AI-readable project metadata: llms.txt · installation guide
A local-first runtime for AI agents. Sessions, sandboxed tools, memory, credentials, audit trails, and a built-in Console — all running on your machine or in your own infrastructure.
Building with DeepSeek Harness? The independent DeepSeek Harness Handbook provides source-backed runtime guides, multilingual troubleshooting, and a regularly updated Agent-first resource map.
Looking for a lightweight bridge instead of a full runtime? SandBase CLI connects 25 AI client targets to 2,000+ models and APIs through a local stdio MCP bridge. If it fits your workflow, star SandBase CLI so other agent users can discover it.
Need hosted model and media APIs instead? SandBase provides one interface for LLM, image, and video generation APIs, with the API quickstart covering keys and first calls.
git clone --branch v0.3.8 --depth 1 https://github.com/sandbaseai/sandbase-harness.git
cd sandbase-harness
npm ci
npm run build
mkdir ../my-agents && cd ../my-agents
node ../sandbase-harness/dist/index.js init
node ../sandbase-harness/dist/index.js start
# open http://127.0.0.1:3000/dashboardChoose SandBase Harness when you need more than a model loop:
| Need | What Harness provides |
|---|---|
| Run generated code safely | Local, Docker, Kubernetes, and self-hosted worker sandboxes |
| Inspect long-running agents | Persistent sessions, resumable event streams, audit, and replay |
| Control tool access | MCP toolsets, credential vaults, permission policies, and approvals |
| Operate any model | OpenAI, Anthropic, MiniMax, and OpenAI-compatible providers, including DeepSeek V4 |
| Keep infrastructure yours | Local-first SQLite and file storage with no required hosted control plane |
If this runtime solves a real agent-infrastructure problem for you, star the repository so other builders can find it.
The project is also discoverable through these independent ecosystem directories:
- Official MCP Registry
- deepseek-plugin.org
- DeepseekPlugin
- DSH Plugin Directory
- DSH Plugin Hub
- DSH Directory
- DSH Harness
- DSH Plugin
- DSH Plugin
- dsh.so Trust & Discovery Registry
- Duink DSH Universe
- DSH Plugin Leaderboard
- Awesome repository index
- Awesome DSH Plugin
- Awesome DeepSeek Harness
- Awesome DeepSeek Harness — ecosystem list
- DSHarness 101 Plugin Radar
- DeepSeekDocs Ecosystem
- Awesome Agents
- Sifted Awesome AI Agents — Agent Runtime Top 100
- Arnon-hs Open Source — MCP projects
- SandBase Awesome Agent Runtime
- abordage/awesome-mcp
- cccakeee/awesome-dsh-plugins
- anbeime/skill — Skills index
- Awesome DeepSeek Harness Plugins
- Hermes Ecosystem — SandBase stack
- AgentStack
- HVTracker: independent automated Agent Frameworks profile and ranking snapshot; not a maintainer review or security certification.
- MCP Servers Live
- DSH X-Ray
- DSH Plugins
- Awesome DSH Hub
- Awesome DSH Plugins 2026
- MCP Repository
- MCP Server Hub: public MCP Server Hub listing for SandBase Harness.
- MCP Central API: public downstream registry mirror returning the active
io.github.sandbaseai/sandbase-harnessentry; its version snapshot may lag the current release. - MCPVault
- F8W 中文项目档案
- RepoRank Русский профиль
- Agent Plugins Hub — legacy snapshot
- MCP Market
- OpenAgentSkill — code-review
- PluginBench
- DSH Plugin Store
- DSH Hub
- DSH Packs
- dshbase
- FindHarness
- DSH Market
- DSH Plugins
- DSH Plugin Directory
- DSH Plugin Registry
- dsh-market
- dshplugin.dev
Recently verified community references:
- dshbase verified plugin page
- MCP Repository — verified project page
- DSHarness 101 — verified plugin radar entry
- DSH Plugin Leaderboard — install-verified entry
- awesome-agent-runtime — merged entry
- Awesome Agent Cortex — merged entry
- Awesome AI Devtools — merged entry
- Awesome Agent Skills — merged entry
- WalkingLabs Awesome Harness Engineering — merged entry
- Adventure Wave Awesome Agent Security — merged entry
- Awesome Native Agent Platforms — merged Harness entry
- Sifted Awesome AI Agents — verified Agent Runtime entry
- Agent Framework Radar — verified automatic entry
- LLM Agents Radar — verified automatic entry
- Awesome DSH Plugin — verified entry
- Awesome DeepSeek Harness — verified entry
- Dominic789654 Awesome DeepSeek Harness — verified public entry
- Zhiyuan-Fan Awesome DeepSeek Harness Plugins — verified runtime entry
- Herdeny Awesome DSH Plugins 2026 — verified public entry
