Deep AgentsDeep Agents 0.7 · Python 3.11+
0%
1
Curious builder0 XP earned · 300 to level 2
0 daysFinish a lesson to begin
Badge collection0 of 6 unlocked
28 small wins to finish your pathNext lesson →

FilesystemBackend: files on your disk

FilesystemBackend is a backend that maps the agent's file paths to real files under a folder you choose, so what the agent writes stays on your disk after the program ends.

Last updated: 29 Sep, 2026 · Deep Agents 0.7

FilesystemBackend: writing to the hard disk · from the Complete Deep Agents Course With LangChain · 71:47 to 74:54

The video's todo.txt on disk

The second backend in the video saves files in a root directory on the hard disk. It imports FilesystemBackend from deepagents.backends, sets the root to the notebook's own folder, and passes virtual_mode=True. The same request as before, create /notes/todo.txt, now makes a real notes folder with todo.txt in the project. The video checks it with pathlib.Path, then builds a fresh agent that has never seen the file and asks it to read the file back. The video's code follows, run on Groq with the model line swapped:

ExampleAPI keyFrom the video, run on Groq
from pathlib import Path

from deepagents import create_deep_agent
from deepagents.backends import FilesystemBackend
from langchain.chat_models import init_chat_model

model = init_chat_model("groq:openai/gpt-oss-120b", max_retries=6)
ROOT = "."

agent = create_deep_agent(model=model, backend=FilesystemBackend(root_dir=ROOT, virtual_mode=True))
result = agent.invoke({"messages": [{"role": "user", "content": (
    "Create a file at /notes/todo.txt with exactly this content:\n"
    "1. Record video\n2. Edit video\n3. Upload video\n"
    "Then tell me you've done it.")}]})
print("--- Agent reply ---")
print(result["messages"][-1].content)

disk_path = Path(ROOT) / "notes" / "todo.txt"
print("--- On disk:", disk_path, "exists:", disk_path.exists())
print(disk_path.read_text())

fresh_agent = create_deep_agent(model=model, backend=FilesystemBackend(root_dir=ROOT, virtual_mode=True))
followup = fresh_agent.invoke({"messages": [{"role": "user", "content": "Read /notes/todo.txt back to me verbatim."}]})
print("--- Read-back with a fresh agent ---")
print(followup["messages"][-1].content)

What the three steps show

  • The agent wrote the file with the same write_file tool as before; only the backend changed.
  • Python found it on disk at notes/todo.txt under the root folder, with the three lines.
  • A fresh agent read it without any files passed in, because the file is on disk, not in a previous result.

The FilesystemBackend call

python
from deepagents.backends import FilesystemBackend

backend = FilesystemBackend(root_dir="trips", virtual_mode=True)   # /notes/a.md -> trips/notes/a.md
agent = create_deep_agent(model=model, backend=backend)

virtual_mode=True keeps every path inside root_dir: the agent cannot reach .., ~ or an absolute path outside it. The installed 0.7.19 defaults it to True, while the docs page still describes False as the default; pass it explicitly, as the docs advise.

StateBackend vs FilesystemBackend

StateBackendFilesystemBackend
Files liveIn the run's stateIn a folder on disk
After the program endsGone, unless a saved checkpointer keeps the threadStill there
Another agent can read themOnly if you pass themYes, from the same folder
RiskNone to your diskThe agent can change real files

Where FilesystemBackend fits

  • A local coding or writing assistant that edits files in a project folder.
  • Saving the trip planner's itinerary where you can open it in an editor.
  • Reading an AGENTS.md or skills folder that already sits in your repository.
Watch out. Point root_dir at a scratch folder, never your home folder or a folder with .env files. With disk access and a web tool, an agent could read a secret and send it somewhere. The docs recommend a sandbox backend for servers.
Try it yourself
  • Change ROOT to "trips" and find where the file lands.
  • Ask the agent to write /../outside.txt and read what the backend does with the path.
  • Edit notes/todo.txt in your editor, then ask a fresh agent to read it.

Little by little, you're building something great.