DeepSeek Harness
TL;DR
DeepSeek Harness (dsh) is an MIT-licensed agent harness from DeepSeek AI, built as a tree of plugins on the Cordis framework, with a web UI, desktop app, headless runner and TypeScript and Python SDKs. It can delegate to subagents, including real Codex and Claude Code sessions. The README labels it a developer preview with breaking changes expected.
Key facts
| Type | Harness |
|---|---|
| Languages / SDKs | TypeScript, Python |
| License | MIT |
| Pricing model | Open source, free |
| Orchestration pattern | Supervisor |
| GitHub stars | 240,788 (as of 2026-09-30) |
| GitHub forks | 28,922 |
| Last push | 2026-09-29 |
| Latest release | No release published |
| Repository | deepseek-ai/deepseek-harness |
| Website | deepseek.com |
| Documentation | deepseek-harness.github.io |
| Last verified | 2026-09-30 |
Key features
- Everything-is-a-plugin architecture on Cordis: the model adapter, tool registry, session log and agent loop are plugins that can be replaced from configuration through profiles, bundles and patch files. (source)
- Shipped profiles for a web app, a headless one-shot runner, a TypeScript SDK, a minimal SDK and an ACP agent, plus an Electron desktop application. (source)
- A subagent family: fresh or history-seeded in-process children, and out-of-process children over ACP, through the Codex app-server, through the Claude Code Agent SDK, or through the dsh SDK, with tools to message, interrupt and list children. (source)
- A
workflowtool that runs model-written orchestration scripts fanning out subagents, and an opt-inralphtool that runs a fixed sequence of fresh agents. (source) - Background jobs that the owning agent can read, wait on, list and cancel, with completion delivered into the session. (source)
- A durable per-session goal with a
/goalcommand and optional automatic continuation across restarts, resumes and forks. (source) - Human collaboration controls: slash commands, one-shot approvals that fail closed without an answerer, permission presets pairing sandbox mode with approval policy, and an
ask_user_questiontool. (source) - MCP client and resource packages, and a hooks group that runs existing Claude Code and Codex hooks.json shell hooks. (source)
Architecture and orchestration pattern
Pattern: Supervisor
dsh is a TypeScript monorepo in which everything is a Cordis plugin contributing services, typed events and reversible effects to a shared context. A running instance is a plugin tree composed at boot from a profile: an ordered stack of bundles plus patch files, from a shared base layer (model adapters, tools, persistence, sandbox and approval policy, settings, credentials, telemetry) up to the web, headless, SDK or ACP application. A Python SDK launches the same CLI with the sdk profile.
Multi-agent work runs through a delegation seam. A parent agent can spawn an in-process child or a child in another process; the out-of-process providers include ACP-compatible agents, Codex and Claude Code, and each child is visible to its parent. The Codex and Claude Code providers run one unattended, self-contained text task and return only the final answer, keeping intermediate traffic out of the parent session. Orchestration scripts can fan out children, and background jobs let a parent continue while children run.
State is an append-only session event log with agent-level live events; a goal records durable completion state per session, and scheduled reminders persist across host restarts. The docs describe the loop, tool pipeline and event producers in detail and assume familiarity with Cordis.
Human in the loop
The interaction group provides slash commands, one-shot approval prompts that fail closed when no answerer exists, permission presets that combine a sandbox mode (read-only, workspace-write or danger-full-access) with an approval policy, and a tool the model uses to ask the human a question. Plan mode presents a plan for approval before execution. Automation profiles answer approvals through ACP instead of a person, and the Codex and Claude Code child providers run unattended. The safety notice says sandboxing and approvals reduce risk but do not guarantee isolation.
Harnesses it can drive
- Claude Code (evidence)
- Codex (evidence)
Protocols
| Protocol | Support | Note |
|---|---|---|
| MCP | Yes evidence | Client side: mcp-client connects one configured MCP server and exposes its tools and instructions, and mcp-resources reads server resources. No MCP server mode is documented. |
| A2A | Unknown | No A2A / Agent2Agent mention in the README or package docs read; the only hits are design notes, one saying A2A remains a future sibling transport to the ACP subagent backend, which is not shipped support. |
| AG-UI | Unknown | No AG-UI mention in the README or package docs read; repo code search for ag-ui returned nothing; not checked against a listing in the AG-UI README. |
Best for
- Developers who want a plugin-composed agent harness with web, desktop, headless and SDK entry points on the same runtime. (shortlist)
- Delegating tasks from one agent to real Codex or Claude Code sessions, ACP agents or other dsh instances as subagents. (shortlist)
- Scripted fan-out of subagents with a model-written workflow, plus background jobs and durable goals for long tasks. (shortlist)
- Teams building on TypeScript or Python SDKs that need to embed a harness and replace individual parts such as the model adapter or tool registry. (shortlist)
Not for
- Production or security-sensitive use; the safety notice says it has not had a security audit and must not be treated as secure.
