Deep Agents

Framework · Last verified 2026-09-30

TL;DR

Deep Agents is LangChain's open-source agent harness for Python, built on LangGraph, with a separate TypeScript library. It ships a ready-to-run agent with a pluggable filesystem, shell access, subagents with isolated context, skills, memory and tool-call approval. It suits developers who want a long-horizon agent they can extend rather than assemble from parts.

Key facts

Deep Agents key facts. Data as of 2026-09-30.
Type Framework
Languages / SDKs Python, TypeScript
License MIT
Pricing model Open core
Orchestration pattern Supervisor
GitHub stars 29,863 (as of 2026-09-30)
GitHub forks 4,199
Last push 2026-09-30
Latest release deepagents==0.7.20
Repository langchain-ai/deepagents
Website docs.langchain.com
Documentation docs.langchain.com
Last verified 2026-09-30

Key features

  • create_deep_agent returns a LangGraph agent preloaded with file tools, subagent delegation, summarization and context offloading. (source)
  • Subagents are spawned through a task tool, each with its own prompt, tools and isolated context; only the final result returns. (source)
  • Async subagents run in the background on Agent Protocol servers while the supervisor keeps talking to the user. (source)
  • Pluggable filesystem backends: thread-scoped state, local disk, LangGraph store, local shell, or composite routes. (source)
  • Sandbox backends run the agent's execute tool in isolated environments. (source)
  • interrupt_on pauses chosen tool calls for approve, edit, reject or respond decisions, optionally with a condition. (source)
  • Long-term memory as files the agent reads into its prompt and updates with its edit tool. (source)
  • Protocol endpoints documented for MCP tools, an A2A server, AG-UI and the Agent Client Protocol (ACP). (source)

Architecture and orchestration pattern

Pattern: Supervisor

Deep Agents sits on top of LangChain's create_agent, which runs on the LangGraph runtime. create_deep_agent returns a compiled LangGraph graph, so streaming, checkpointing and deployment work the same way as any LangGraph app; behaviour is added through middleware (filesystem, subagents, summarization, skills, and to-do planning, which is opt-in since 0.7).

Multi-agent work is supervisor-style. The main agent calls a task tool naming a subagent; the subagent runs with its own instructions, tools and context window and hands back only its final answer. Async subagents run as separate threads on Agent Protocol servers and can be steered or cancelled, and any compiled LangGraph graph can be plugged in as a subagent.

Short-term state lives in LangGraph checkpoints per thread. Files the agent writes go to a backend you choose, from ephemeral graph state to local disk or a LangGraph store, and long-term memory is simply files on a persistent route that are loaded into the prompt or read on demand.

Human in the loop

Pass interrupt_on to create_deep_agent, mapping tool names to True, False or an InterruptOnConfig with allowed decisions and an optional when predicate. When a listed tool is called, the run stops with an __interrupt__ entry describing the pending actions; the app resumes with Command(resume={"decisions": [...]}) using approve, edit, reject or respond. A checkpointer and the same thread_id are required. Async subagents can also be steered or cancelled mid-run.

Protocols

MCP, A2A and AG-UI support for Deep Agents. See the full matrix.
ProtocolSupportNote
MCP Yes evidence
checked 2026-09-30
Client: tools from any MCP server are loaded with LangChain's MCPAdapter (langchain[mcp], beta namespace) and passed to create_deep_agent.
A2A Partial evidence
checked 2026-09-30
Server only: a deep agent served by Agent Server (langgraph dev or a LangSmith deployment) exposes /a2a/{assistant_id}; no A2A client for calling remote agents is documented in the library.
AG-UI Yes evidence
checked 2026-09-30
Adapter: serve the deep agent as a LangGraph server and connect the TypeScript @ag-ui/langgraph adapter (or a CopilotKit bridge); deepagents has no built-in AG-UI endpoint of its own.

Best for

  • Long-running coding or research agents that need a scratch filesystem, shell and delegation out of the box.
  • Research agents that fan work out to subagents and write a report, as in the official deep research tutorial.
  • Teams already on LangGraph who want a higher-level harness with the same runtime and deployment path.
  • TypeScript teams, via the separate deepagents.js library.

