This release is a pre-release and may not be stable for production use.
Python authoring package and CLI launcher for Managed Deep Agents.
[!IMPORTANT] Public beta. Managed Deep Agents is in public beta. The PyPI package API and managed runtime contract may change. See the docs for getting started and updates.
managed-deepagents is the PyPI package for authoring Managed Deep Agents in
Python. It includes:
define_deep_agent, the Python authoring contract for managed agents.define_schedule, the Python contract for managed cron schedules.mda, the CLI used to build and deploy your agent to LangSmith.managed_deepagents.runtime, the runtime helper used by generated managed entry modules.
Install
uv tool install managed-deepagents
[!NOTE] Private beta: dev releases only. We currently publish only PEP 440 pre-release (dev) versions and no stable version yet. uv skips pre-releases by default unless they are allowed explicitly:
uv tool install --prerelease allow managed-deepagents
This package requires Python 3.9 or newer. Each platform wheel bundles the
prebuilt mda binary for its OS and CPU architecture and exposes it through the
mda console script. This PyPI-installed CLI scaffolds and compiles Python
projects only and vendors the Python runtime bundled with this wheel.
To start a new project, run mda init. In a terminal, the CLI asks you to name
the agent:
mda init
Run mda init -i to initialize your agent interactively and optionally hand it
off to a coding agent to build:
mda init -i
Choose a coding agent to continue in the new project, or select View raw prompt to copy the setup instructions.
For coding agents and other headless use, pass the project name:
mda init my-agent
mda init can shape the project up front — --instructions "..." (or
--instructions-file <path>) writes the system prompt, --model <spec> picks
the model, --memory agent opts into deployment-shared durable memory,
--no-sandbox leaves out the sandbox, and -c slack (also --channel /
--channels) writes channels/slack.py. Every new project includes an
identity.py that explicitly selects auth.langsmith_api_key() authentication.
mda init my-agent --gateway runs the agent on
LangSmith Gateway — a model
LangSmith hosts, billed to your workspace's Gateway Credits, authenticated with
a LangSmith API key instead of a model provider key of your own. It is mutually
exclusive with --model, which names a provider you hold the key for.
Evaluate
Managed Deep Agent evals run in Harbor. Install uv and Docker before running
them.
-
From the project root, initialize the eval workspace:
mda evals init -i
-
Follow the coding-agent prompt to author tasks directly under
evals/<task>/. The CLI creates the user-ownedevals/harbor-job.jsononce and preserves later edits..mda/evals/is generated. A task may include an authoredevals/<task>/identity.jsonfixture. It requires a non-emptyuser.id;user.kind,user.email, and top-levelgroups,claims, andsource.providerare optional. Keep it with the task, not in generated.mda/evals/. -
Export
LANGSMITH_API_KEY,LANGSMITH_WORKSPACE_IDwhen your credentials require it, and the model or tool credential variables used by the agent. -
From the same project root, run the pinned Harbor 0.21.0 command included at the end of the coding-agent prompt. The command loads
MDAJobPluginandLangSmithPlugin. It uses POSIX syntax on macOS/Linux and PowerShell on native Windows. -
From the same project root, inspect results:
uv run --python 3.12 --with 'harbor[langsmith]==0.21.0' harbor view .mda/evals/jobs
MDAJobPlugin compiles a fresh eval artifact at every Harbor job start.
This POC keeps MDA's custom Harbor adapter; migration to Harbor's built-in
LangGraph agent is deferred.
Define an Agent
Create an agent.py that defines an agent:
from managed_deepagents import define_deep_agent
# The system prompt comes from instructions.md next to this file.
agent = define_deep_agent(
name="research-assistant",
model="openai:gpt-5.5",
tools=[query_db],
)
define_deep_agent requires a static name (LangGraph assistant id and default LangSmith deployment name) and otherwise accepts the create_deep_agent keyword surface minus the managed keys: backend, store, checkpointer, memory, skills, and system_prompt. Those are provided by the managed runtime when your agent is deployed. Write the system prompt in instructions.md next to agent.py; the CLI embeds it at deploy time.
To authenticate SDK and API requests with a LangSmith workspace key while retaining MDA's thread and store authorization, declare it explicitly:
identity = define_identity(auth=auth.langsmith_api_key())
Clients send the key as x-api-key. LangSmith Cloud supplies the verification
endpoint and tenant configuration; do not add those platform-owned values to
the project .env.
On deploy, Context Hub stores harness files (instructions.md, skills/**). A
root memory.py declaring define_memory(scope="agent") additionally mounts one
deployment-shared memory tree at /memories/agent/.
