[{"data":1,"prerenderedAt":1258},["ShallowReactive",2],{"navigation_docs":3,"-reference-harnesses":270,"-reference-harnesses-surround":1253},[4,28,51,110,243],{"title":5,"path":6,"stem":7,"children":8},"Get started","\u002Fget-started","1.get-started",[9,12,16,20,24],{"title":10,"path":6,"stem":11},"Overview","1.get-started\u002Findex",{"title":13,"path":14,"stem":15},"Why Kraft","\u002Fget-started\u002Fwhy-kraft","1.get-started\u002F0.why-kraft",{"title":17,"path":18,"stem":19},"Install","\u002Fget-started\u002Finstall","1.get-started\u002F1.install",{"title":21,"path":22,"stem":23},"Your first work item","\u002Fget-started\u002Ffirst-work-item","1.get-started\u002F2.first-work-item",{"title":25,"path":26,"stem":27},"Troubleshooting and FAQ","\u002Fget-started\u002Ftroubleshooting","1.get-started\u002F3.troubleshooting",{"title":29,"path":30,"stem":31,"children":32},"Concepts","\u002Fconcepts","2.concepts",[33,35,39,43,47],{"title":10,"path":30,"stem":34},"2.concepts\u002Findex",{"title":36,"path":37,"stem":38},"Vocabulary","\u002Fconcepts\u002Fvocabulary","2.concepts\u002F1.vocabulary",{"title":40,"path":41,"stem":42},"How a work item runs","\u002Fconcepts\u002Fhow-a-work-item-runs","2.concepts\u002F2.how-a-work-item-runs",{"title":44,"path":45,"stem":46},"Caps and budgets","\u002Fconcepts\u002Fcaps-and-budgets","2.concepts\u002F3.caps-and-budgets",{"title":48,"path":49,"stem":50},"Why a permission gate","\u002Fconcepts\u002Fpermission-gate","2.concepts\u002F4.permission-gate",{"title":52,"path":53,"stem":54,"children":55},"Guides","\u002Fguides","3.guides",[56,58,62,66,70,74,78,82,86,90,94,98,102,106],{"title":10,"path":53,"stem":57},"3.guides\u002Findex",{"title":59,"path":60,"stem":61},"Use Kraft from your agent","\u002Fguides\u002Fagent-integration","3.guides\u002F01.agent-integration",{"title":63,"path":64,"stem":65},"Kraft Lite","\u002Fguides\u002Fkraft-lite","3.guides\u002F02.kraft-lite",{"title":67,"path":68,"stem":69},"Remote access","\u002Fguides\u002Fremote-access","3.guides\u002F03.remote-access",{"title":71,"path":72,"stem":73},"Add or override a harness","\u002Fguides\u002Fadding-a-harness","3.guides\u002F04.adding-a-harness",{"title":75,"path":76,"stem":77},"Schedule or webhook work","\u002Fguides\u002Fschedule-and-webhook-work","3.guides\u002F05.schedule-and-webhook-work",{"title":79,"path":80,"stem":81},"Add a security review or a gate reviewer","\u002Fguides\u002Fadd-review-agents","3.guides\u002F06.add-review-agents",{"title":83,"path":84,"stem":85},"Kraft for VS Code","\u002Fguides\u002Fvscode","3.guides\u002F07.vscode",{"title":87,"path":88,"stem":89},"Reviewing a change","\u002Fguides\u002Freview-a-change","3.guides\u002F08.review-a-change",{"title":91,"path":92,"stem":93},"Write your own chain","\u002Fguides\u002Fwrite-your-own-chain","3.guides\u002F09.write-your-own-chain",{"title":95,"path":96,"stem":97},"Switch a harness","\u002Fguides\u002Fswitch-harness","3.guides\u002F10.switch-harness",{"title":99,"path":100,"stem":101},"Upgrade your templates","\u002Fguides\u002Fupgrading-templates","3.guides\u002F11.upgrading-templates",{"title":103,"path":104,"stem":105},"Operations","\u002Fguides\u002Foperations","3.guides\u002F12.operations",{"title":107,"path":108,"stem":109},"Worker Kit","\u002Fguides\u002Fworker-kit","3.guides\u002F13.worker-kit",{"title":111,"path":112,"stem":113,"children":114},"Reference","\u002Freference","4.reference",[115,117,139,183,201,205,227,231,235,239],{"title":10,"path":112,"stem":116},"4.reference\u002Findex",{"title":118,"path":119,"stem":120,"children":121},"CLI","\u002Freference\u002Fcli","4.reference\u002F1.cli\u002Findex",[122,123,127,131,135],{"title":10,"path":119,"stem":120},{"title":124,"path":125,"stem":126},"Item