- HackSing DSH Plugins — verified public entry
- white0dew Awesome DSH Plugins — verified generated entry
- saltbo Awesome Stars — verified public entry
- GitHub Insight Radar — verified public recommendation
- Blue-Whale-Harness — verified public directory entry
- DSH Plugin Radar — verified automatic entry
- Awesome DSH Plugin — merged Harness entry
- Awesome DeepSeek Harness — merged runtime entry
- Arnon-hs Open Source / AtlasRepo — verified MCP entry
- Sagargupta16 Awesome MCP Servers — merged entry
- Awesome Agents — public entry
- abordage/awesome-mcp — public entry
Pending community review:
- McpMux Server Registry PR #286
- Mctrinh Awesome MCP Servers PR #105
- Docker MCP Registry PR #4841 — validation complete; maintainer review pending
- ToolSDK MCP Registry PR #488 — schema and Biome checks pass; maintainer review pending
- MCP.Directory submission — already submitted; directory review pending
- Awesome Agentic Open-Source Tools PR #1 — added to Agent Frameworks & Orchestration; maintainer review pending
- awesome-ai-agents-2026 PR #2 — added to Local Runtimes & LLM Management; maintainer review pending
- AgentFirst directory PR #46 — added to Compute & Sandboxes; enrichment check passed, maintainer review pending
- AI Agent Tools submission — submitted to the MCP Servers category; directory review pending
- MCP Server Finder evaluation issue #4 — requested an independent quality and security assessment of the MCP bridge; review pending
- Agentic DevOps MCP PR #42 — added to Kubernetes & Containers; maintainer review pending
- Awesome DevOps AI PR #54 — added to MCP Servers for DevOps; maintainer review pending
- Awesome Platform Engineering PR #63 — added to Internal Developer Platforms; maintainer review pending
- Awesome DevOps Platform PR #4 — added to AI & Automation in DevOps; maintainer review pending
- Awesome Platform Engineering PR #11 — added to AI Platform Engineering & LLMOps; maintainer review pending
- Awesome LLMOps PR #539 — generated from project request #538 under Runtime / AI Agent; build passed, maintainer review pending
- Awesome Agent Infrastructure PR #21 — added to Execution Sandboxes; entry refreshed to the current MCP installation guide, maintainer review pending
- Awesome DevOps PR #30 — added SandBase Harness to the MCP tools catalog; DCO passed, maintainer review pending
- Awesome Self-Hosted Agents PR #6 — added SandBase Harness to the self-hosted agent frameworks list; PR is clean and maintainer review pending
- Awesome Agent Infra PR #2 — added SandBase Harness to the machine-readable runtime catalog; validation, tests, and lint pass, maintainer review pending
- Awesome AI Agents PR #1 — added SandBase Harness to Agent infrastructure; PR is clean and maintainer review pending
- Awesome Agent Operating Systems PR #11 — added SandBase Harness to Agent Runtimes with a dated verification link; maintainer review pending
- Awesome Agent Services PR #8 — added SandBase Harness to Sandboxes & Compute; PR is clean and maintainer review pending
- Awesome AI Automation PR #3 — added SandBase Harness to AI agents & LLM automation; PR is clean and maintainer review pending
- Awesome Best Open Source AI Agents 2026 PR #1 — added a GitHub-verified runtime entry with license, language, Stars, activity, and Best-for metadata; PR is clean and maintainer review pending
- Awesome AI Agents — Agent Playbook PR #1 — added SandBase Harness to the self-hosted frameworks list; PR is clean and maintainer review pending
- Discussion #116 — official DevOps runtime and MCP bridge discovery post
- Cline MCP Marketplace issue #2364
- MCPSo submission issue #3834
- Awesome Agent Frameworks architecture proposal #6
- Agent Sandbox Taxonomy profile proposal #5
- Awesome Agent Sandboxes PR #9
- Mossaka Awesome Agent Sandboxes PR #1
- Yenanjing Awesome Harness Engineering PR #6
- Awesome Harness Engineering 中文版 PR #6
- Awesome Agent Architecture issue #90
These listings are independent directories; the repository and its release metadata remain the source of truth.
The included development container installs dependencies and builds the runtime. When the terminal is ready, start the server on the forwarded port:
node dist/index.js start --host 0.0.0.0Open the forwarded SandBase Harness Console port, then configure a model in Settings > Models. Codespaces usage may be billed by GitHub; the local quick start below remains free and keeps all runtime data on your machine.