Not for

  • Workloads that rely on the model to police itself; the project states a trust-the-LLM security model.
  • Users who want explicit graph control over every step (LangGraph itself fits better, per the README).
  • Setups that need an A2A client or A2A without running an Agent Server.

Quickstart

pip install deepagents

Install not yet verified by this site. What this means

from deepagents import create_deep_agent
from langchain.tools import tool
from langgraph.checkpoint.memory import MemorySaver
from langgraph.types import Command

@tool
def publish(text: str) -> str:
    """Publish the final text."""
    return "published"

reviewer = {"name": "reviewer", "description": "Checks drafts for errors.", "system_prompt": "List factual or spelling errors.", "tools": []}
agent = create_deep_agent(model="anthropic:claude-sonnet-4-6", tools=[publish], subagents=[reviewer],
                          interrupt_on={"publish": True}, checkpointer=MemorySaver())

config = {"configurable": {"thread_id": "demo-1"}}
result = agent.invoke({"messages": [{"role": "user", "content": "Draft a 2-line changelog, get it reviewed, then publish it."}]}, config=config)
if result.get("__interrupt__"):  # a human approves the publish call
    result = agent.invoke(Command(resume={"decisions": [{"type": "approve"}]}), config=config)
print(result["messages"][-1].content)

Common pitfalls

  • Set the key for your model provider (for example ANTHROPIC_API_KEY or OPENAI_API_KEY); models are named as provider:model.
  • Human-in-the-loop needs a checkpointer, and the resume call must reuse the same thread_id.
  • Since 0.7.0 the to-do planning middleware is opt-in: pass middleware=[TodoListMiddleware()] to get write_todos back.
  • MCP tools need langchain[mcp]>=1.4.0, whose langchain.mcp namespace is beta.
  • Since 0.7.0, FilesystemBackend and LocalShellBackend default to virtual_mode=True, so paths outside root_dir raise ValueError.
  • The default backend keeps files in thread state only; choose a filesystem, store or composite backend for persistence, and a sandbox backend before letting the agent run shell commands.

Official quickstart

Pros

  • Runs out of the box with opinionated defaults, while any piece can be overridden or replaced. (source)
  • Built on LangGraph, so streaming, persistence and checkpointing come with the runtime. (source)
  • Works with any tool-calling model, including self-hosted ones through Ollama, vLLM or llama.cpp, per the README FAQ. (source)
  • Per-tool human review with approve, edit, reject and respond decisions and conditional interrupts. (source)
  • Documented integrations for MCP, A2A, AG-UI and ACP cover tools, other agents, frontends and editors. (source)

Cons

  • 0.7.0 shipped breaking changes: to-do planning became opt-in and backend factory APIs were removed. (source)
  • The README describes a trust-the-LLM model: the agent can do anything its tools allow, so limits must be enforced by tools or sandboxes. (source)
  • The A2A endpoint exists only when the agent is served by Agent Server; no client-side A2A support is documented. (source)
  • MCP support relies on LangChain's langchain.mcp namespace, which the docs label beta and subject to change. (source)
  • Since 0.7.0 agents get a recursive delete tool when the backend supports it, and a write permission on a path also authorizes deleting that subtree unless a deny or interrupt rule covers it. (source)

Alternatives

FAQ

How is Deep Agents different from LangGraph and LangChain?

Per the README, LangGraph is the graph runtime, LangChain's create_agent is a minimal harness on top of it, and Deep Agents is a more opinionated harness on create_agent with filesystem, subagents, context management and skills bundled.

Does Deep Agents support MCP, A2A and AG-UI?

MCP tools load through LangChain's MCPAdapter. A2A is server-side only, via Agent Server's /a2a endpoint. AG-UI works by serving the agent as a LangGraph server behind the @ag-ui/langgraph adapter.

Is Deep Agents free?

The library is MIT-licensed. LangChain sells LangSmith (tracing, evaluation and deployment), which the docs recommend for production but which is optional.

Can a human approve Deep Agents tool calls?

Yes. interrupt_on pauses chosen tools; you resume with approve, edit, reject or respond decisions. It requires a checkpointer and the same thread_id.

Is there a JavaScript version?

Yes, the README points to deepagents.js, a separate JavaScript/TypeScript library.

Sources