Deep Agents
github.com/langchain-ai/deepagents- Category
- AI Agents
- Rank
- No. 707Tools index
- Pricing
- Open Source
- Type
- TOOL
- Use case
- Agent Building
- Interfaces
- CLI · SDK · API
- Builder
- langchain-ai
- GitHub
- 30.1k stars
- Latest release
- deepagents==0.7.23
- Date
About
Deep Agents is LangChain's open-source agent harness that ships with built-in filesystem access, subagent delegation, context/memory management, and human-in-the-loop controls for building long-horizon, multi-step LLM agents. It sits atop LangGraph and LangChain's create_agent, works with any tool-calling model, and includes a companion terminal coding agent (Deep Agents Code).
What it does
This is a batteries-included toolkit for building AI agents that keep working through jobs too large for a single context window. It gives an agent a working-memory model: notes written to a virtual disk, pieces of a job handed off to helper agents running in their own isolated context, and a checkpoint where a person can approve or block a risky action before it executes. A companion terminal application packages the same machinery as a ready-made coding assistant. Any large language model that supports tool calling can drive it, not just one vendor's models.
Why it's ranked here
This is a well-organized project, not just a wrapper script: a documented three-layer architecture separates the runtime, the agent abstraction, and the harness, and the monorepo splits cleanly into an SDK, a terminal coding agent, an editor integration, and a dedicated evaluation suite with its own command-line tool. MIT licensing and model-agnostic design, including self-hosted models, make it easy to adopt. The catch: the project states its security model plainly as trusting the model to behave, and pushes sandboxing entirely onto whoever wires up the tools.
What's good
The model-agnostic design is real, not marketing: it runs against frontier APIs, open-weight models hosted by other providers, and fully local models through common self-hosting tools, with no code changes beyond swapping the model string. Work can be delegated to helper agents that get their own context window instead of polluting the main thread, and a human approval step can intercept a tool call before it runs rather than only reviewing after the fact. Storage is pluggable too, so files an agent writes can live on local disk, in a sandbox, or on a remote backend depending on how much isolation a deployment needs.
Tradeoffs
There is no built-in sandbox: the project says outright that the agent can do anything its tools allow, so safety has to be enforced by whoever configures the backend and tools, not by the framework itself. It is also tightly coupled to LangChain's ecosystem for its runtime, tracing, and evaluation pipeline, so adopting it means signing up for that stack rather than a standalone library. The JavaScript version lives in a separate repository, so teams outside Python get a smaller, differently maintained slice of the same idea.
How to use it well
Reach for this when you want a full agent harness out of the box: planning, delegation, memory, and approval steps already wired together, so you configure rather than assemble from scratch. Try it first through the terminal coding agent to see the pieces working before writing any code. Skip it if you only need a thin agent loop with no bundled middleware, since a lighter harness one layer down already covers that, or if you need a custom orchestration shape the standard agent loop cannot express.
Technical notes+
The middleware layer documented in libs/deepagents/deepagents/middleware/__init__.py is the actual mechanism: middleware subclasses override a model-call hook that runs before every LLM request, which is how FilesystemMiddleware, MemoryMiddleware, and SummarizationMiddleware inject prompt text or filter tools, something a plain function passed to the tools list cannot do. libs/ARCHITECTURE.md lays out the three-layer split (LangGraph runtime, LangChain's create_agent, and the Deep Agents harness on top) and names construction and execution as the two phases worth tracing when changing behavior. The ACP bridge in libs/acp/deepagents_acp/server.py wraps a compiled LangGraph agent to speak the Agent Client Protocol, which is how the same agent runs inside an editor like Zed. libs/evals/deepagents_evals/cli.py defines a separate deepagents-evals console script with run, trials, aggregate, and radar subcommands, plus three distinct exit codes for eval failures, configuration errors, and missing reports. libs/README.md lists six independently versioned packages under libs/ (deepagents, code, acp, evals, talon, partners), and both libs/README.md and AGENTS.md contain text addressed directly at an AI agent reading the repository rather than at a human contributor, including one line in libs/README.md instructing a 'coding agent' to refuse to continue until it has read the contributing guide.
Observed
- License
- MIT
- Language
- Python for the core SDK, terminal coding agent, ACP integration, and evals suite; a separate JavaScript/TypeScript package exists outside this repository
- Packaging
- Installable from PyPI as the deepagents package; the terminal coding agent is a separate deepagents-code package installed via a shell script or pip
- Interfaces
- Python library (create_deep_agent), a terminal CLI (dcode), an Agent Client Protocol server for editor integration, and a separate deepagents-evals command-line tool
- Repository structure
- Monorepo with six independently versioned packages: a core SDK, a terminal coding agent, an ACP integration, an evaluation suite, an experimental runtime host, and provider partner integrations
- Model support
- Works with any tool-calling model: frontier APIs, open-weight models hosted by third-party providers, and self-hosted models via Ollama, vLLM, or llama.cpp
- Dependency
- Built on LangGraph and LangChain's create_agent rather than a custom runtime
- Security model
- States it follows a 'trust the LLM' model and relies on tool- and sandbox-level enforcement rather than built-in guardrails
- Documentation
- Includes a generated internal documentation index alongside a hand-written architecture guide
Read from README.md, AGENTS.md, libs/deepagents/deepagents/__init__.py, libs/deepagents/deepagents/backends/__init__.py, libs/deepagents/deepagents/middleware/__init__.py, libs/deepagents/deepagents/profiles/__init__.py, libs/code/deepagents_code/main.py, libs/code/deepagents_code/app.tcss, libs/acp/deepagents_acp/server.py, libs/evals/deepagents_evals/cli.py, openwiki/architecture/index.md, openwiki/concepts/index.md, libs/ARCHITECTURE.md, libs/README.md, LICENSE.
What it can do
Provide agents with filesystem access for reading and writing files
File operations requested by agent → File system changes
Delegate tasks to subagents
Task description → Subagent execution results
Manage context and memory across long-horizon agent tasks
Conversation/task history → Persisted context/memory state
Enable human-in-the-loop approval controls during agent execution
Pending agent action → Human approval/rejection decision
Run a terminal-based coding agent
Coding task or command → Code changes or terminal output
Intel on Deep Agents
- Managed Deep Agents 0.9 adds Slack Reactions API
- Managed Deep Agents 0.8 adds HTTP channels for webhook-driven agents
- LangChain Pitches Deep Agents as a Fix for Context Engineering
- LangChain Ships Managed Deep Agents With Container-Based Evals
- Managed Deep Agents now bake their environment at deploy time
Tags
Media

Comments (0)
No comments yet
Editorially curated, with community endorsements as a secondary signal. Corrections welcome.