agentboards.org

Deep Agents

#8 agent frameworkverified Sep 4, 2026deepagents==0.7.21

LangChain's batteries-included agent harness: sub-agents, a pluggable filesystem, shell access, skills and MCP tools

Key differences

LangChain's batteries-included agent harness: sub-agents, a pluggable filesystem, shell access, skills and MCP tools

  • Runs local. Free and open source under MIT; you pay whichever model provider you point it at, or run an open-weight model locally
  • Runs local models. Listed for 60 of 118 tools in this category.
  • Runs multiple agents. Listed for 97 of 118 tools in this category.
  • Keep in mind: Shell access runs commands in whichever sandbox backend you configure.

“It ships in Python and TypeScript, so your team can keep arguing about the language and still lose the argument to the same harness.”

Website Docs 30k starsCompare vs…Dispute a fact
Appeal a claim or request ownership transfer

What it is

Deep Agents is LangChain's opinionated agent harness: an agent that runs out of the box with defaults tuned for long-horizon, multi-step work, where any piece can be overridden or replaced without forking. It ships sub-agents that take delegated tasks in isolated context windows, a filesystem tool set that reads, writes, edits and searches over pluggable local, sandboxed or remote backends, context management that summarises long threads and offloads tool output to disk, shell access into a sandbox of your choice, persistent memory with pluggable state and store backends, human-in-the-loop approval of tool calls before they run, on-demand skills, and your own functions or any MCP server as tools. It is model-agnostic across frontier, open-weight and local models, and is built on LangGraph for streaming, persistence and checkpointing. It exists as both a Python package and a JavaScript/TypeScript library, and a prebuilt terminal coding agent, Deep Agents Code, is built on it.

Specification

Source verification

Row snapshot checked 2026-09-04. Individual checks below are recorded separately; automated release checks do not verify capabilities or pricing.

overview
Needs individual review
capabilities
Needs individual review
protocols
Needs individual review
models
Needs individual review
install
Needs individual review
license
Needs individual review
first_release
Needs individual review

Architecture

Type
Agent framework
Runssrc ↗
local
Platforms
macos, linux, windows
Context windowsrc ↗
not documented
Languages
python, typescript

Models

Backbonesrc ↗
any tool-calling LLM, frontier models, open-weight models, local models
Bring your own model
Yes
Local models
Yes

Protocols

MCP clientsrc ↗
Yes
MCP server
No
OpenAPI tools
No

Capabilities

Terminal commandssrc ↗
Yes
Multi-file edits
Yes
Git operations
No
Browser control
No
Sandboxed execution
No
Filesystem and shell backends are pluggable between local, sandboxed and remote, but the README names no specific container runtime.
Multi-agent
Yes
Headless / CI
No

Cost

Modelunsourced
byok
Starts at
$0/mo
Free tier
Yes
Bring your own key
Yes

Free and open source under MIT; you pay whichever model provider you point it at, or run an open-weight model locally

Openness

Open sourcesrc ↗
Yes
License
MIT
First release
2025-07
open-sourcelangchainlanggraphsub-agentsskillsmcpharness

Los Agentes on Deep Agents

Who are they?
The ruling
El JuezThe judge

The panel agrees within three points and the one gap that matters is El Crítico's: the isolation everyone assumes is present is a backend you have to choose.

Adopt
Reasoning and trade-offs · AI analysis

Agreement is the story. El Hacker likes the licence and the model freedom, El Profesor likes the context handling, La Inversora likes the distribution, and none of them found a dealbreaker. La Jefa scores lowest, and she is answering a question this row never posed: nothing here was offered as a product she administers.

El Crítico is the one to read twice. His point is not that the design is wrong but that a configurable boundary is an unconfigured boundary until somebody sets it. Adopt, if you are building the agent rather than buying one, and pick the shell backend before the first command runs.

Agree with El Juez?
El AmigoThe friend

Pick this when you want a working agent today and the freedom to replace one piece later; pick a smaller library if you would rather understand every line first.