verbs","\u002Freference\u002Fcli\u002Fitem","4.reference\u002F1.cli\u002F2.item",{"title":128,"path":129,"stem":130},"View verbs","\u002Freference\u002Fcli\u002Fview","4.reference\u002F1.cli\u002F3.view",{"title":132,"path":133,"stem":134},"Repo verbs","\u002Freference\u002Fcli\u002Frepo","4.reference\u002F1.cli\u002F4.repo",{"title":136,"path":137,"stem":138},"Admin verbs","\u002Freference\u002Fcli\u002Fadmin","4.reference\u002F1.cli\u002F5.admin",{"title":140,"path":141,"stem":142,"children":143},"Configuration","\u002Freference\u002Fconfiguration","4.reference\u002F2.configuration\u002Findex",[144,145,155,159,163,167,171,175,179],{"title":10,"path":141,"stem":142},{"title":146,"path":147,"stem":148,"children":149},"Repos","\u002Freference\u002Fconfiguration\u002Frepos","4.reference\u002F2.configuration\u002F2.repos\u002Findex",[150,151],{"title":10,"path":147,"stem":148},{"title":152,"path":153,"stem":154},"Workspaces","\u002Freference\u002Fconfiguration\u002Frepos\u002Fworkspaces","4.reference\u002F2.configuration\u002F2.repos\u002F3.workspaces",{"title":156,"path":157,"stem":158},"Policy","\u002Freference\u002Fconfiguration\u002Fpolicy","4.reference\u002F2.configuration\u002F3.policy",{"title":160,"path":161,"stem":162},"Library and chains","\u002Freference\u002Fconfiguration\u002Flibrary-and-chains","4.reference\u002F2.configuration\u002F4.library-and-chains",{"title":164,"path":165,"stem":166},"Harnesses file","\u002Freference\u002Fconfiguration\u002Fharnesses-file","4.reference\u002F2.configuration\u002F5.harnesses-file",{"title":168,"path":169,"stem":170},"Access","\u002Freference\u002Fconfiguration\u002Faccess","4.reference\u002F2.configuration\u002F6.access",{"title":172,"path":173,"stem":174},"Intake","\u002Freference\u002Fconfiguration\u002Fintake","4.reference\u002F2.configuration\u002F7.intake",{"title":176,"path":177,"stem":178},"Sandbox host","\u002Freference\u002Fconfiguration\u002Fsandbox","4.reference\u002F2.configuration\u002F8.sandbox",{"title":180,"path":181,"stem":182},"Environment variables","\u002Freference\u002Fconfiguration\u002Fenvironment-variables","4.reference\u002F2.configuration\u002F9.environment-variables",{"title":184,"path":185,"stem":186,"children":187},"Chain nodes","\u002Freference\u002Fchain-nodes","4.reference\u002F3.chain-nodes\u002Findex",[188,189,193,197],{"title":10,"path":185,"stem":186},{"title":190,"path":191,"stem":192},"Subprocess tasks","\u002Freference\u002Fchain-nodes\u002Fsubprocess-tasks","4.reference\u002F3.chain-nodes\u002F2.subprocess-tasks",{"title":194,"path":195,"stem":196},"Fix loop and judge","\u002Freference\u002Fchain-nodes\u002Ffix-loop","4.reference\u002F3.chain-nodes\u002F3.fix-loop",{"title":198,"path":199,"stem":200},"Result file","\u002Freference\u002Fchain-nodes\u002Fresult-file","4.reference\u002F3.chain-nodes\u002F4.result-file",{"title":202,"path":203,"stem":204},"Permission gate","\u002Freference\u002Fpermissions","4.reference\u002F4.permissions",{"title":206,"path":207,"stem":208,"children":209},"Agent harnesses","\u002Freference\u002Fharnesses","4.reference\u002F5.harnesses\u002Findex",[210,211,215,219,223],{"title":10,"path":207,"stem":208},{"title":212,"path":213,"stem":214},"Unattended runs","\u002Freference\u002Fharnesses\u002Funattended-runs","4.reference\u002F5.harnesses\u002F2.unattended-runs",{"title":216,"path":217,"stem":218},"Agent profiles","\u002Freference\u002Fharnesses\u002Fagent-profiles","4.reference\u002F5.harnesses\u002F3.agent-profiles",{"title":220,"path":221,"stem":222},"Harness