4.2 KiB
4.2 KiB
Runtime API (HTTP/SSE)
DeepSeek CLI can expose a local runtime API for external clients:
deepseek serve --http --host 127.0.0.1 --port 7878 --workers 2
Defaults:
- bind:
127.0.0.1:7878 - workers:
2(clamped to1..8)
Security Model (Local-First)
- The server is designed for trusted local use.
- There is no built-in auth, user isolation, or TLS termination.
- Do not expose this API directly to untrusted networks.
- If remote access is required, place it behind your own authenticated reverse proxy/VPN.
Runtime Data Model
The runtime uses a durable Thread/Turn/Item lifecycle.
ThreadRecordid,created_at,updated_atmodel,workspace,modelatest_turn_id,latest_response_bookmark,archived
TurnRecordid,thread_idstatus:queued|in_progress|completed|failed|interrupted|canceled- timestamps, duration, usage, error summary
TurnItemRecordid,turn_idkind:user_message|agent_message|tool_call|file_change|command_execution|context_compaction|status|error- lifecycle
status:queued|in_progress|completed|failed|interrupted|canceled
The event log is append-only with global monotonic seq for replay/resume.
Endpoints
Health and Session
GET /healthGET /v1/sessions?limit=50&search=<substring>
Compatibility Stream (Single Turn)
POST /v1/stream
Backwards-compatible one-shot SSE wrapper. Internally creates an archived runtime thread+turn.
Request body:
{
"prompt": "Summarize recent commits",
"model": "deepseek-reasoner",
"mode": "agent",
"workspace": ".",
"allow_shell": false,
"trust_mode": false,
"auto_approve": true
}
Typical SSE events:
turn.startedmessage.deltatool.startedtool.progresstool.completedapproval.requiredsandbox.deniedstatuserrorturn.completeddone
Thread Lifecycle
POST /v1/threadsGET /v1/threads?limit=50&include_archived=falseGET /v1/threads/{id}POST /v1/threads/{id}/resumePOST /v1/threads/{id}/fork
Create thread request example:
{
"model": "deepseek-reasoner",
"workspace": ".",
"mode": "agent",
"allow_shell": false,
"trust_mode": false,
"auto_approve": true,
"archived": false
}
Turn Lifecycle
POST /v1/threads/{id}/turnsPOST /v1/threads/{id}/turns/{turn_id}/steerPOST /v1/threads/{id}/turns/{turn_id}/interruptPOST /v1/threads/{id}/compact
Notes:
- Only one active turn is allowed per thread (
409 Conflicton overlap). interruptreturns quickly and marksturn.interrupt_requested.- Terminal turn status becomes
interruptedonly after cleanup completes. - Manual compaction is exposed as a turn with
context_compactionitem lifecycle events.
Replayable Events
GET /v1/threads/{id}/events?since_seq=<u64>
Returns SSE replay backlog, then live events for that thread.
SSE payload shape:
{
"seq": 42,
"timestamp": "2026-02-11T20:18:49.123Z",
"thread_id": "thr_1234abcd",
"turn_id": "turn_5678efgh",
"item_id": "item_90ab12cd",
"event": "item.delta",
"payload": {
"delta": "partial output",
"kind": "agent_message"
}
}
Common event names:
thread.startedthread.forkedturn.startedturn.lifecycleturn.steeredturn.interrupt_requestedturn.completeditem.starteditem.deltaitem.completeditem.faileditem.interruptedapproval.requiredsandbox.denied
Compaction visibility:
- auto compaction emits
item.started/item.completedwith item kindcontext_compactionandauto=true - manual compaction emits the same with
auto=false
Background Tasks
GET /v1/tasksPOST /v1/tasksGET /v1/tasks/{id}POST /v1/tasks/{id}/cancel
Tasks execute through the same runtime thread/turn pipeline and include:
- linked
thread_id/turn_id - runtime event count
- timeline + tool summaries + artifact references
Persistence
Runtime store (default under task data root):
runtime/threads/*.jsonruntime/turns/*.jsonruntime/items/*.jsonruntime/events/{thread_id}.jsonlruntime/state.json(monotonic sequence)
Task store:
- default
~/.deepseek/tasks(override withDEEPSEEK_TASKS_DIR)
Both runtime and task state are restart-safe.