Agent SDKs handle the model loop. Production agents need more: persistent
sessions, tool governance, sandbox boundaries, credential handling, memory,
auditability, and a UI for humans to inspect what happened. managed-agents
is that runtime layer — not a visual workflow builder and not another model SDK.
- Claude Managed Agents-style
/v1API and local Console - SQLite-backed agents, sessions, environments, credential vaults, memory stores, files, skills, and API keys — SQLite metadata by default
- local file/skill bytes stored in the workspace state directory
- Resumable Server-Sent Events for session replay and debugging
- One active model provider boundary configured through Settings V2
- Sandbox backends: local process, Docker (per-session containers), Kubernetes (kubectl exec/cp), self-hosted worker queue
- Settings V2: one workspace model vendor, loop engine, storage, memory, sandbox — with validation, form/JSON modes, and restart flow
- MCP toolsets, permission policies, built-in tools, and skill packages
- DeepSeek Harness bridge over MCP stdio for agents, sessions, streamed turns, artifacts, and cancellation
- TypeScript SDK at
managed-agents/sdk - Release gate:
npm run release:check
| Console overview | Settings | API reference |
|---|---|---|
![]() |
![]() |
![]() |
See the Showcase for three practical paths: an auditable coding agent, DeepSeek Harness as an interactive front end, and controlled code execution across Local, Docker, Kubernetes, and self-hosted sandboxes.
For client-specific setup, see the installation guide, including the pinned Cline CLI command and the Docker MCP Bridge configuration.
Community use-case discussions:
- Memory migration between Codex, Claude Code, and DSH
- Sandbox and filesystem protection for third-party plugins
- Node.js 22+
- npm 10+
- A model provider API key (OpenAI, Anthropic, MiniMax, or an OpenAI-compatible endpoint)
- Docker (optional, for Docker-backed sandboxes)
Run this project as a DSH plugin instead of treating dsh-plugin as discovery
metadata only. Install the bundle into a DSH profile, start managed-agents,
then boot that profile:
export MANAGED_AGENTS_URL=http://127.0.0.1:3000
# Preferred: install a local source checkout after `npm run build`.
dsh plugin --profile web add -w ../sandbase-harness
# Git URL fallback. Keep HTTPS; do not convert the spec to SSH.
# dsh plugin --profile web add git+https://github.com/sandbaseai/sandbase-harness.git
dsh webIf Plugin Hub reports already installed: managed-agents after a partial or
repeated install, update the Hub first, then remove only the displayed
managed-agents plugin entry and retry from the tagged HTTPS Git source:
dsh plugin --profile web update dsh-plugin
dsh plugin --profile web remove managed-agents
dsh plugin --profile web add git+https://github.com/sandbaseai/sandbase-harness.gitThis is a Plugin Hub duplicate-install path, not an npm installation path. If the installed view shows a different target identifier, remove that exact identifier instead. Keep the profile directory and its evidence until the runtime starts successfully; see the reported recovery issue.
The profile installs the verified source checkout directly; it does not resolve
the unrelated unscoped npm package. A git-hosted install runs prepare only
when dist/ is missing. Keep the HTTPS git spec; converting it to SSH fails on
Windows hosts without GitHub SSH access.
A git-hosted install needs one extra step for pnpm's build allowlist. The
first dsh plugin --profile web add fails with
ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED and prints the exact key. Add that key
under allowBuilds: in the profile's pnpm-workspace.yaml, then re-run the
same add command; a plain package name does not match a git-hosted
resolution:
allowBuilds:
"managed-agents@https://codeload.github.com/sandbaseai/sandbase-harness/tar.gz/<commit>": trueThe second run builds dist/ through prepare, creates the
managed-agents / managed-agents-mcp bins, and joins the bundle layer. The
patch starts the bundled MCP entry over
stdio. DSH can then list agents,
create and run sessions, inspect results and artifacts, and stop work through
native mcp__sandbase__* tools. See
examples/deepseek-harness for the full
tool list and authenticated-runtime configuration.
For a walkthrough that starts with DSH and adds this runtime as a real third-party plugin, read the DeepSeek Harness developer guide.
Pair the plugin with SandBase Skills to give the same DSH project a portable, source-verifiable research workflow:
npx --yes github:sandbaseai/sandbase-skills add multi-source-search
dsh webThis installs the complete Skill into .dsh/skills/multi-source-search, DSH's
project-scoped discovery directory. It runs from GitHub source and needs no
SandBase account when DSH already provides web/search tools.
