitting almost exactly on the human baseline, and Qwen3 VL 235B at 66.7% as the strongest open-source entry - OSWorld-Verified leaderboard. Everything at 72.7% and above is at or past human baseline: the benchmark's frontier went decisively super-human during 2026, and Anthropic's models sweep the top of the table.
The shape of the climb explains why these scores translate into usable reliability rather than demo reliability. The sub-human era was defined by compounding failure: an agent with 90% per-step accuracy fails most 20-step tasks, because errors multiply across steps, which is why early agents demoed brilliantly and collapsed on real workflows. The breakthrough behind the 2026 numbers was less about smarter single steps than about mid-task recovery: current frontier models notice their own mistakes, back up, and try another path, converting per-step accuracy into end-to-end completion. That is also why the verified table's top is swept by models trained explicitly as agents rather than by the largest general models, and why a harness-engineering entry like OSAgent can sit above a frontier lab's model on this specific benchmark: the last mile of computer use is an engineering problem wrapped around a capability problem, and both layers move scores.
Now the honesty that separates this page from a press release: Claude Opus 5 is not on the independent leaderboard yet. Its computer-use claim, that it surpasses Fable 5's best result at just over a third of the cost, comes from Anthropic's own runs on OSWorld 2.0, a different and newer version of the benchmark than the OSWorld-Verified board tracks, which makes the numbers not directly comparable to the table above - Anthropic. The leaderboard itself flags most frontier entries as self-reported from system cards while awaiting independent verification, and notes that harness differences move scores by multiple points between evaluators. So the defensible August statement is layered: Claude models hold the top positions on the benchmark version the community actually tracks, with the leaderboard's own self-reporting caveats attached; Opus 5's claimed improvement is vendor-reported on a successor benchmark it currently has to itself; and no number on any leaderboard means an agent completes that share of your workload, which includes ambiguity and judgment calls no benchmark captures. Our computer-use benchmarks guide unpacks the methodology differences in depth.
Two of the less famous rows carry their own pricing lessons. Opus 4.6 at 72.7%, sitting almost exactly on the human baseline, is a reminder of how recent the super-human turn is: that model was Anthropic's frontier in February 2026, meaning the entire gap between "matches a human" and "clearly exceeds one" opened in under six months, within a single subscription price. And Qwen3 VL 235B at 66.7% as the strongest open-source entry quantifies the open-versus-closed gap for computer use specifically: roughly 18 points below the verified frontier, which is the honest number to weigh against open weights' zero per-token cost if you are tempted by self-hosting an office agent. For most business workloads the reliability delta swamps the inference savings, because section 3's math already showed the subscription fee is noise next to the cost of redone work; for high-volume, low-stakes automation the calculus can flip, which is the lane the on-device models in section 10 occupy.
What the trend line means for the pricing decision has not changed direction, only magnitude. At the 32% success rates of early-2025 systems, an agent subscription was a toy: two of three tasks needed human redo. At 83-85% verified, the expected value flips, review effort concentrates on a shrinking failure tail, and the same $100 Max plan buys categorically more finished work than it did at Cowork's January launch. If Opus 5's vendor numbers survive independent verification, that curve took another step in July at zero price change, which is the quiet compounding this whole guide keeps finding: in 2026, capability per subscription dollar rises between price changes, and the pricing page is the last place that shows it.
10. What Cowork Competes Against on Price
Cowork's pricing only means something against the alternatives, and every major competitor changed since mid-summer coverage froze. This section compresses the field to what moved and what it costs; the full platform-by-platform treatment lives in our top 10 Cowork alternatives guide.
OpenAI remains the head-to-head rival, with Codex reaching every ChatGPT tier and expanding from code into office work, a trajectory TechCrunch summarized as the coding agent wars "spilling into the rest of the office" - TechCrunch. What we can verify precisely this run is the API side: the GPT-5.6 lineup left limited preview and is now on the public price list at gpt-5.6-sol $5/$30, gpt-5.6-terra $2/$12, and gpt-5.6-luna $0.20/$1.20, alongside GPT-5.5 at $5/$30 and GPT-5.4 at $2.50/$15 - OpenAI pricing docs. OpenAI's consumer plan pages block automated verification, so this refresh deliberately does not restate ChatGPT consumer prices it could not re-check; our ChatGPT agent pricing guide tracks that side, including Operator's absorption into agent mode. The structural contrast stands regardless of exact consumer figures: OpenAI runs a distribution-first play reaching free users, Anthropic a capability-first play that charges from dollar one.
