# Deep Agents: LangChain's Batteries-Included Agent Harness

> Deep Agents bundles filesystem access, sub-agents, context management and skills on top of LangChain's create_agent. It is a real convenience layer with a real cost: a trust-the-LLM security model and a fast-moving dependency on LangGraph.

**langchain-ai/deepagents** — The batteries-included agent harness. Use LangChain's create_agent when you want a lighter harness without the bundled middleware.

- Repository: https://github.com/langchain-ai/deepagents
- Website: https://docs.langchain.com/deepagents
- Stars: 29,766 · Forks: 4,180
- Language: Python
- License: MIT
- Published: 2026-08-04 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/langchain-ai-deepagents

## What Deep Agents solves, and who it is for

Building an agent that works across many steps is mostly plumbing. The model call is the easy part. The hard parts are keeping the context window from filling up, letting the agent read and write files, delegating subtasks so one long thread does not drown in detail, and remembering anything across sessions. Deep Agents ships those pieces as a single harness. The README calls it "an opinionated agent that runs out of the box" and lists sub-agents, a filesystem, context management, shell access, persistent memory, human-in-the-loop approval, skills and tool integration as included features.

The target reader is a Python developer who has already decided an agent loop is the right shape for the problem, and who would rather override defaults than write them. The README's own framing puts the three layers in order: LangGraph is the graph runtime, LangChain's create_agent is a minimal harness on top of it, and Deep Agents is a more opinionated harness on top of create_agent. If you want the lighter harness, the README says to use create_agent directly. If the agent loop itself is the wrong shape, it says to drop to LangGraph.

That layering matters because it tells you what you are buying. You are not buying a different runtime. You are buying a set of middleware and conventions that sit on the same building blocks.

## The mechanism: middleware over create_agent, not a new runtime

The central API is create_deep_agent. You pass a model, a list of tools and a system prompt, and you get back an agent object with an invoke method. That signature is the whole architecture in miniature: the harness supplies the middleware, you supply the domain.

The four bundled capabilities are where the opinion lives. Sub-agents delegate tasks to agents with isolated context windows, which is the standard way to keep a long research thread from consuming the parent's budget. The filesystem lets the agent read, write, edit or search over pluggable local, sandboxed or remote backends. Context management summarizes long threads and offloads tool outputs to disk, which is the same idea applied to the parent thread. Persistent memory uses pluggable state and store backends for cross-session recall.

Because it is built on LangGraph, the streaming, persistence and checkpointing behavior comes from the runtime rather than from the harness. That is a genuine advantage and also the main coupling risk: the harness inherits LangGraph's release cadence. The README also notes that any LangGraph CompiledStateGraph can be passed in as a sub-agent, so custom orchestration plugs in alongside the defaults rather than replacing them. Skills are described as reusable behaviors the agent can load on demand, which keeps rarely used instructions out of the base prompt.

## Installing Deep Agents and running a first agent

The README uses uv for installation. One command adds the package.

```bash
uv add deepagents
```

The quickstart then builds an agent with a model string, a tool list and a system prompt. Note the model identifier as written in the README; substitute a model you actually have access to, since the harness is model-agnostic and only requires tool calling.

```python
from deepagents import create_deep_agent

agent = create_deep_agent(
    model="openai:gpt-5.5",
    tools=[my_custom_tool],
    system_prompt="You are a research assistant.",
)
result = agent.invoke({"messages": "Research LangGraph and write a summary"})
```

After invoke returns, the README says the agent can plan, read and write files, and manage its own context. That is the part worth verifying on your first run: watch whether the agent actually reaches for the filesystem tools and whether tool outputs get offloaded as the thread grows. The README does not document what the returned result object contains beyond the messages you passed in, so inspect it rather than assuming a schema.

There is a separate product in the same repository worth distinguishing. Deep Agents Code is a pre-built terminal coding agent, described as similar to Claude Code or Cursor, powered by any LLM. It installs with a shell one-liner.

```bash
curl -LsSf https://langch.in/dcode | bash
```

That is a different artifact from the library. If you want the library, use uv add deepagents; the curl installer is for the terminal agent.

## The security model is a boundary you must supply

The README is unusually direct about this, and it deserves to be quoted rather than paraphrased: Deep Agents follows a "trust the LLM" model, and the agent can do anything its tools allow. The recommended posture is to enforce boundaries at the tool and sandbox level rather than expecting the model to self-police.

That is the correct design for a general harness, and it is also the single largest thing a new user underestimates. The harness ships shell access, which the README describes as running commands in your sandbox of choice. The phrase "of choice" is doing the work: Deep Agents does not pick or harden a sandbox for you. If you wire shell access to the host, you have given the model the host. The same logic applies to the filesystem backends, which can be local, sandboxed or remote.

Human-in-the-loop approval, described as approving, editing or rejecting tool calls before they run, is the harness-level control you have. It is a real mitigation and it is not a substitute for a sandbox, because approval fatigue is a known failure mode when a long-horizon agent makes many calls. Treat the approval gate as a second layer, not the first.