/memories/agent/AGENTS.md is injected every turn; other files are read on
demand. Deploy never overwrites existing memories. Memory is independent of
identity, and a project without memory.py mounts no durable memory.
Project Shape
my-agent/
agent.py # named `agent` variable
identity.py # managed authentication (included by `mda init`)
instructions.md # managed system prompt
pyproject.toml
.env # local deploy secrets, never committed
schedules/ # optional managed cron schedules
tools/ # optional custom tools
middleware/ # optional middleware
skills/ # optional skills synced to Context Hub
sandbox/ # LangSmith sandbox (`mda init` includes this; delete to opt out)
connectors/mcp.py # optional MCP server declaration
The CLI copies your project files into the managed build and generates the entry module that connects your definition to the hosted runtime.
The agent entry must live at the project root as agent.py.
Define a Schedule
Create one file per schedule under schedules/ and define a named schedule:
# schedules/daily_digest.py
from managed_deepagents import define_schedule
schedule = define_schedule(
cron="0 8 * * 1-5",
timezone="America/Los_Angeles",
prompt="Write the daily digest.",
)
mda deploy reconciles schedules as LangSmith cron jobs after the deployment is
live. Declarations must be statically serializable literals or top-level
constants; prompt schedules become user-message input, and stateless runs clean
up their temporary thread after completion.
Sandbox
mda init scaffolds sandbox/__init__.py with a LangSmith sandbox. MDA only
enables the sandbox when that declaration is present — delete sandbox/ to opt
out:
from managed_deepagents import define_sandbox
sandbox = define_sandbox(
idle_ttl_seconds=600,
)
If sandbox/setup.sh exists, mda deploy / mda dev bake it into a recipe
snapshot once; thread sandboxes clone that snapshot and do not re-run setup.
MDA owns sandbox naming, image/snapshot selection, reuse, and lifecycle.
Private published images can declare registry credentials by environment variable name; MDA creates or updates the deployment-owned Host registry:
sandbox = define_sandbox(
docker_image="ghcr.io/acme/agent-base:1",
registry={
"url": "ghcr.io",
"username": "octocat",
"password_env": "GHCR_TOKEN",
},
)
Put GHCR_TOKEN in the project .env or process environment. Its value is
used only to reconcile the registry and never enters the build or snapshot.
MCP Connectors
Add connectors/mcp.py to attach MCP servers. The file must define a
module-level connector. By default, MDA exposes every tool loaded from each
declared server. Supply your own auth via static headers when the server
requires credentials:
from managed_deepagents import connectors
connector = connectors.mcp(
mcp_servers={
"langchainDocs": {
"transport": "http",
"url": "https://docs.langchain.com/mcp",
"include_tools": ["search", "fetch"],
},
},
)
Use include_tools or exclude_tools inside a server config to select a
subset. Tool names are raw MCP tool names before the managed {server}__ prefix
is applied, so "include_tools": ["search"] on server langchainDocs exposes
langchainDocs__search when prefixing is enabled.
CLI
Create a new project:
mda init my-agent
Build locally:
mda build ./my-agent
Run on the local LangGraph dev server:
mda dev ./my-agent
mda dev requires uv on PATH, but it resolves the local LangGraph dev
server automatically; you do not need to install a global langgraph command.
Deploy to LangSmith:
mda deploy ./my-agent
The generated build is written to <root>/.mda/build by default.
Common deploy options:
mda deploy ./my-agent --name my-agent-dev --deployment-type dev
mda deploy ./my-agent --workspace-id "$LANGSMITH_WORKSPACE_ID"
mda deploy ./my-agent --no-wait
Read the deployed agent's server logs:
mda logs ./my-agent
mda logs ./my-agent --lines 200 --level error
mda logs ./my-agent > agent.log
In a terminal mda logs streams new output until you press Ctrl-C. When the
output is piped or redirected it prints the most recent lines (1000 by default)
and exits.
Tear it down again:
mda delete ./my-agent
mda delete (alias mda destroy) removes the LangSmith deployment, the tracing
project created alongside it, the deployment's Context Hub repo (plus any legacy
per-user or org child memory repos left from older runtimes), and the managed
sandboxes the deployment created. It asks for confirmation first; pass --yes
to skip the prompt in scripts. Agent memory and thread history are not
recoverable afterwards.
Sandboxes are matched by name: the runtime names each one
{deployment}--{digest} of the thread id, which also lets a restarted
deployment re-adopt its existing sandbox instead of stranding it. Recipe changes
(setup.sh or bake base) produce a new deploy-time snapshot; live threads keep
their boxes until reclaim. Sandboxes created before this behavior existed are
unnamed and are left to
LangSmith's idle-stop and retention window.