For a complete, reproducible workflow that combines the evidence ledger with sandboxed execution, credentials, audit, and replay, read Build an Auditable Research Agent.
New to DSH profiles, plugin composition, tool policy, or session semantics? The independent DeepSeek Harness Handbook provides source-backed quickstarts, architecture maps, and troubleshooting for the runtime layers used by this integration. Read its SandBase Harness bridge guide for the DSH-specific contract, then start with the local-browser Install Doctor for installation evidence, or use the Failure Router to identify the first broken runtime boundary.
git clone --branch v0.3.8 --depth 1 https://github.com/sandbaseai/sandbase-harness.git
cd sandbase-harness
npm ci
npm run build
mkdir ../my-agents && cd ../my-agents
node ../sandbase-harness/dist/index.js init
node ../sandbase-harness/dist/index.js startOpen http://127.0.0.1:3000/dashboard, go to Settings > Models, paste your
API key, and you're running.
The unscoped managed-agents name on npm is not this project. Until an
official scoped package is announced in this repository, install only from the
tagged GitHub source release shown above. Do not run npx managed-agents or
npm install managed-agents.
The six-tool MCP bridge is published as a multi-architecture OCI image. Start the Harness API, then add this stdio command to an MCP client:
Container package: GitHub Container Registry
docker pull ghcr.io/sandbaseai/sandbase-harness-mcp:0.3.8
docker run --rm -i \
-e MANAGED_AGENTS_URL=http://host.docker.internal:3000 \
ghcr.io/sandbaseai/sandbase-harness-mcp:0.3.8For an authenticated remote runtime, also pass MANAGED_AGENTS_API_KEY. The
container image contains only the MCP bridge; agent sessions and sandbox work
remain in the connected Harness runtime. Every release image is built from the
matching Git tag for linux/amd64 and linux/arm64, includes OCI source and
MCP ownership metadata, and receives a GitHub build-provenance attestation.
Copilot CLI, VS Code, and other Agent Plugins 1.0 clients can install the same OCI-backed MCP bridge directly from this repository. Start the Harness API and Docker first, then expose its URL to the plugin process:
export MANAGED_AGENTS_URL=http://host.docker.internal:3000
# Optional when the runtime requires authentication:
export MANAGED_AGENTS_API_KEY=your-runtime-key
copilot plugin install sandbaseai/sandbase-harness:agent-pluginThe plugin passes these environment variables through to the pinned
ghcr.io/sandbaseai/sandbase-harness-mcp:0.3.8 image. It does not store a key
in plugin.json, mcp.json, or the installed plugin files. On Linux, the
plugin's Docker command maps host.docker.internal through host-gateway.
For development from the latest main branch:
git clone https://github.com/sandbaseai/sandbase-harness.git
cd sandbase-harness && npm ci && npm run build
cd .. && mkdir my-agents-dev && cd my-agents-dev
node ../sandbase-harness/dist/index.js init
node ../sandbase-harness/dist/index.js startmy-agents/
├── agents/ # Seed agent definitions (YAML)
│ └── assistant.yaml
├── skills/ # Seed skill packages
│ └── example-skill/
│ └── SKILL.md
└── .managed-agents/ # Runtime state (gitignored)
├── config.yaml # Workspace configuration
├── data.db # SQLite metadata
├── logs/runtime.log
├── files/ # Uploaded file bytes
├── skills/ # Uploaded skill packages
├── snapshots/ # Session workspace snapshots
└── sandbox/ # Local session sandboxes
.managed-agents/config.yaml:
model:
provider: openai
api_key: ${OPENAI_API_KEY}
storage:
metadata: { provider: sqlite, options: {} }
artifacts: { provider: local, options: { base_path: files } }Agents pick concrete model IDs (gpt-4o, claude-sonnet-4-20250514,
openai/gpt-5.5). The workspace config only says how to reach the model
service.
For DeepSeek V4 Pro/Flash configuration, including maximum reasoning effort, see DeepSeek V4.