Google restructured around a new flagship, and the biggest correction in this section is a product death: Project Mariner no longer appears anywhere on Google's subscription page, having been discontinued on May 4, 2026 and folded into Gemini Agent and Chrome's Auto Browse, as documented in our browser-use agents review. The live subscriptions page now leads with access to Gemini Omni, lists Gemini 3 Pro, Deep Search, and agentic capabilities on paid tiers, includes Google Antigravity (Google's agentic development environment) with per-tier agent-model limits, and offers Gemini Omni Flash inside the Flow creative studio - Gemini subscriptions. Verified pricing: AI Plus at EUR 4.99/month (2x usage vs free), AI Pro at EUR 21.99 (4x), and AI Ultra from EUR 99.99 (5x) with a EUR 219.99 20x option. Any comparison still selling "Ultra bundles Mariner browser control" describes a product that no longer exists; our Gemini Omni guide covers what replaced it.
The Google restructuring also moved agentic features down-market in a way that pressures Anthropic's entry tier specifically. Agent-grade capability that lived only in premium bundles a year ago now appears at EUR 21.99, one notch above Claude Pro's price point, inside an ecosystem that already holds many organizations' documents, mail, and calendars. For a company living in Google Workspace, that integration gravity is worth an evaluation slot before any cross-vendor comparison: an agent that natively reads your Docs, Sheets, and Gmail starts with context every competitor has to be granted folder by folder. The counter-argument is the one this guide keeps returning to: Cowork's file-system depth, Excel formula generation, and scheduled cloud sessions form a more complete delegation loop for file-anchored recurring work, and per-seat Team pricing with a 2-seat floor is an easier organizational purchase than consumer subscriptions repurposed for work.
Amazon and Microsoft occupy deliberately different lanes than a consumer office agent. Nova Act is a generally available AWS service for deploying fleets of browser-automation agents with IAM, CloudWatch, and Bedrock AgentCore integration: usage-based infrastructure for thousands of parallel workflows, not a coworker for your Tuesday spreadsheet - AWS Nova Act. Fara-7B remains Microsoft Research's 7-billion-parameter computer-use model that perceives screens through screenshots only and runs on-device, the privacy-and-cost lane rather than the capability lane - Microsoft Research. Microsoft's commercial agent story runs through Copilot, dissected in our Copilot vs Cowork analysis.
A routing scenario grounds the abstractions, because real teams increasingly run more than one of these. A five-person growth team holding both Claude Team Standard seats and an OpenAI footprint routes its weekly metrics deck (pull data from three sources, build the spreadsheet, generate slides) to Cowork, where file-system depth, Excel formula generation, and the scheduled cloud run decide it. Its open-ended market research routes to OpenAI's agent surface, where browsing breadth and research tooling are strongest. Its ad-copy iteration at volume routes to whichever quota pool has headroom that day, because both handle it. After a quarter, the observable pattern in teams like this is that recurring, structured, file-anchored work migrates toward Cowork while exploratory, web-anchored work migrates the other way, which is exactly what the two products' architectures predict. The dual stack costs less per month than one hour of the labor it displaces, which is why "pick one ecosystem" is increasingly the wrong frame for teams even as individuals sensibly start with one.
The synthesis for a buyer: genuine substitutes exist at every price point, from free-tier Codex and open-weights Fara-7B through EUR 4.99 Gemini plans to enterprise-metered Nova Act, so the question is never "which agent is best" but which consumption model matches your constraint: subscription depth (Anthropic), free distribution (OpenAI), ecosystem bundling (Google), metered infrastructure (Amazon), or on-device privacy (Microsoft). And there is a sixth model the other five quietly converged toward when Cowork's sessions moved into the cloud: agents as a managed workforce, where platforms like O-mega run autonomous agents with browser and computer capabilities server-side as named workers with standing responsibilities, priced on the workforce rather than the meter. Anthropic arriving at account-bound cloud agents from the desktop direction is a strong signal about where the whole category settles.
11. Which Plan to Buy: The Decision Framework
Pulling the verified facts into a decision. Cowork in August 2026 is a cross-platform, cloud-executing office agent bundled into every paid Claude plan, now driven by Opus 5 on the plans most buyers choose, priced under a shared-quota system whose only 2026 changes favored the customer, with one honest asterisk that has not moved since June: metering pressure on autonomous workloads surfaced once, paused, and retains every economic reason to return.