files","\u002Freference\u002Fharnesses\u002Fharness-files","4.reference\u002F5.harnesses\u002F4.harness-files",{"title":224,"path":225,"stem":226},"Fallback and escalation","\u002Freference\u002Fharnesses\u002Ffallback-and-escalation","4.reference\u002F5.harnesses\u002F5.fallback-and-escalation",{"title":228,"path":229,"stem":230},"Inbound triggers","\u002Freference\u002Ftriggers","4.reference\u002F6.triggers",{"title":232,"path":233,"stem":234},"HTTP API","\u002Freference\u002Fhttp-api","4.reference\u002F7.http-api",{"title":236,"path":237,"stem":238},"MCP tools","\u002Freference\u002Fmcp-tools","4.reference\u002F8.mcp-tools",{"title":240,"path":241,"stem":242},"Events","\u002Freference\u002Fevents","4.reference\u002F9.events",{"title":244,"path":245,"stem":246,"children":247},"Project","\u002Fproject","5.project",[248,250,254,258,262,266],{"title":10,"path":245,"stem":249},"5.project\u002Findex",{"title":251,"path":252,"stem":253},"Architecture","\u002Fproject\u002Farchitecture","5.project\u002F1.architecture",{"title":255,"path":256,"stem":257},"Contributing","\u002Fproject\u002Fcontributing","5.project\u002F2.contributing",{"title":259,"path":260,"stem":261},"Security","\u002Fproject\u002Fsecurity","5.project\u002F3.security",{"title":263,"path":264,"stem":265},"Data and privacy","\u002Fproject\u002Fdata-and-privacy","5.project\u002F4.data-and-privacy",{"title":267,"path":268,"stem":269},"Status and support","\u002Fproject\u002Fstatus-and-support","5.project\u002F5.status-and-support",{"id":271,"title":206,"body":272,"description":1246,"extension":1247,"links":1248,"meta":1249,"navigation":1250,"path":207,"seo":1251,"stem":208,"__hash__":1252},"docs\u002F4.reference\u002F5.harnesses\u002Findex.md",{"type":273,"value":274,"toc":1237},"minimark",[275,279,284,315,351,425,449,452,864,868,933,979,994,1000,1024,1052,1077,1105,1109,1116,1144,1147,1233],[276,277,278],"p",{},"A harness is one agent runtime described as data; this page lists the six Kraft ships and what each supports.",[280,281,283],"h2",{"id":282},"in-this-section","In this section",[285,286,287,295,305,310],"ul",{},[288,289,290,294],"li",{},[291,292,293],"a",{"href":213},"How each harness runs unattended",": the mode each CLI runs in when nobody can answer a prompt.",[288,296,297,299,300,304],{},[291,298,216],{"href":217},": named model tiers a task selects with ",[301,302,303],"code",{},"profile:",".",[288,306,307,309],{},[291,308,220],{"href":221},": the YAML file that describes one harness.",[288,311,312,314],{},[291,313,224],{"href":225},": where a launch goes next, and which harness runs an escalation turn.",[276,316,317,318,322,323,326,327,333,334,338,339,342,343,346,347,350],{},"A ",[319,320,321],"strong",{},"harness"," is one agent runtime, described as data — a fact about a CLI, not\ncode. An ",[301,324,325],{},"agent"," task in ",[291,328,330],{"href":329},"\u002Freference\u002Fconfiguration\u002Flibrary-and-chains#libraryyaml-reusable-components",[301,331,332],{},"library.yaml","\nnames a harness ",[335,336,337],"em",{},"profile"," in its ",[301,340,341],{},"harness:"," field, and ",[301,344,345],{},"harnesses.yaml"," says\nwhich harness (the profile's ",[301,348,349],{},"provider",") that profile runs:",[352,353,358],"pre",{"className":354,"code":355,"language":356,"meta":357,"style":357},"language-yaml shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","spec_author: { kind: agent, harness: claude, prompt: \"...