DeepSeek Harness can read project files, use a model and run tools from a web interface on your computer. DeepSeek calls the product a public preview; its repository calls the software a developer preview that may introduce compatibility-breaking changes. The safety notice says it has not had a security audit and is not ready for production. A first run belongs in a disposable environment with an unimportant project.
The official release list included the v0.2.1-alpha.1 prerelease dated October 3, 2026 when checked on October 5. The documented npx command below does not itself select that GitHub prerelease, so check the version you install before following a version-specific feature note. DeepSeek already offered desktop builds before the October 5 news report that brought this tool to our attention; the procedure here uses its documented local web interface.
The big change
DeepSeek now offers an open-source agent harness in public preview with a web interface launched from code and official desktop downloads for Apple silicon Macs and 64-bit Windows. Its plugin system can combine model access, tools and other agent capabilities. For someone evaluating an agent on files, the useful change is that they can bring a small local workspace and choose a model provider rather than starting with a company repository or live business data. The preview labels and safety notice still govern that experiment: the agent can run commands and access files, credentials and the network available to its process. A selected workspace and an approval prompt do not guarantee isolation.
Prepare an environment and a first task
Use a disposable virtual machine, container or dedicated computer account with the least access the task needs, as DeepSeek advises. Within it, make a new directory containing only a short, non-sensitive README.md that you can afford to lose. Keep personal files, company repositories, credentials, browser sessions and mounted drives outside the environment. Make a backup of anything the process can reach. A directory alone does not confine a process to that directory; the underlying account and environment determine what else it can access.
The documented web route requires Node.js and a model account or API credential. Open a terminal in the disposable directory and run the command from DeepSeek's README:
npx @deepseek-ai/dsh webAccording to the README, this starts the Web UI at http://127.0.0.1:3080 by default and opens it in the local browser. If it does not open, use the URL printed by the command; an SSH launch has different forwarding behavior. Avoid exposing the service through a public address during this exercise. The Web UI guide says the process uses its launch directory as the default filesystem location, but a fresh interface has no selected workspace. Choose workspace, add that disposable directory and select it; the composer stays unavailable until a workspace is selected.
Configure one model and check the charges
In Settings → Models, the official configuration guide says you can enter a DeepSeek API key and save it. It also documents built-in third-party provider entries and a custom model API for a gateway or self-hosted endpoint. For a third-party provider, use Add model provider, choose a provider from the installed list, enter its API key and save. Then choose its model in the session picker. OAuth sign-in providers such as Codex are not supported by this configuration path, according to the guide. If your provider is absent, the custom route requires a provider ID, base URL, matching API protocol, credential and at least one model ID; that is a separate integration task.
The Models page displays a redacted key descriptor after saving. DeepSeek says it keeps the key in $DSH_HOME/.credentials.yaml and a reference in settings. Protect that file and the environment in which it sits. The repository has an MIT license, while model calls may cost money. DeepSeek's terms put custom provider token or subscription charges on the user and warn that one input may trigger continuing model calls. Check the provider's current price and usage controls before sending a task. No fixed price or free allowance can be inferred from the software license.
Send a read-only request, then inspect what happened
In the selected workspace, start a session with a narrow request:
Summarize the README in this workspace. Do not run commands, edit files, install plugins or make network requests through tools. Ask before taking any other action.This suggested prompt limits the tool actions requested of the agent; the configured remote model still communicates with its provider. The prompt is not a security boundary. The official quickstart uses a repository-summary task and says the agent can read and edit files, run commands and delegate work; operations that require approval under the active policy prompt the user.
Look for a response that accurately describes your small README and check any tool calls against the task. Reject proposed commands or file changes you did not authorize. If the agent seeks a path outside the selected directory, encounters a secret, proposes a plugin or proposes an external tool request beyond the configured model call, stop the session and examine the environment before continuing. DeepSeek's safety notice says approval and sandbox controls can reduce risk but cannot guarantee isolation. Do not treat a correct summary as proof that a longer workflow will behave reliably.
The expected first output is a model summary, with no requested file change. BIG CHANGE has not installed or run this version, checked its prompts in a live environment or measured its reliability. These steps are a route through DeepSeek's documentation and a conservative task design, not a hands-on result.
Account for session data
DeepSeek's privacy policy, updated September 20, describes session logs that can include inputs, authorized files, model outputs, tool information and plugin configuration. For custom models, it says inputs go directly to the chosen model provider and are governed by that provider's policy, while DeepSeek does not store those inputs and outputs on its server. Read the current policies for the model and any plugins you enable, and keep this first test free of sensitive material.
Sources & further reading
- DeepSeek Harness product page, checked October 5, 2026. It describes public-preview access, official desktop download platforms and the
npxweb route. - Official repository and README, checked October 5, 2026. It documents developer-preview status, the local Web UI command, default address and MIT license. The release list identifies the October 3
v0.2.1-alpha.1prerelease; it does not establish the version installed by thenpxcommand. - Web UI quickstart and model configuration guide, checked October 5, 2026. These describe workspace selection, provider setup, credential storage and the supported configuration routes.
- Safety notice, checked October 5, 2026. DeepSeek describes the experimental status, available system capabilities, limits of approval and sandbox controls, and its recommendation for a disposable environment.
- Privacy policy and terms of use, both last updated September 20, 2026, checked October 5. The policy describes session logs and the custom-provider data path; the terms describe user-borne custom-model charges.