For first-class MiniMax configuration, regional endpoints, and the supported MiniMax-M3 and MiniMax-M2.7 model IDs, see MiniMax.
managed-agents init
managed-agents start [--host 127.0.0.1] [--port 3000]
managed-agents list
managed-agents reload
managed-agents chat <agent-id> --message "hello"
managed-agents template list | install <name> | create <name>Create an agent:
curl -X POST http://127.0.0.1:3000/v1/agents \
-H "Content-Type: application/json" \
-d '{
"name": "Incident commander",
"model": "gpt-4o",
"system": "You are an on-call incident commander.",
"tools": [{ "type": "agent_toolset_20260401" }]
}'Create an environment (local sandbox):
curl -X POST http://127.0.0.1:3000/v1/environments \
-H "Content-Type: application/json" \
-d '{
"name": "Default local",
"config": { "hosting_type": "local", "sandbox_provider": "local" }
}'Create a Docker-isolated environment:
curl -X POST http://127.0.0.1:3000/v1/environments \
-H "Content-Type: application/json" \
-d '{
"name": "Docker sandbox",
"config": {
"sandbox_provider": "docker",
"image": "node:22-slim",
"resources": { "memory": "1g", "cpu": 1 }
}
}'Start a session:
curl -X POST http://127.0.0.1:3000/v1/sessions \
-H "Content-Type: application/json" \
-d '{
"agent": "agent_...",
"environment_id": "env_...",
"title": "Triage SENTRY-123"
}'Send a message:
curl -X POST http://127.0.0.1:3000/v1/sessions/SESSION_ID/messages \
-H "Content-Type: application/json" \
-d '{ "content": "Investigate the alert." }'Resume the event stream:
curl -N http://127.0.0.1:3000/v1/sessions/SESSION_ID/events/stream \
-H "Last-Event-ID: 42"import { ManagedAgentsClient } from 'managed-agents/sdk';
const client = new ManagedAgentsClient({
baseUrl: 'http://127.0.0.1:3000',
});
const session = await client.sessions.create({
agent: 'agent_...',
environment_id: 'env_...',
});
for await (const event of client.sessions.chat(session.id, 'Hello')) {
if (event.type === 'agent.message_chunk') {
process.stdout.write(event.delta ?? '');
}
}The /v1 API follows Claude Managed Agents resource shapes, so you can also
point the Anthropic SDK at the local runtime:
import Anthropic from '@anthropic-ai/sdk';
const client = new Anthropic({
apiKey: process.env.MANAGED_AGENTS_API_KEY ?? 'local-dev-key',
baseURL: 'http://127.0.0.1:3000',
});
const session = await client.beta.sessions.create({
agent: 'agent_...',
environment_id: 'env_...',
});Open by default. Authentication activates when at least one API key exists:
# Static key via environment
export MANAGED_AGENTS_API_KEY=sk-local-example
# Or create a managed key
curl -X POST http://127.0.0.1:3000/v1/api-keys \
-H "Content-Type: application/json" \
-d '{ "name": "Local Console" }'Clients send Authorization: Bearer <key>.
Agents are YAML files in agents/:
name: Incident commander
description: Triages alerts and coordinates response.
model: gpt-4o
system: |-
You are an on-call incident commander.
mcp_servers:
- name: sentry
type: url
url: https://mcp.sentry.dev/mcp
tools:
- type: agent_toolset_20260401
default_config:
permission_policy: { type: always_ask }
configs:
- name: bash
permission_policy: { type: always_ask }
- type: mcp_toolset
mcp_server_name: sentry
skills:
- type: custom
skill_id: skill_...
metadata:
template: incident-commandernpm ci
npm run typecheck # src + tests
npm test # vitest
npm run build # runtime + console + SDK
npm run release:check # full local release gaterelease:check runs typecheck, tests, both builds, npm pack --dry-run, CLI
init smoke, and examples/basic startup smoke.
- SandBase Skills — 88 installable Agent Skills for research, social intelligence, marketing, and business workflows across Codex, Claude Code, Cursor, Gemini CLI, and other clients.
- SandBase CLI — connect Cursor, Claude Code, Codex, Windsurf, Gemini CLI, OpenCode, and other MCP clients to 2,000+ AI models and APIs with one onboarding command.
- DSH Plugin Store — discover, filter, install, and manage community DeepSeek Harness plugins from the native Settings experience.
- SandBase — hosted agent infrastructure, model access, tools, and managed sandboxes.
- Machine-readable project metadata
- Agent / MCP installation guide
- Installation
- Usage Guide
- API Reference
- Skills
- Deployment
- Architecture
- Contributing
- Citation metadata
- Promotion status
- Promotion outreach templates
- Changelog
- Build an Auditable Research Agent — a reproducible guide combining evidence ledgers, sandboxed execution, credentials, audit, and replay with SandBase Harness.
- Self-host the SandBase agent runtime by SSD Nodes — an independent VPS walkthrough covering installation, agent configuration, MCP servers, sandbox modes, and reverse-proxy deployment. The article demonstrates v0.3.2; use the current release command above for v0.3.8.