\", produces: spec }\n","yaml","",[301,359,360],{"__ignoreMap":357},[361,362,365,369,373,376,379,381,385,388,391,393,396,398,401,403,406,409,412,414,417,419,422],"span",{"class":363,"line":364},"line",1,[361,366,368],{"class":367},"swJcz","spec_author",[361,370,372],{"class":371},"sMK4o",":",[361,374,375],{"class":371}," {",[361,377,378],{"class":367}," kind",[361,380,372],{"class":371},[361,382,384],{"class":383},"sfazB"," agent",[361,386,387],{"class":371},",",[361,389,390],{"class":367}," harness",[361,392,372],{"class":371},[361,394,395],{"class":383}," claude",[361,397,387],{"class":371},[361,399,400],{"class":367}," prompt",[361,402,372],{"class":371},[361,404,405],{"class":371}," \"",[361,407,408],{"class":383},"...",[361,410,411],{"class":371},"\"",[361,413,387],{"class":371},[361,415,416],{"class":367}," produces",[361,418,372],{"class":371},[361,420,421],{"class":383}," spec",[361,423,424],{"class":371}," }\n",[276,426,427,428,431,432,434,435,437,438,441,442,444,445,448],{},"Every agent task Kraft ships names ",[301,429,430],{},"claude",". To run a task on another\nharness, make sure ",[301,433,345],{}," has a profile for it (the shipped file has\n",[301,436,430],{}," and ",[301,439,440],{},"codex",") and change the task's ",[301,443,341],{}," to that profile's id.\n",[291,446,447],{"href":96},"Switch a task to another harness"," walks through it.",[276,450,451],{},"Kraft ships seven harnesses:",[453,454,455,471],"table",{},[456,457,458],"thead",{},[459,460,461,465,468],"tr",{},[462,463,464],"th",{},"id",[462,466,467],{},"Binary",[462,469,470],{},"Notable gaps",[472,473,474,488,543,616,689,774,801],"tbody",{},[459,475,476,481,485],{},[477,478,479],"td",{},[301,480,430],{},[477,482,483],{},[301,484,430],{},[477,486,487],{},"Full capability set.",[459,489,490,494,499],{},[477,491,492],{},[301,493,440],{},[477,495,496],{},[301,497,498],{},"codex exec",[477,500,501,502,505,506,509,510,513,514,437,517,520,521,524,525,528,529,533,534,537,538,542],{},"No ",[301,503,504],{},"restrict_tools",", ",[301,507,508],{},"approval_channel",", or ",[301,511,512],{},"autocompact"," — a profile or task asking for one of those is rejected at load. ",[301,515,516],{},"deny_tools",[301,518,519],{},"allowed_tools"," work through a ",[301,522,523],{},"PreToolUse"," hook passed with ",[301,526,527],{},"-c"," and trusted for that launch only, answered by the ",[291,530,532],{"href":531},"\u002Freference\u002Fpermissions#codex","permission gate","; web search never reaches it. Tokens, the thread id and a usage-limit stop are read off its ",[301,535,536],{},"--json"," log; it reports no cost, and no reset time for a limit, so ",[291,539,541],{"href":540},"\u002Fconcepts\u002Fcaps-and-budgets#harnesses-that-report-no-cost","the dollar caps estimate it"," on the model Kraft launched it with.",[459,544,545,550,555],{},[477,546,547],{},[301,548,549],{},"cursor",[477,551,552],{},[301,553,554],{},"agent -p --trust",[477,556,557,558,561,562,565,566,569,570,573,574,505,576,505,578,580,581,584,585,437,587,520,589,592,593,596,597,600,601,604,605,607,608,611,612,615],{},"Cursor's agent CLI. Runs in ",[301,559,560],{},"--auto-review"," (Cursor's classifier); ",[301,563,564],{},"permission_mode: force"," overrides it. No out-of-band context channel (context goes in the prompt), no ",[301,567,568],{},"effort"," (a model id can carry one, such as ",[301,571,572],{},"'name[effort=high]'","), and no ",[301,575,504],{},[301,577,508],{},[301,579,512],{}," or ",[301,582,583],{},"rate_limit_signal",". ",[301,586,516],{},[301,588,519],{},[301,590,591],{},"preToolUse"," hook Kraft installs in the worktree, answered by the ",[291,594,532],{"href":595},"\u002Freference\u002Fpermissions#cursor",". Tokens and the chat id ",[301,598,599],{},"resume"," takes are read off its ",[301,602,603],{},"stream-json"," log; it reports no cost and names its model \"Auto\", so ",[291,606,541],{"href":540}," only on a launch model ",[301,609,610],{},"prices.json"," lists, and otherwise count it as $0 and warn. An API-key install needs ",[301,613,614],{},"env_passthrough: [CURSOR_API_KEY]"," on the repo.",[459,617,618,623,628],{},[477,619,620],{},[301,621,622],{},"opencode",[477,624,625],{},[301,626,627],{},"opencode run",[477,629,630,631,634,635,505,637,580,639,584,641,437,643,645,646,649,650,653,654,657,658,661,662,664,665,668,669,672,673,676,677,680,681,684,685,688],{},"Needs OpenCode 2.0.0 or newer (not npm's 1.x ",[301,632,633],{},"opencode-ai","); an older one is refused at launch. No out-of-band context channel (context goes in the prompt), no ",[301,636,504],{},[301,638,508],{},[301,640,512],{},[301,642,516],{},[301,644,519],{}," are written into the launch's own OpenCode config, with ",[301,647,648],{},"--standalone",", when the task's policy sets either (",[291,651,532],{"href":652},"\u002Freference\u002Fpermissions#opencode-and-amp-rules-written-at-launch","). ",[301,655,656],{},"model"," is ",[301,659,660],{},"provider\u002Fmodel"," for any provider OpenCode knows. There is no ",[301,663,568],{},": name a variant in the model id (",[301,666,667],{},"openai\u002Fgpt-5.5#high","). Every launch passes ",[301,670,671],{},"--auto",", since ",[301,674,675],{},"run"," otherwise rejects every permission request. Tokens, cost, the session id and a rate-limit stop are read off its ",[301,678,679],{},"--format json"," log. That log leaves out the last step's usage, so Kraft reads the session's totals from ",[301,682,683],{},"opencode session export \u003Csession id>"," when the run ends, and falls back to the log's steps if that fails. A ",[301,686,687],{},"task"," sub-agent's tokens are not in the log.",[459,690,691,696,701],{},[477,692,693],{},[301,694,695],{},"antigravity",[477,697,698],{},[301,699,700],{},"agy -p",[477,702,703,704,707,708,711,712,715,716,718,719,723,724,505,726,505,728,505,730,580,732,734,735,657,737,740,741,743,744,746,747,749,750,752,753,755,756,759,760,762,763,766,767,769,770,304],{},"Google's Antigravity CLI, for an individual Google account: Gemini CLI stopped serving those on 2026-06-18, so ",[301,705,706],{},"gemini"," is for API-key and Code Assist users. Every launch passes ",[301,709,710],{},"--dangerously-skip-permissions",", since headless ",[301,713,714],{},"agy"," otherwise denies every file write and shell command and still exits 0. So Kraft has no per-action control over an ",[301,717,714],{}," worker: the worktree is the boundary, and a ",[291,720,722],{"href":721},"\u002Freference\u002Fconfiguration\u002Frepos#sandboxed-workers","sandbox"," is the way to bound what it can reach. No out-of-band context channel (context goes in the prompt), no ",[301,725,516],{},[301,727,519],{},[301,729,504],{},[301,731,508],{},[301,733,512],{},": a task with a tool policy is refused. ",[301,736,568],{},[301,738,739],{},"--effort low|medium|high|max",", checked by ",[301,742,714],{}," against the model. Tokens, the conversation id ",[301,745,599],{}," takes and a quota stop are read off its ",[301,748,603],{}," log; it reports no cost, so ",[291,751,541],{"href":540}," on the model it was launched with when ",[301,754,610],{}," lists it. Name the base model (",[301,757,758],{},"gemini-3.8-flash",") and set ",[301,761,568],{},", not a slug with the effort in it (",[301,764,765],{},"gemini-3.8-flash-low","), or the session can't be priced. Needs a prior interactive sign-in (",[301,768,714],{}," once) on the machine, or a Gemini API key: see ",[291,771,773],{"href":772},"\u002Fguides\u002Fadding-a-harness#antigravity","Antigravity