- Setups that need stable interfaces; the README warns that compatibility-breaking changes will happen.
- Readers unfamiliar with Cordis who want to modify the internals; the architecture doc assumes Cordis knowledge.
Quickstart
npx @deepseek-ai/dsh web # Needs Node.js. Starts the Web UI at http://127.0.0.1:3080
npx @deepseek-ai/dsh web
# server only, no browser
npx @deepseek-ai/dsh web --no-open
# From a checkout
git clone https://github.com/deepseek-ai/deepseek-harness.git
cd deepseek-harness
pnpm install
pnpm run build
pnpm dsh web
# Print the plugin tree that a profile boots (with dsh on the PATH)
dsh --profile web --dump-config
Common pitfalls
- The project is a developer preview and the README warns of compatibility-breaking changes; read SAFETY.md before running it.
- GitHub releases so far are release-candidate pre-releases (for example dsh-v0.2.0-rc.2), not stable versions.
- Run it with least privilege, preferably in a disposable VM or container; sandboxing and approvals do not guarantee isolation.
- The Codex and Claude Code subagent providers use the native authentication and settings of those tools, and run unattended.
- Building from source uses pnpm;
pnpm run buildmust run beforepnpm dsh web. - Desktop and npm CLI share product data but keep packages, activation and lockfiles separate.
Pros
- Documented delegation to real Codex and Claude Code sessions and to any ACP-compatible agent, so one harness can drive several coding agents. (source)
- Every layer, including the agent loop, is a replaceable plugin, and
--dump-configprints the exact tree a profile boots. (source) - Permission presets pair sandbox mode with approval policy, and approvals fail closed when no answerer is present. (source)
- Existing Claude Code and Codex shell hooks can be reused through the hooks group. (source)
- MIT licensed, with a candid safety notice and per-package documentation for every capability group. (source)
Cons
- Developer preview: the README says compatibility-breaking changes will occur. (source)
- The safety notice says the project has had no security audit, can execute model-generated code and commands, and that sandboxing and approvals do not guarantee isolation. (source)
- Only release-candidate pre-releases are published on GitHub, with no stable release yet. (source)
- The Codex and Claude Code subagent providers handle one self-contained text task per run and return only the final answer or a failure diagnostic. (source)
- The architecture guide assumes Cordis knowledge and points newcomers to a separate primer and tutorial. (source)
Alternatives
FAQ
Does DeepSeek Harness support MCP?
Yes, as a client. The mcp-client package connects a configured MCP server and exposes its tools and instructions, and mcp-resources reads its resources. No MCP server mode is documented.
Can it run other coding agents?
Yes, as subagents. The subagent family includes providers that run a real Codex session through its app-server protocol, a real Claude Code session through the Agent SDK, and any ACP-compatible agent in a subprocess. Each returns a final answer to the parent.
Is it stable?
No. The README calls it a developer preview with compatibility-breaking changes expected, and its GitHub releases are release candidates. The safety notice says it has not been security audited.
Is it tied to DeepSeek models?
The repository is developed by DeepSeek AI and includes a DeepSeek API key adapter, but its architecture treats the model adapter as a replaceable plugin. Check the model adapter packages for the providers you need.
Is it free?
The repository is MIT licensed and no paid product is documented. Model API usage is billed by the provider you configure.
Sources
- DeepSeek Harness architecture
- Subagent capability family README
- Workflow group README
- Jobs group README
- Goal group README
- Interaction group README
- MCP group README
- Hooks group README
- DeepSeek Harness safety notice
- DeepSeek Harness README
- DeepSeek Harness releases
- Codex subagent provider README
- DeepSeek Harness README, run section
- DeepSeek Harness homepage (repository homepage)
- DeepSeek Harness documentation site
- deepseek-ai/deepseek-harness GitHub repository