curl -LsSf https://langch.in/dcode | bash
# With model provider extras
# OpenAI, Anthropic, and Gemini are included by default
DEEPAGENTS_CODE_EXTRAS="nvidia,ollama" curl -LsSf https://langch.in/dcode | bash
Run:
dcode
The fastest way to start using Deep Agents. deepagents-code is a pre-built coding agent in your terminal — similar to Claude Code or Cursor — powered by any LLM that supports tool calling. One install command and you're up and running, no code required.
What deepagents-code adds on top of the SDK:
By default, dcode trusts the directory you run it in. Human-in-the-loop approval gates model-requested tool calls, but project artifacts are read before any approval prompt.
Do not run dcode in a directory you do not trust without a sandbox backend. For untrusted repositories, use a remote sandbox so execution is isolated from your machine. Running dcode in a directory lets that directory's files shape execution. See THREAT_MODEL.md for details.
See our Releases and Versioning policies.
As an open-source project in a rapidly developing field, we are extremely open to contributions, whether it be in the form of a new feature, improved infrastructure, or better documentation.
For detailed information on how to contribute, see the Contributing Guide.
This project was primarily inspired by Claude Code, and initially was largely an attempt to see what made Claude Code general purpose, and make it even more so.
The one-per-process result with named slots to prevent transposition.
Swap the model or per-call settings from runtime.context.
Full configuration payload passed from the app to the server subprocess.
Raised when a downloaded archive fails SHA-256 verification.
Raised when no managed helper binary is available for this system.
Goal/rubric text exceeds a model-visible context budget.
Additive token and estimated-cost accounting for one or more requests.
A priced side-operation delta pending checkpoint persistence.
Agent state extended with the cumulative thread-cost channel.
Own the thread's cumulative _session_cost_usd checkpoint value.
A transport-independent event delivered from outside the TUI.
Source of external events for the Textual app.
Line-delimited JSON event source over a local Unix domain socket.
Metadata for a custom subagent loaded from filesystem.
Parsed origin remote attribution for coding-agent-v1 traces.
Raised when an external editor cannot be opened or read.
Explicit user/project path context for project-sensitive behavior.
Line counts for a change, named so the pair cannot be swapped silently.
Data used to render HITL previews.
Line and byte level metrics for a file operation.
Track a single filesystem tool call.
Collect file operation metrics during an interaction.
A cache-using request's start time and effective cache identity.
Prompt-cache behavior needed to decide and price a warning.
Estimated input cost for a cold prefix and its warm-cache delta.
Validated data needed to render one advisory warning.
ACP server that supplies trusted classifier context in Auto mode.
Represents a pasted image with its base64 encoding.
Represents a pasted video with its base64 encoding.
Raised when model configuration or creation fails.
Raised when a model is outside the effective models.allowed policy.
Raised when no credentials are configured for any default-resolvable provider.
Raised when models.allowed is active but none of its models can auth.
Raised when neither the app nor init_chat_model can infer a provider.
Raised when a provider is selected but its API key env var is unset.
Raised when a provider is selected but its LangChain package is not installed.
Credential readiness state for a model provider.
Origin of a CONFIGURED credential, used to discriminate display.
Credential readiness information for a provider.
A model specification in provider:model format.
Profile data for a model with override tracking.
Configuration for a model provider.
Parsed model configuration from config.toml.
A project-scoped, definition-bound MCP server approval.
User-level allow/deny lists for project MCP servers.
Coalesced thread-selector configuration read from a single TOML parse.
Stable identifiers for notification actions dispatched by the app.
One button/action row in the notification modal.
Typed payload for a missing-dependency notification.
Typed payload for an update-available notification.
A single notice waiting for user action.
In-memory store of pending notifications.
JSON-safe workspace descriptor carried in LangGraph runtime context.
Server-authoritative workspace and resource policy for one thread.
A workspace claim or runtime conflicts with server resource policy.
Goal/rubric state channels shared by every schema that touches them.