credentials",[459,775,776,780,784],{},[477,777,778],{},[301,779,706],{},[477,781,782],{},[301,783,706],{},[477,785,786,787,789,790,792,793,796,797,800],{},"No out-of-band context channel (context goes in-band via the prompt), no ",[301,788,568],{},", no ",[301,791,599],{}," at all (Gemini's ",[301,794,795],{},"--resume"," takes an index or ",[301,798,799],{},"\"latest\"",", not a session id, so the capability isn't declared).",[459,802,803,808,813],{},[477,804,805],{},[301,806,807],{},"amp",[477,809,810],{},[301,811,812],{},"amp -x",[477,814,501,815,817,818,820,821,824,825,828,829,505,831,505,833,580,835,584,837,437,839,841,842,845,846,848,849,600,851,749,854,856,857,859,860,863],{},[301,816,656],{},": Amp picks it. ",[301,819,568],{}," is Amp's mode (",[301,822,823],{},"-m low|medium|high|ultra","). Context goes in-band via the prompt. No ",[301,826,827],{},"permission_mode"," (Amp asks for no approvals), no ",[301,830,504],{},[301,832,508],{},[301,834,512],{},[301,836,583],{},[301,838,516],{},[301,840,519],{}," go into a settings file of the launch's own (",[301,843,844],{},"--settings-file",") when the task's policy sets either (",[291,847,532],{"href":652},"). Tokens and the thread id ",[301,850,599],{},[301,852,853],{},"--stream-json",[291,855,541],{"href":540}," on the model its log names when ",[301,858,610],{}," lists it. Both command lines pass ",[301,861,862],{},"--no-archive-after-execute",", because an archived thread can't be resumed.",[280,865,867],{"id":866},"capabilities-not-flags","Capabilities, not flags",[276,869,870,871,874,875,505,878,505,881,505,883,505,885,887,888,505,890,505,892,505,894,505,896,887,898,505,900,505,903,505,906,505,908,505,911,914,915,657,917,920,921,924,925,928,929,932],{},"A task's YAML never names a harness's actual CLI flags. It asks for a\n",[319,872,873],{},"capability"," — ",[301,876,877],{},"prompt",[301,879,880],{},"context",[301,882,656],{},[301,884,568],{},[301,886,827],{},",\n",[301,889,516],{},[301,891,519],{},[301,893,504],{},[301,895,508],{},[301,897,599],{},[301,899,512],{},[301,901,902],{},"structured_log",[301,904,905],{},"usage",[301,907,583],{},[301,909,910],{},"writable_dirs",[301,912,913],{},"mcp_config"," — and each harness's own YAML\n(a YAML file per harness) maps that capability onto\nwhatever its CLI actually calls it. ",[301,916,827],{},[301,918,919],{},"--permission-mode acceptEdits|auto|..."," for Claude, ",[301,922,923],{},"-c sandbox_mode=read-only|workspace-write|...","\nfor Codex, ",[301,926,927],{},"--approval-mode default|yolo|..."," for Gemini, ",[301,930,931],{},"--auto-review|--force","\nfor Cursor — one Kraft-side name, four different flags.",[276,934,935,936,938,939,942,943,946,947,887,950,953,954,956,957,580,960,963,964,967,968,971,972,974,975,978],{},"Codex's options are all ",[301,937,527],{}," config keys. Codex\nruns in its \"approve for me\" mode by default, Claude's ",[301,940,941],{},"auto"," counterpart: the\nsandbox is ",[301,944,945],{},"workspace-write",", and a sandbox escalation the model asks for goes\nto Codex's automatic reviewer (",[301,948,949],{},"approval_policy=on-request",[301,951,952],{},"approvals_reviewer=auto_review","), not to a human. A ",[301,955,827],{}," of\n",[301,958,959],{},"read-only",[301,961,962],{},"danger-full-access"," (a harness profile's ",[301,965,966],{},"defaults:"," or a task)\nchanges the sandbox. The reviewer stays on in every mode. Under Kraft's\n",[291,969,970],{"href":721},"docker sandbox"," the default\nbecomes ",[301,973,962],{}," (",[301,976,977],{},"container_permission_mode","): Codex's own\nsandbox cannot start inside a container, and the container is the