Independent, source-backed, agent-first
Operate the harness, not just the model.
Source-backed guides and local tools for installing, operating, and debugging the official DeepSeek AI agent runtime.
Latest field signals · 30 August 2026
Three failures, three different owners.
Each route starts from a current official report, pins the implementation evidence, and ends with a reversible recovery test.
spawn sandbox-exec ENOENT separately from a denied file effect and keep unavailable backends fail closed
Subagent · version · route fidelityThe same 400 has two version branchesrc.2 drops effort; alpha.1 carries it, so prove the active package graph before calling the symptom a regression
Identity · provenance · installation safetySearch ranking is not project provenanceVerify the official repository, npm integrity, release commit, installer permissions, and binary signature before executing or entering credentials
Filesystem · URL · capability boundaryA URL is not a local pathReject HTTP(S) before path resolution and route remote retrieval to a web/fetch capability
Firefox · Web client · bootstrapBlank is a browser boundary until proven otherwiseCompare the same server, preserve the first Console/Network failure, and isolate clean-profile behavior before touching Sessions
Auth · token · extension bridgeAcquisition and entry are different contractsSeparate callback, UI, storage, scope, and outbound-header evidence without exposing credentials
Five-minute first run
Start with evidence.
Launch the official Web profile from a disposable workspace, choose a model, and begin with a bounded read-only task.
First confirm that you have the official DeepSeek AI Agent runtime, not a same-name API wrapper.
npx @deepseek-ai/dsh web
- Choose the workspace.Select the exact disposable repository the agent may inspect.
- Configure the model.Use a limited credential with an environment spending cap.
- Ask for evidence.Require real file paths and stop before writes or external effects.
- Inspect the graph.Run
dsh --profile web --dump-configbefore changing policy.
A runtime is a composition.
A profile resolves bundles and patches into one Cordis graph. The model is one adapter inside that graph, not the product boundary.
- Model
- Provider, endpoint, credential reference, and reasoning route.
- Effects
- Tools, approval policy, sandbox, and independent verification.
- Session
- Durable events that reconstruct model-visible history.
- Surface
- Web, headless, SDK, or a custom client over the same runtime.
Pick the path that matches the job.
Explore 173 canonical guides. Each one states the expected evidence, failure branch, and safety boundary.
154 indexed paths
Open the complete canonical indexA prompt is an instruction. The boundary lives in policy, isolation, and evidence.
Pin the runtime. Review the resolved graph. Separate credentials by environment. Test denial, timeout, partial completion, and cleanup.
Open the operator cheat sheetBuild on facts that can be replayed.
The handbook is independent, open source, and verified against primary DeepSeek Harness sources.
Read and star on GitHub