Extends agent state with per-checkpoint facts restored on resume.
Persists per-checkpoint resume facts after each model call.
Versioned, allowlisted policy snapshot persisted beside a binding.
One drifted policy field, reported within the snapshot allowlist.
Structured, secret-free detail attached to a workspace refusal.
Middleware that provides an ask_user tool for interactive questioning.
A different dcode entry point is winning on PATH than the one we upgraded.
A single package version change parsed from uv's environment-diff output.
Raised when uv tool requested requirements cannot be preserved.
Raised when an extra cannot be removed from this install.
Raised when an uninstall targets a required base-dependency extra.
Raised when a selected composite still supplies the requested extra.
Result of an attempted optional-extra install.
Result of an attempted optional-extra removal.
Validate shell commands against an allow-list without HITL interrupts.
Stock HITL routing with an async live-mode read after model completion.
Rubric state carrying dcode's private runtime model selections.
Nested-grader state used to scope verification-tool budgets.
Run a context-aware nested grader with CLI verification middleware.
A single choice option for a multiple choice or multi-select question.
A question to ask the user.
Request payload sent via interrupt when asking the user questions.
Trusted same-turn authorization recorded after an ask_user response.
Widget result when the user submits answers.
Widget result when the user cancels the prompt.
Path-safety and size limits for read-only repository inspection tools.
A single labeled diagnostic fact.
A named group of related diagnostic items.
tool.use hook payload (schema documented in hooks).
tool.error hook payload (schema documented in hooks).
tool.result hook payload (schema documented in hooks).
In-progress state for a single streamed tool call.
Counts of buffered tool calls that never emitted a tool.use.
Token stats for a single model within a session.
Token and cost stats for one UsageKind bucket.
Usage returned after recording one streamed model message.
Stable identity of one model invocation in the usage ledger.
Message identity, optionally scoped to one model attempt.
Stats accumulated over a single agent turn (or full session).
What a stream consumer last recorded for one request.
Declared context_schema for the agent graph.
Client-facing builder for the per-run graph context payload.
State for local context middleware.
Inject local context (git state, project structure, etc.) into the system prompt.
Suppress native stderr writes while the TUI owns the terminal.
Character set mode for TUI display.
Character glyphs for TUI display.
Mutable metadata for the model active in this process.
One complete generation of credentials and project context.
Stable owner of the active credential and project-context snapshot.
Why /trace found no LangSmith key, when an empty override is involved.
Offline snapshot of LangSmith tracing configuration for diagnostics.
Base class for typed LangSmith project URL lookup failures.
The langsmith package is not installed.
The LangSmith project URL lookup exceeded its hard timeout.
The LangSmith SDK call raised — auth, 404, network, etc.
The LangSmith project does not exist yet (lookup returned 404).
Result of creating a chat model, bundling the model with its metadata.
Deterministic chat model for integration tests.
Deterministic tool-calling model for auto-approve integration tests.
Exercise nested criteria generation with a repository read.
Structured version facts for a single installed distribution.
Network-free snapshot of the version facts diagnostics need.
Raised when installed extras cannot be determined safely.
Install status for one optional dependency extra.
Resolved recovery action for a missing provider package.
A single tool's display metadata.
A named group of tools sharing a source.
An MCP server that was discovered but currently exposes no tools.
Everything dcode tools list needs to render, in display order.
Revert agent edits to the managed onboarding-name memory block.
Classifier denial categories exposed to the agent and TUI.
One validated verdict bound by the server to its proposed tool call.
Server-assembled verdicts for one unresolved action batch.
One checkpointed classifier request and its validated response.
Bounded provider-neutral classifier history.
Server-owned denial and availability counters for one thread.
Checkpoint-safe disposition for one gated call.
Private checkpoint record joining model output to after-model routing.
Server-owned provenance for one exclusively allocated scratch file.
Reducer update that creates or removes one exact artifact record.
Agent state carrying private Auto decisions and scratch provenance.