The tier logic, condensed against the verified table in section 1. Choose Pro at $20/month ($17 annual) if agents will do under an hour of work for you on a typical day; since July 24 that $20 includes Opus 5 as its strongest model, plus Code, Design, Science, and Microsoft 365, and it is the strongest $20 in the category. Choose Max from $100 when agent work becomes daily and multi-hour, with the 20x option when Cowork sessions, scheduled tasks, and parallel jobs amount to a part-time worker; Max also carries the Fable 5 at 50% of weekly limits mechanic and first access to betas, both verified this run. Teams now start at 2 seats: Standard at $20/seat annual for Pro-class allocation, Premium at $100/seat annual for 5x that, and the choice per seat follows the same daily-agent-hours rule. Organizations needing compliance route through Enterprise, where the new self-serve tier handles org controls and the sales-assisted tier adds SSO, custom retention, and the now self-serve-configurable HIPAA readiness. If your workload is headless and high-volume, price it at section 5's API rates before betting a process on subscription economics: the June 15 pause is a stay, not a verdict.
Who is actually buying this is worth one grounding paragraph, because it calibrates "enough quota." Anthropic's analysis of 1.2 million Cowork sessions across more than 600,000 organizations found the largest use category is business process operations at 33.4% of sessions, with over 90% of usage being non-development work - TechCrunch. The buyer is the operations manager with recurring reports, not the engineer, and recurring workloads favor Team plans and scheduled cloud sessions over one power user's Max account. The same recurring-operations workload is what O-mega packages as named agents with standing responsibilities, and the mobile expansion pushing this pattern is well documented - PYMNTS. The counterweight belongs next to it: Gartner forecasts that 40% of agentic AI projects face cancellation by 2027 on cost, unclear value, and weak risk controls - Software Strategies Blog. The way to be in the surviving majority is boring: start with the recurring process categories the session data validates, measure completed-task cost against the human alternative, and scale autonomy only as fast as your section 7 review capacity.
Three public, dated indicators will tell you more about your 2027 agent budget than any forecast, and all three are checkable without insider access. August 31: whether Sonnet 5's intro pricing reverts on schedule is the cleanest single read on mid-tier competitive pressure; an extension signals the price war intensifying, a clean reversion signals capacity discipline, and this page will record the outcome after September 1. The credit overhaul's return: Anthropic promised advance notice, so the announcement itself is the indicator, and its shape (grant sizes, what counts as headless) will define the real price of autonomous workloads on subscriptions. Pro's cloud-session rollout: how fast the web and mobile beta finishes reaching Pro reveals how much serving capacity actually exists beyond the Max tier, because always-on remote sessions are the most compute-hungry feature Anthropic has shipped to consumers. Watch those three dates and announcements; everything else in this market is commentary.
First moves, by reader. If you have never run an agent, buy one month of Pro, pick one recurring report or checklist from your actual week, and delegate it end to end: the experiment costs $20 and settles the question empirically. If you run Cowork daily, audit what you have not yet delegated, because the compounding returns live in the second through tenth workflow, and re-check your tier against the Opus 5 shift since the same money now buys a newer engine. If you own a team decision, use the 2-seat Team floor to pilot with real admin controls instead of scattered Pro accounts, run the governance sequence from section 7, and make a scale-or-stop call on measured cost per completed task within a quarter. And if what you want is the delegated outcome without operating any vendor's app surface, evaluate a managed agent workforce alongside the subscriptions: that lane exists precisely because the operating burden is real.
This refresh was researched and re-verified by Yuma Heymans (@yumahey), founder of O-mega and co-founder of HeroHunt.ai, whose day job of running cloud agent fleets against these exact quota systems is why the limits in this guide come from tested behavior and live documentation rather than vendor summaries.
One closing observation earns its sentence. Between this article's January publication and today, Cowork went from a macOS research preview to a cloud service on every screen, its engine advanced two generations, verified computer-use scores settled above the human baseline, and the subscription price of all of it moved zero dollars. The honest August 2026 reading is that the sticker prices are the most stable thing in this market and the least informative: what a plan buys changes monthly, almost always upward, and the dates that matter next are August 31 (Sonnet 5's price cliff) and whenever Anthropic gives notice that the metering framework is back.
This guide reflects Claude Cowork pricing and the agent ecosystem as of August 5, 2026, with every price and limit verified against the linked official pages on that date. Pricing, usage limits, model availability, and benchmark standings change frequently: verify current details against the linked sources before purchasing. This page will be updated after September 1, 2026 to record whether Sonnet 5's introductory pricing reverted on schedule.