Before deploying, make sure your model provider key such as OPENAI_API_KEY
or ANTHROPIC_API_KEY is available in the project .env or LangSmith
workspace secrets; a value exported in your shell is not deployed. For
LangSmith itself, set LANGSMITH_API_KEY in .env or your shell, or run
interactively and press Enter at the prompt to sign in with your browser (the
CLI creates a key and writes it to .env). Use LANGSMITH_WORKSPACE_ID or
--workspace-id when your credentials require a workspace selection.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distributions
Built Distributions
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file managed_deepagents-0.5.4.dev37-py3-none-win_arm64.whl.
File metadata
- Download URL: managed_deepagents-0.5.4.dev37-py3-none-win_arm64.whl
- Upload date:
- Size: 1.9 MB
- Tags: Python 3, Windows ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
28149643871c038cd4abb4453a7999f8ea65a136461d0a80c8bec1ae5f578047
|
|
| MD5 |
8e69281af7b2e6936fde1de5ff46899d
|
|
| BLAKE2b-256 |
19d58b7bbdb9d90983bd7c6ef181a496d35cd3a692d8cb8ff8a415155fb0de76
|
Provenance
The following attestation bundles were made for managed_deepagents-0.5.4.dev37-py3-none-win_arm64.whl:
Publisher:
release.yml on langchain-ai/managed-deepagents-sdk
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
managed_deepagents-0.5.4.dev37-py3-none-win_arm64.whl -
Subject digest:
28149643871c038cd4abb4453a7999f8ea65a136461d0a80c8bec1ae5f578047 - Sigstore transparency entry: 2556126545
- Sigstore integration time:
-
Permalink:
langchain-ai/managed-deepagents-sdk@cb1f626c7092fafff188e1d201c676f135d33ec5 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/langchain-ai
-
Access:
internal
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@cb1f626c7092fafff188e1d201c676f135d33ec5 -
Trigger Event:
push
-
Statement type:
File details
Details for the file managed_deepagents-0.5.4.dev37-py3-none-win_amd64.whl.
File metadata
- Download URL: managed_deepagents-0.5.4.dev37-py3-none-win_amd64.whl
- Upload date:
- Size: 2.0 MB
- Tags: Python 3, Windows x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
d7640c39f15c9de7527b1a3d61bcfed9ea618a3cde87409a974e1cb9b2d7d4e7
|
|
| MD5 |
2b7870dbbef77a3b10d207a39af558b4
|
|
| BLAKE2b-256 |
417f43927ef22e8538be8cea5f0d70859b92dccf8f2f63c0af9e273e67cea8c9
|
Provenance
The following attestation bundles were made for managed_deepagents-0.5.4.dev37-py3-none-win_amd64.whl:
Publisher:
release.yml on langchain-ai/managed-deepagents-sdk
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
managed_deepagents-0.5.4.dev37-py3-none-win_amd64.whl -
Subject digest:
d7640c39f15c9de7527b1a3d61bcfed9ea618a3cde87409a974e1cb9b2d7d4e7 - Sigstore transparency entry: 2556126149
- Sigstore integration time:
-
Permalink:
langchain-ai/managed-deepagents-sdk@cb1f626c7092fafff188e1d201c676f135d33ec5 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/langchain-ai
-
Access:
internal
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@cb1f626c7092fafff188e1d201c676f135d33ec5 -
Trigger Event:
push
-
Statement type:
File details
Details for the file managed_deepagents-0.5.4.dev37-py3-none-manylinux2014_x86_64.whl.
File metadata
- Download URL: managed_deepagents-0.5.4.dev37-py3-none-manylinux2014_x86_64.whl
- Upload date:
- Size: 2.3 MB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ce644325a155e0f8bbcea8c500fedebfa20764e4feeac82c2e631700e145178b
|
|
| MD5 |
c2aa6467026a026c949c1c33050930e7
|
|
| BLAKE2b-256 |
5b0ff5c8bcd1323701d427c6e834925e6db561e080029e0157c6d4227fdd2b54
|
Provenance
The following attestation bundles were made for managed_deepagents-0.5.4.dev37-py3-none-manylinux2014_x86_64.whl:
Publisher:
release.yml on langchain-ai/managed-deepagents-sdk
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
managed_deepagents-0.5.4.dev37-py3-none-manylinux2014_x86_64.whl -
Subject digest:
ce644325a155e0f8bbcea8c500fedebfa20764e4feeac82c2e631700e145178b - Sigstore transparency entry: 2556126005
- Sigstore integration time:
-
Permalink:
langchain-ai/managed-deepagents-sdk@cb1f626c7092fafff188e1d201c676f135d33ec5 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/langchain-ai
-
Access:
internal
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@cb1f626c7092fafff188e1d201c676f135d33ec5 -
Trigger Event:
push
-
Statement type:
File details
Details for the file managed_deepagents-0.5.4.dev37-py3-none-manylinux2014_aarch64.whl.