Trusted metadata attached by the Textual client to a user message.
Server-resolved approval mode and trace-safe diagnostics.
Apply deterministic policy, classifier review, and HITL fallback.
Reject dynamically gated MCP calls when no approval UI exists.
Structured proposal returned by the criteria agent.
A new proposal or a rejection-based regeneration.
An amendment to an accepted goal; both extra fields are required.
Main-agent state carrying a criteria request until it is cleared.
Private per-invocation state for the nested criteria agent.
Nested-grader state used to scope verification-tool budgets.
Run goal-criteria requests entirely inside the main server graph.
Recover failed connections and preserve actionable login errors.
Complete set of semantic colors for one theme variant.
Metadata for a registered theme.
Structured log record retained by the in-memory debug buffer.
Logging handler retaining the most recent structured records in memory.
Discriminator for ConfigResolutionError reasons.
Structured error returned when a login target cannot be resolved.
Successful resolution of a merged MCP config for login.
Resolved server config plus enough context for error messages.
Unified parse result for dropped-path payload detection.
Track pasted images and videos in the current conversation.
Thread metadata returned by list_threads.
Classification that controls whether a command can skip the message queue.
A single slash-command definition.
A single autocomplete entry for the slash-command controller.
A persisted API key credential.
A persisted OAuth subscription credential.
Result of a credential write that may have warnings to surface.
Result of a credential delete that may have warnings to surface.
Canonical goal/rubric fields used for notices and fingerprints.
The three user-controlled text sections a goal-state notice can embed.
Metadata extracted from a canonical goal-state notice.
OSC 9;4 progress states.
A dangerous Unicode character found in text.
Safety analysis output for a URL string.
Raised when the launch-time profile location cannot be resolved.
One component in the context audit.
Structured context audit ready for presentation.
Paths whose contents belong to one user profile and trust root.
Paths owned by the installed tool rather than a selected profile.
Project-controlled paths derived from an explicit repository root.
Frozen launch-time profile and installation paths.
Whether a probed path exists, is absent, or could not be read.
Tool-approval policy selected for an interactive thread.
Stored approval-mode control payload.
Stored content for a collapsed paste.
Merged view of built-in, entry-point, and config sandbox providers.
Snapshot of the ChatGPT OAuth login state.
Raised when the user cancels a sign-in flow mid-callback wait.
Raised when a stored ChatGPT token cannot be refreshed.
UI hooks for the browser loopback sign-in flow.
How to install the package that provides a sandbox backend.
Static description of a sandbox provider used by the registry.
Base error for sandbox provider operations.
Raised when the requested sandbox cannot be found.
Interface for creating and deleting sandbox backends.
Configuration for a single config-declared sandbox provider.
Parsed [sandboxes] configuration from config.toml.
Expose tools registered after the agent graph was built.
Registrations and isolated errors from one load pass.
Authorized sources and non-fatal resolution errors.
Default decision for project-authored extension code.
Effective extension configuration for one process.
Runtime mode exposed to extensions.
Factory-scoped registrar and read-only session context.
GitHub-hosted MCP: RFC 8628 Device Authorization Grant.
Outcome of a provider's pre-handshake run_login step.
Base class for provider-specific OAuth dispatch.
Fallback provider for spec-compliant MCP servers with no quirks.
Slack-hosted MCP: loopback Authorization Code with a public client.
Raised when a marketplace cannot be loaded.
Local directory or JSON file used as a marketplace source.
GitHub or Git repository used as a marketplace source.
Marketplace manifest downloaded from an HTTP URL.
Parsed plugin manifest.
Inventory of supported plugin components.
A discovered plugin ready to feed dcode adapters.
A plugin stored relative to its marketplace.
A plugin sourced from a GitHub repository.
A plugin sourced from a subdirectory in a Git repository.
A plugin sourced from a Git repository URL.
A catalog entry from a marketplace manifest.
A parsed marketplace manifest.
Persisted marketplace source record.