boundary.",[276,980,981,982,505,984,505,986,988,989,887,991,993],{},"Three capabilities are required — ",[301,983,877],{},[301,985,880],{},[301,987,905],{}," — since no\nagent dispatch can be built without them. Two are non-invocable —",[301,990,905],{},[301,992,583],{}," — they describe what Kraft reads back out of a session\n(from its structured log or a result file), not an argv it constructs.",[276,995,996,997,999],{},"One is filled by Kraft, never by a task: ",[301,998,910],{},", the directories\noutside the worktree that a worker must write. There are two:",[285,1001,1002,1013],{},[288,1003,1004,1005,1008,1009,1012],{},"the directory holding the launch's ",[301,1006,1007],{},"$KRAFT_RESULT_PATH","\n(",[301,1010,1011],{},"$KRAFT_HOME\u002Frun\u002Fresults",");",[288,1014,1015,1016,1019,1020,1023],{},"the worktree's git common dir, where every commit writes. For a linked\nworktree that's the main checkout's ",[301,1017,1018],{},".git",". Kraft asks git for it\n(",[301,1021,1022],{},"git rev-parse --git-common-dir",") and leaves it out when git has none.",[276,1025,1026,1029,1030,1033,1034,1037,1038,1040,1041,1044,1045,1048,1049,1051],{},[301,1027,1028],{},"{value}"," is one JSON array of absolute paths, such as\n",[301,1031,1032],{},"[\"\u002Fhome\u002Fme\u002F.kraft\u002Frun\u002Fresults\",\"\u002Fhome\u002Fme\u002Fsrc\u002Fapp\u002F.git\"]",". It's for a CLI whose\nown sandbox would refuse to write outside the worktree. Codex binds it to\n",[301,1035,1036],{},"-c sandbox_workspace_write.writable_roots={value}"," (TOML reads the JSON array\nas an inline array). Its ",[301,1039,945],{}," sandbox writes only the workspace\nand ",[301,1042,1043],{},"\u002Ftmp",", so without the grant a codex worker on a default install\n(",[301,1046,1047],{},"~\u002F.kraft",") can write neither its result file nor a commit. Kraft grants both\ndirectories outright, because Codex's automatic reviewer is not relied on for\neither one. A harness\nthat doesn't declare ",[301,1050,910],{}," gets nothing extra.",[276,1053,1054,1055,1058,1059,1062,1063,1065,1066,1069,1070,1073,1074,1076],{},"Another is filled by Kraft only for a ",[291,1056,1057],{"href":721},"sandboxed","\nlaunch with ",[301,1060,1061],{},"network:",": ",[301,1064,913],{},", the CLI's MCP servers as one JSON object,\n",[301,1067,1068],{},"{\"mcpServers\": {\"kraft\": {\"type\": \"http\", \"url\": \"http:\u002F\u002Fkraft\u002Fmcp\"}}}",": Kraft's\nown server for that session, reached through the sandbox's route out, since the\nMCP server registered on your machine is out of the container's reach. Claude\nbinds it to ",[301,1071,1072],{},"--strict-mcp-config --mcp-config {value}",", so that server is its\nonly one and its ",[301,1075,508],{}," tool is answered there.",[276,1078,1079,1080,1083,1084,657,1086,1089,1090,1093,1094,1097,1098,1100,1101,1104],{},"Some harnesses declare ",[301,1081,1082],{},"values:"," on a capability — a closed vocabulary the\nCLI itself would reject (Codex's ",[301,1085,568],{},[301,1087,1088],{},"minimal, low, medium, high, xhigh",",\nClaude's is ",[301,1091,1092],{},"low, medium, high, xhigh, max",") — checked at load time, and\n",[301,1095,1096],{},"always:"," — the value Kraft uses when nothing else is supplied (Gemini's\n",[301,1099,827],{}," defaults to ",[301,1102,1103],{},"yolo",", since a headless worker has nobody to\nanswer an approval prompt).",[1106,1107,1108],"h3",{"id":807},"Amp",[276,1110,1111,1112,304],{},"Amp needs credentials a headless process can use. See ",[291,1113,1115],{"href":1114},"\u002Fguides\u002Fadding-a-harness#set-up-harness-credentials","Set up harness credentials",[285,1117,1118,1124,1131],{},[288,1119,1120,1121,304],{},"Kraft's token counts for an Amp run are the thread's own, message by message.