## Context management is the feature that decides whether this fits

Long-horizon, multi-step work is the stated design target, and context management is the mechanism that makes it possible. Two pieces do the work: summarizing long threads, and offloading tool outputs to disk. The second is the more interesting one because it changes where state lives. A tool result that would otherwise sit in the message history becomes a file the agent can read again if it needs to.

That is a real trade-off rather than a free win. Offloading keeps the window small, but it means the agent's working state is now split between the conversation and a filesystem backend. If that backend is remote, every re-read is a round trip. If it is local, you have introduced a persistence concern into what looked like a stateless agent. The README does not document eviction policy, summarization thresholds or what happens when the backend is unavailable, so those are questions to answer from the API reference and from reading the middleware source before you depend on them.

Sub-agents have a related cost. Isolated context windows keep the parent clean, but information crossing the boundary has to be summarized, and summarization loses detail. The README does not specify how results are returned from a sub-agent to its parent.

## Deep Agents vs LangGraph, create_agent and Claude Code

The README answers the LangGraph comparison itself, and the answer is not competitive. All three are layers in the same stack. LangGraph is the graph runtime. create_agent is a minimal harness on top of it. Deep Agents is a more opinionated harness on top of create_agent, with filesystem, sub-agents, context management and skills bundled in. Choosing Deep Agents over create_agent is choosing bundled middleware over assembling it. Choosing LangGraph over either is choosing a custom graph because the agent loop is the wrong shape.

The comparison with Claude Code is different in kind, because the README names Claude Code as the inspiration rather than a peer. The acknowledgement says Deep Agents is "inspired by Claude Code: an attempt to identify what makes it general-purpose, and push that further." The concrete differences the README supports are model-agnosticism, since any model supporting tool calling works, and the fact that the harness is a library you embed rather than a terminal product. Deep Agents Code is the terminal-shaped counterpart in the same repository.

The README also states there is a JavaScript/TypeScript library, deepagents.js, in a separate repository. If your stack is TypeScript, that is the artifact to look at; this page covers the Python package.

## Maintenance, versioning and licence

The repository is not archived. The last push was on 2026-08-28, and the most recent release in the same window was deepagents==0.7.11, with deepagents==0.7.10 the day before and deepagents-talon==0.0.6 alongside it. The version number is the relevant signal here: 0.x releases, with two patch releases in two days, indicate a project still settling its API. Pin your version and read the release notes before upgrading.

The Python package is MIT licensed, which is permissive and places few obligations on how you redistribute or embed it. The repository also contains a deepagents-talon package and a separate deepagents.js library in another repository, each with its own release stream. The README does not state the licence of those separate artifacts, so check them independently if you depend on them. This is an observation about what the README documents, not legal advice.

Upgrade cost is dominated by the LangGraph dependency. Because streaming, persistence and checkpointing come from the runtime, a LangGraph change can surface as a Deep Agents behavior change even when the harness itself did not move.

## Conclusion

Adopt Deep Agents when you want planning, filesystem access, sub-agents and context management without assembling them yourself, and when you can enforce boundaries at the tool and sandbox level rather than relying on the model. Do not adopt it if you need a minimal loop with full control over every step, or if you cannot accept a harness that follows a trust-the-LLM security model. Before committing, verify three things: which LangGraph version your install resolves to, whether your chosen model supports tool calling, and how your sandbox constrains shell access. The repository's own examples/ directory, including examples/deep_research/ and examples/text-to-sql-agent/, is the fastest way to see whether the bundled middleware matches your workload.

## FAQ

### How do I install Deep Agents?

The README's quickstart uses uv and a single command, uv add deepagents. There is also a separate terminal product, Deep Agents Code, installed with curl -LsSf https://langch.in/dcode | bash.

### What is Deep Agents Code?

The README describes it as a pre-built coding agent in your terminal, similar to Claude Code or Cursor, powered by any LLM. It is installed separately from the deepagents Python library and has its own documentation page.

### Is Deep Agents open source?

Yes. The repository is public, the Python package is MIT licensed, and the README links to a contributing guide and code of conduct. The JavaScript/TypeScript library lives in a separate repository.

### What is the difference between Deep Agents and LangGraph?

LangGraph is the graph runtime. Deep Agents is a harness built on LangChain's create_agent, which itself sits on LangGraph. The README says to drop to LangGraph when the agent loop is not the right shape and you need a custom graph.

### What are the key differences between Deep Agents and Claude Code?

The README says Deep Agents was inspired by Claude Code, an attempt to identify what makes it general-purpose and push that further. Deep Agents is a library that works with any model supporting tool calling, while Deep Agents Code is the terminal-shaped product in the same repository.

### What is Deep Agents?

The README describes it as the batteries-included agent harness: an opinionated agent that runs out of the box, built on LangGraph, with sub-agents, filesystem access, context management, shell access, persistent memory, human-in-the-loop approval and skills.

## Sources

- [Official documentation](https://docs.langchain.com/deepagents)
- [Official README](https://github.com/langchain-ai/deepagents#readme)
- [Project repository](https://github.com/langchain-ai/deepagents)
- [Release notes](https://github.com/langchain-ai/deepagents/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/langchain-ai-deepagents