Install record for a plugin.
Result from plugin discovery.
Raised when a plugin manifest is malformed enough to skip the plugin.
Raised when existing plugin state cannot be safely modified.
Load namespaced plugin skills without extending the SDK source API.
Raised when the HITL interrupt loop exceeds _MAX_HITL_ITERATIONS rounds.
A tool call whose tool.use has fired but whose result has not arrived.
Mutable state accumulated while iterating over the agent stream.
Best-effort background LangSmith thread URL lookup state.
Manages a langgraph dev server subprocess.
An option paired with its resolved effective value, for display.
Adapt hook invocations and handler output across the wire boundary.
Persisted trust record for one canonical workspace root.
Versioned on-disk trust store for project-scoped hooks.
Decides whether project-scoped hooks may run in a given directory.
Live client identity projected into every hook invocation.
Result of a lifecycle hook that may halt the caller.
Result of UserPromptSubmit, including its prompt rewrites.
Owns the Hooks v2 runtime, presenter, hook service, and transcripts.
One JSONL record in a materialized transcript projection.
Identity of a materialized transcript file.
Append-only JSONL transcript projections owned by the client process.
Collect completed stream messages into a Hooks transcript runtime.
Client-only materialization needed to build one hook wire envelope.
Client-owned session runtime around an immutable Hooks snapshot.
One ordered command handler in a configuration snapshot.
Matched handlers for one invocation.
Immutable, declaration-ordered Hooks v2 runtime configuration.
Origin of the matcher groups contributed by one hooks document.
A project or user hooks file, which defines no variables.
Origin and environment for groups one enabled plugin contributed.
Validated configuration plus load diagnostics and source paths.
Deduplicate hook fulfillment for one client session.
Execute Hooks v2 invocations against one immutable snapshot.
Client approval decision compatible with HITL resume payloads.
Normalized result shared by TUI and headless permission handling.
How one batch of gated tool calls was resolved by hooks.
Validated output and diagnostics from one command handler.
Raised when a client-owned hook stops lifecycle processing.
Client state required to create a domain hook invocation.
Execute client-owned events and apply their common side effects.
Request sent for a server-owned hook invocation.
Response returned for a server-owned hook invocation.
Configuration for a synchronous command hook.
A matcher and its ordered hook handlers.
Top-level configuration grouped by hook event.
A tool.result payload held back until the authoritative result arrives.
A validated rubric_evaluation_end event forwarded to the caller.
Adapter for rendering agent output to Textual widgets.
One prompt summary row.
Message sent when a prompt row is clicked.
Filter, preview, copy, or select a previously submitted prompt.
Keep the session cost warning visible until acknowledged.
Ask whether to start a new session or exit after a blocked resume.
How to resolve a cold prompt-cache warning.
Ask whether to send a turn whose prompt cache may be cold.
Ask whether to compact a just-resumed thread before the next turn.
Confirm a model switch that preserves a large conversation context.
Modal showing the copyable entire-thread token and cost breakdown.
Arrow-key navigable plugin manager for /plugins.
Posted when a plugin manager tab label is clicked.
Mouse-clickable tab label in the plugin manager header.
In-TUI first-run notice describing what Auto mode does.
The closed set of LangSmith region selections in the /auth prompt.
Outcome of resolving the region selector to an endpoint to persist.
Outcome of an AuthPromptScreen interaction.
Confirm before launching an authentication flow for a model.
Confirmation overlay shown before clearing a stored credential.
Modal that captures and persists an API key for one provider.
Modal that lists configured providers and lets the user manage keys.
Posted when a key prompt successfully persists credentials.
Posted when a key prompt deletes stored credentials.
Confirmation overlay for installing an arbitrary --package.
Confirmation overlay for installing a model provider's extra.
Modal asking whether to restart the server for a spawn-time change.
A single row in the console's session snapshot.
Modal showing a session snapshot and a live tail of recent log records.
Dismissal payload identifying which action the user picked.