8.0
Reasoning and trade-offs · AI analysis

The deciding trait is that the defaults are opinionated and none of them are load-bearing. You start with something that already works for long, multi-step tasks, and when a piece is wrong for you, you replace that piece instead of forking the project or rebuilding around it. That is a rare combination and it is why this one is worth the first hour.

What you inherit is a large vendor's idea of how agents should be structured, which is comfortable until you disagree with it. Pick it if you want momentum. Pick a smaller library if you would rather own every decision.

reliability
7
usefulness
8
cost
9
longevity
8
Agree with El Amigo?
El CríticoThe critic

Shell access runs in a sandbox of your choosing and the documentation names no container runtime, so the isolation is a backend you must supply and can forget to.

6.8
Reasoning and trade-offs · AI analysis

The gap is the default. Filesystem and shell backends are pluggable between local, sandboxed and remote, which is the correct architecture and also means the safe option is a choice rather than a starting point. A developer who wires this up quickly gets a shell tool pointed at the machine they are sitting at, and nothing in the row says that is unusual.

What it does right is delegation. Sub-agents receive tasks in separate context windows, so a long side quest does not poison the parent thread with its own transcript.

reliability
6
usefulness
7
cost
7
longevity
7
Agree with El Crítico?
El ProfesorThe professor

Context management is explicit: long threads are summarised and tool output is offloaded to disk rather than carried, which treats the window as a budget instead of a container.

8.0
Reasoning and trade-offs · AI analysis
  1. Offloading tool results to files and referring to them by path is the correct treatment of large observations, because it decouples what the agent can access from what it must currently hold. 2. Summarisation of long threads is applied as a documented stage rather than left to a prompt instruction, which makes the loss of detail a design decision instead of an accident.

  2. Checkpointing under the graph runtime means a run has resumable states, so failure analysis starts from a recorded position. 4. No evaluation is published and none is claimed.

reliability
8
usefulness
8
cost
8
longevity
8
Agree with El Profesor?
La InversoraThe investor

Twenty-nine thousand stars and three hundred thousand weekly npm installs make this a distribution asset, and LangChain has already shown it can convert that into a paid platform.

8.0
Reasoning and trade-offs · AI analysis

This is the strongest position on the open side of the category. A vendor with an existing developer base publishes the harness free, the harness pulls people onto the runtime underneath it, and the runtime is where the commercial platform lives. The giveaway is not charity, it is the cheapest customer acquisition in developer tooling.

Moat: distribution and habit, both real and both durable. Pricing power sits one layer up, not here. Likely path: this stays free indefinitely because it has to. Position: safe to depend on, and read the terms of the layer above before you depend on that too.

reliability
8
usefulness
8
cost
8
longevity
8
Agree with La Inversora?
La JefaThe CTO

No licence cost across sixty engineers, and the only governance primitive in the row is that a human can approve tool calls before they execute.

6.8
Reasoning and trade-offs · AI analysis

The approval gate is the part procurement can use. A documented interruption before a tool runs means an operator can be inserted into the loop by policy rather than by convention, and that is the difference between a control and a hope. I would make it mandatory in anything we deploy.

Everything else remains ours. No console, no identity integration, no retention statement, and nothing that runs unattended, so this is a component my platform team wraps in a service and operates. Approved with conditions: approval gates on, and one owning team accountable for the spend.

reliability
6
usefulness
5
cost
9
longevity
7
Agree with La Jefa?
El HackerThe tinkerer

MIT, `uv add deepagents`, any MCP server becomes a tool, and it is model-agnostic down to open-weight models on my own machine.

8.8
Reasoning and trade-offs · AI analysis

Model freedom here is not a footnote. Frontier, open-weight and local are all first-class, so the same harness runs against my box or somebody's API without a different code path, and my key pays for whichever I chose. MCP servers arrive as tools directly, so the things I already run plug in without an adapter.

The permissive licence means a fork outlives the vendor, which matters more here than usual because the vendor is large enough to change direction. Every piece is replaceable without forking, and that claim survives contact with the source.

reliability
9
usefulness
9
cost
9
longevity
8
Agree with El Hacker?