\nThey match ",[301,1122,1123],{},"amp threads export",[288,1125,1126,1127,1130],{},"Amp's bill (",[301,1128,1129],{},"amp threads usage",") can count a few requests that aren't in the\nthread, and it's the only place Amp reports cost, so Kraft records none.",[288,1132,1133,1134,1136,1137,1139,1140,1143],{},"An agent profile can't select ",[301,1135,807],{},": a profile needs a model for the\nprovider, and Amp takes none. A task on ",[301,1138,807],{}," sets ",[301,1141,1142],{},"effort:"," itself.",[1106,1145,1146],{"id":549},"Cursor",[285,1148,1149,1161,1190,1206,1223],{},[288,1150,1151,1154,1155,1157,1158,1160],{},[319,1152,1153],{},"Mode."," Kraft runs ",[301,1156,325],{}," in ",[301,1159,560],{},", Cursor's Smart Auto: a\nserver-side classifier runs the tool calls it judges safe and refuses the\nrest. Without a mode, print mode only proposes edits and applies none.",[288,1162,1163,1166,1167,1170,1171,1174,1175,1178,1179,1182,1183,1186,1187,1189],{},[319,1164,1165],{},"Config directory."," Every launch sets ",[301,1168,1169],{},"CURSOR_CONFIG_DIR"," to\n",[301,1172,1173],{},"$KRAFT_HOME\u002Frun\u002Fharness-config\u002Fcursor\u002F",", a directory Kraft owns. Your own\n",[301,1176,1177],{},"~\u002F.cursor"," is never read or changed. Before each launch Kraft writes\n",[301,1180,1181],{},"cli-config.json"," there with commit attribution off, because with it on\nCursor adds a ",[301,1184,1185],{},"Co-authored-by: Cursor"," trailer to every commit and the\nclassifier refused those commits. The file adds no permission rule. The\ndirectory is shared by all launches, not one per launch, because ",[301,1188,795],{},"\nhas to find the chat an earlier launch wrote. A sandboxed item gets one of\nits own, inside its sandbox home.",[288,1191,1192,1195,1196,437,1198,1200,1201,1203,1204,304],{},[319,1193,1194],{},"Tool policy."," ",[301,1197,516],{},[301,1199,519],{}," go through a ",[301,1202,591],{}," hook. See ",[291,1205,1146],{"href":595},[288,1207,1208,1211,1212,1215,1216,1219,1220,1222],{},[319,1209,1210],{},"Login."," The login lives in the OS keychain, not the config dir. With an\nAPI key instead, name ",[301,1213,1214],{},"CURSOR_API_KEY"," in the repo's ",[301,1217,1218],{},"env_passthrough",": the\nonly way a ",[291,1221,1057],{"href":721},"\nworker, which has no keychain, logs in.",[288,1224,1225,1228,1229,1232],{},[319,1226,1227],{},"Usage."," Tokens come off the log's closing ",[301,1230,1231],{},"result"," line, one per run:\nuncached input, output, and cache reads and writes. Cursor reports no cost,\nso Kraft records none, only an estimate when it can price the launch model.",[1234,1235,1236],"style",{},"html pre.shiki code .swJcz, html code.shiki .swJcz{--shiki-light:#E53935;--shiki-default:#F07178;--shiki-dark:#F07178}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":357,"searchDepth":1238,"depth":1238,"links":1239},2,[1240,1241],{"id":282,"depth":1238,"text":283},{"id":866,"depth":1238,"text":867,"children":1242},[1243,1245],{"id":807,"depth":1244,"text":1108},3,{"id":549,"depth":1244,"text":1146},"Which agent CLIs Kraft runs, what each supports, and how a task picks one.","md",null,{},{"title":10},{"title":206,"description":1246},"pBrmpXySnSJJkPpRQZb48VoOrao6gRzJlkYjDe2Qgww",[1254,1256],{"title":202,"path":203,"stem":204,"description":1255,"children":-1},"What Kraft's permission gate does per harness, how it decides, and the keys that configure it.",{"title":212,"path":213,"stem":214,"description":1257,"children":-1},"The permission mode each harness runs in when no one can answer a prompt.",1790824506051]