Posted when a notification row is clicked with the mouse.
Posted when the user picks SUPPRESS from a notification's detail modal.
Posted when the user toggles the settings disclosure row.
Posted for an action that opens a follow-up modal in place.
Shared hub for pending notifications and warning preferences.
Base class for tool approval widgets.
Generic approval widget for unknown tools.
Approval widget for write_file - shows file content with syntax highlighting.
Approval widget for edit_file - shows clean diff with colors.
One startup tip displayed above the chat input.
Raised by MCPLoginScreen.action_cancel when the user cancels the flow.
Modal that renders the OAuth login flow and collects user input.
Docked two-pane panel visualizing js_eval subagent fan-out by phase.
Outcome of the YOLO first-enable notice.
In-TUI acknowledgement shown before unrestricted YOLO becomes active.
Prompt filter with standard modified-Backspace word deletion.
Query field for the inline prompt search panel.
Posted on Escape or empty-query Backspace, to close the search.
One clickable prompt row in the inline search panel.
Message sent when a prompt row is clicked.
Inline prompt history search rendered above the input row.
Message sent when the panel's rendered row count changes.
Message sent when a prompt row is clicked in the panel.
Modal asking whether to switch cwd when resuming or switching to a thread.
Ask how project hooks in a newly entered workspace should be trusted.
TextArea that detects paste-like keystroke bursts.
Paste-aware text area that collapses large pastes into placeholders.
Keep the current goal and lifecycle state visible above the input.
Which stored preference Ctrl+S toggles, and how the footer names it.
A clickable model option in the selector.
Message sent when a model option is clicked.
Selector title whose current-model span copies on click.
Full-screen modal for model selection.
Compact welcome banner shown at startup.
Manages command history with file persistence.
Free-form answer input for ask-user questions.
Posted when the user presses Enter to submit an ask-user answer.
Interactive widget for asking the user questions.
Message sent when user submits all answers.
Message sent when user cancels the ask_user prompt.
Ask before changing agents to resume a thread.
Run the ChatGPT OAuth Authorization Code Flow with PKCE inline.
Outcome of the CodexSignedInScreen quick-action overlay.
Quick-action overlay shown when openai_codex is already signed in.
Strategy for building a tool's HITL approval widget.
Renderer for write_file tool - shows full file content.
Renderer for task tool — interrupt description provides full context.
Renderer for delete tool - shows removed file content when available.
Renderer for edit_file tool - shows unified diff.
Widget result when the generated criteria are accepted unchanged.
Widget result when the user submits revised criteria.
Widget result when the user rejects criteria with feedback.
Widget result when the user cancels the proposal.
Text input that keeps goal-review edit keystrokes inside the editor.
Posted when the user presses Enter to submit goal-review text.
Posted when Escape should leave goal criteria edit mode.
Inline review widget for generated goal acceptance criteria.
Message sent when the user accepts, edits, or cancels.
Captured stdout printed during a js_eval evaluation.
Parse an ordered model allowlist of exact specs and provider wildcards.
Return " (released Nd ago)" for version, or "" when unknown.
Return a human-readable age for SDK version (e.g., 'released 3d ago').
Map a raw ToolMessage.status to the two-value hook domain, fail-closed.
Record a validated provisional usage event from a nested model call.
Resolve the model spec the Auto approval classifier should use.
Fetch the LangSmith project URL, raising on any failure.
Validate that the model has required capabilities for deepagents.
Collect version facts for the installed deepagents SDK distribution.
Build a safe agent/UI reason for a failed auto classifier call.
Reset the terminal's dynamic default background color with OSC 111.
Neutralize control characters and deceptive Unicode in untrusted text.
Return the project-level tool-agnostic .agents/skills directory.
Read a live approval mode from the server-side LangGraph Store.
Validate late routes and flag graph-bound registrations for restart.
Resolve or materialize a marketplace plugin entry to a plugin root.
Merge managed policy over user config with this project's precedence.