File metadata
- Download URL: managed_deepagents-0.5.4.dev37-py3-none-manylinux2014_aarch64.whl
- Upload date:
- Size: 2.2 MB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
d450069347da8d487836ccca9383393d5e35889955f36ba19d51c78effebb926
|
|
| MD5 |
b972f41990812760b6355fac40c9a835
|
|
| BLAKE2b-256 |
c617d6643de0c209d883c43ab478b8774e750e63e60507da0d9ee779e7506cec
|
Provenance
The following attestation bundles were made for managed_deepagents-0.5.4.dev37-py3-none-manylinux2014_aarch64.whl:
Publisher:
release.yml on langchain-ai/managed-deepagents-sdk
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
managed_deepagents-0.5.4.dev37-py3-none-manylinux2014_aarch64.whl -
Subject digest:
d450069347da8d487836ccca9383393d5e35889955f36ba19d51c78effebb926 - Sigstore transparency entry: 2556126780
- Sigstore integration time:
-
Permalink:
langchain-ai/managed-deepagents-sdk@cb1f626c7092fafff188e1d201c676f135d33ec5 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/langchain-ai
-
Access:
internal
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@cb1f626c7092fafff188e1d201c676f135d33ec5 -
Trigger Event:
push
-
Statement type:
File details
Details for the file managed_deepagents-0.5.4.dev37-py3-none-macosx_11_0_arm64.whl.
File metadata
- Download URL: managed_deepagents-0.5.4.dev37-py3-none-macosx_11_0_arm64.whl
- Upload date:
- Size: 2.0 MB
- Tags: Python 3, macOS 11.0+ ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b7c83ca866c031357a750c2d155c735d638df87ad107cd788af6d166c2d3396c
|
|
| MD5 |
1d6a27db26a45a6efc49daa83ca07026
|
|
| BLAKE2b-256 |
21403774725c570d9542e41f9626e936abd193c44b2433ffd9d0f0bb8c08d6ca
|
Provenance
The following attestation bundles were made for managed_deepagents-0.5.4.dev37-py3-none-macosx_11_0_arm64.whl:
Publisher:
release.yml on langchain-ai/managed-deepagents-sdk
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
managed_deepagents-0.5.4.dev37-py3-none-macosx_11_0_arm64.whl -
Subject digest:
b7c83ca866c031357a750c2d155c735d638df87ad107cd788af6d166c2d3396c - Sigstore transparency entry: 2556126924
- Sigstore integration time:
-
Permalink:
langchain-ai/managed-deepagents-sdk@cb1f626c7092fafff188e1d201c676f135d33ec5 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/langchain-ai
-
Access:
internal
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@cb1f626c7092fafff188e1d201c676f135d33ec5 -
Trigger Event:
push
-
Statement type:
File details
Details for the file managed_deepagents-0.5.4.dev37-py3-none-macosx_10_12_x86_64.whl.
File metadata
- Download URL: managed_deepagents-0.5.4.dev37-py3-none-macosx_10_12_x86_64.whl
- Upload date:
- Size: 2.1 MB
- Tags: Python 3, macOS 10.12+ x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
aeb78124d33203c9cbaae085d9414ed1a59073190056c620f2568f30daf2b171
|
|
| MD5 |
71b2e20fea17772e8406f92daf8160c8
|
|
| BLAKE2b-256 |
4ce757df158a04191407c3ab76cdaaeb78091bdcd57939600eedcc854045e1df
|
Provenance
The following attestation bundles were made for managed_deepagents-0.5.4.dev37-py3-none-macosx_10_12_x86_64.whl:
Publisher:
release.yml on langchain-ai/managed-deepagents-sdk
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
managed_deepagents-0.5.4.dev37-py3-none-macosx_10_12_x86_64.whl -
Subject digest:
aeb78124d33203c9cbaae085d9414ed1a59073190056c620f2568f30daf2b171 - Sigstore transparency entry: 2556126357
- Sigstore integration time:
-
Permalink:
langchain-ai/managed-deepagents-sdk@cb1f626c7092fafff188e1d201c676f135d33ec5 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/langchain-ai
-
Access:
internal
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@cb1f626c7092fafff188e1d201c676f135d33ec5 -
Trigger Event:
push
-
Statement type: