[{"data":1,"prerenderedAt":1176},["ShallowReactive",2],{"navigation_docs":3,"-reference-harnesses":270,"-reference-harnesses-surround":1171},[4,28,51,110,243],{"title":5,"path":6,"stem":7,"children":8},"Get started","\u002Fget-started","1.get-started",[9,12,16,20,24],{"title":10,"path":6,"stem":11},"Overview","1.get-started\u002Findex",{"title":13,"path":14,"stem":15},"Why Kraft","\u002Fget-started\u002Fwhy-kraft","1.get-started\u002F0.why-kraft",{"title":17,"path":18,"stem":19},"Install","\u002Fget-started\u002Finstall","1.get-started\u002F1.install",{"title":21,"path":22,"stem":23},"Your first work item","\u002Fget-started\u002Ffirst-work-item","1.get-started\u002F2.first-work-item",{"title":25,"path":26,"stem":27},"Troubleshooting and FAQ","\u002Fget-started\u002Ftroubleshooting","1.get-started\u002F3.troubleshooting",{"title":29,"path":30,"stem":31,"children":32},"Concepts","\u002Fconcepts","2.concepts",[33,35,39,43,47],{"title":10,"path":30,"stem":34},"2.concepts\u002Findex",{"title":36,"path":37,"stem":38},"Vocabulary","\u002Fconcepts\u002Fvocabulary","2.concepts\u002F1.vocabulary",{"title":40,"path":41,"stem":42},"How a work item runs","\u002Fconcepts\u002Fhow-a-work-item-runs","2.concepts\u002F2.how-a-work-item-runs",{"title":44,"path":45,"stem":46},"Caps and budgets","\u002Fconcepts\u002Fcaps-and-budgets","2.concepts\u002F3.caps-and-budgets",{"title":48,"path":49,"stem":50},"Why a permission gate","\u002Fconcepts\u002Fpermission-gate","2.concepts\u002F4.permission-gate",{"title":52,"path":53,"stem":54,"children":55},"Guides","\u002Fguides","3.guides",[56,58,62,66,70,74,78,82,86,90,94,98,102,106],{"title":10,"path":53,"stem":57},"3.guides\u002Findex",{"title":59,"path":60,"stem":61},"Use Kraft from your agent","\u002Fguides\u002Fagent-integration","3.guides\u002F01.agent-integration",{"title":63,"path":64,"stem":65},"Kraft Lite","\u002Fguides\u002Fkraft-lite","3.guides\u002F02.kraft-lite",{"title":67,"path":68,"stem":69},"Remote access","\u002Fguides\u002Fremote-access","3.guides\u002F03.remote-access",{"title":71,"path":72,"stem":73},"Add or override a harness","\u002Fguides\u002Fadding-a-harness","3.guides\u002F04.adding-a-harness",{"title":75,"path":76,"stem":77},"Schedule or webhook work","\u002Fguides\u002Fschedule-and-webhook-work","3.guides\u002F05.schedule-and-webhook-work",{"title":79,"path":80,"stem":81},"Add a security review or a gate reviewer","\u002Fguides\u002Fadd-review-agents","3.guides\u002F06.add-review-agents",{"title":83,"path":84,"stem":85},"Kraft for VS Code","\u002Fguides\u002Fvscode","3.guides\u002F07.vscode",{"title":87,"path":88,"stem":89},"Reviewing a change","\u002Fguides\u002Freview-a-change","3.guides\u002F08.review-a-change",{"title":91,"path":92,"stem":93},"Write your own chain","\u002Fguides\u002Fwrite-your-own-chain","3.guides\u002F09.write-your-own-chain",{"title":95,"path":96,"stem":97},"Switch a harness","\u002Fguides\u002Fswitch-harness","3.guides\u002F10.switch-harness",{"title":99,"path":100,"stem":101},"Upgrade your templates","\u002Fguides\u002Fupgrading-templates","3.guides\u002F11.upgrading-templates",{"title":103,"path":104,"stem":105},"Operations","\u002Fguides\u002Foperations","3.guides\u002F12.operations",{"title":107,"path":108,"stem":109},"Worker Kit","\u002Fguides\u002Fworker-kit","3.guides\u002F13.worker-kit",{"title":111,"path":112,"stem":113,"children":114},"Reference","\u002Freference","4.reference",[115,117,139,183,201,205,227,231,235,239],{"title":10,"path":112,"stem":116},"4.reference\u002Findex",{"title":118,"path":119,"stem":120,"children":121},"CLI","\u002Freference\u002Fcli","4.reference\u002F1.cli\u002Findex",[122,123,127,131,135],{"title":10,"path":119,"stem":120},{"title":124,"path":125,"stem":126},"Item verbs","\u002Freference\u002Fcli\u002Fitem","4.reference\u002F1.cli\u002F2.item",{"title":128,"path":129,"stem":130},"View verbs","\u002Freference\u002Fcli\u002Fview","4.reference\u002F1.cli\u002F3.view",{"title":132,"path":133,"stem":134},"Repo verbs","\u002Freference\u002Fcli\u002Frepo","4.reference\u002F1.cli\u002F4.repo",{"title":136,"path":137,"stem":138},"Admin verbs","\u002Freference\u002Fcli\u002Fadmin","4.reference\u002F1.cli\u002F5.admin",{"title":140,"path":141,"stem":142,"children":143},"Configuration","\u002Freference\u002Fconfiguration","4.reference\u002F2.configuration\u002Findex",[144,145,155,159,163,167,171,175,179],{"title":10,"path":141,"stem":142},{"title":146,"path":147,"stem":148,"children":149},"Repos","\u002Freference\u002Fconfiguration\u002Frepos","4.reference\u002F2.configuration\u002F2.repos\u002Findex",[150,151],{"title":10,"path":147,"stem":148},{"title":152,"path":153,"stem":154},"Workspaces","\u002Freference\u002Fconfiguration\u002Frepos\u002Fworkspaces","4.reference\u002F2.configuration\u002F2.repos\u002F3.workspaces",{"title":156,"path":157,"stem":158},"Policy","\u002Freference\u002Fconfiguration\u002Fpolicy","4.reference\u002F2.configuration\u002F3.policy",{"title":160,"path":161,"stem":162},"Library and chains","\u002Freference\u002Fconfiguration\u002Flibrary-and-chains","4.reference\u002F2.configuration\u002F4.library-and-chains",{"title":164,"path":165,"stem":166},"Harnesses file","\u002Freference\u002Fconfiguration\u002Fharnesses-file","4.reference\u002F2.configuration\u002F5.harnesses-file",{"title":168,"path":169,"stem":170},"Access","\u002Freference\u002Fconfiguration\u002Faccess","4.reference\u002F2.configuration\u002F6.access",{"title":172,"path":173,"stem":174},"Intake","\u002Freference\u002Fconfiguration\u002Fintake","4.reference\u002F2.configuration\u002F7.intake",{"title":176,"path":177,"stem":178},"Sandbox host","\u002Freference\u002Fconfiguration\u002Fsandbox","4.reference\u002F2.configuration\u002F8.sandbox",{"title":180,"path":181,"stem":182},"Environment variables","\u002Freference\u002Fconfiguration\u002Fenvironment-variables","4.reference\u002F2.configuration\u002F9.environment-variables",{"title":184,"path":185,"stem":186,"children":187},"Chain nodes","\u002Freference\u002Fchain-nodes","4.reference\u002F3.chain-nodes\u002Findex",[188,189,193,197],{"title":10,"path":185,"stem":186},{"title":190,"path":191,"stem":192},"Subprocess tasks","\u002Freference\u002Fchain-nodes\u002Fsubprocess-tasks","4.reference\u002F3.chain-nodes\u002F2.subprocess-tasks",{"title":194,"path":195,"stem":196},"Fix loop and judge","\u002Freference\u002Fchain-nodes\u002Ffix-loop","4.reference\u002F3.chain-nodes\u002F3.fix-loop",{"title":198,"path":199,"stem":200},"Result file","\u002Freference\u002Fchain-nodes\u002Fresult-file","4.reference\u002F3.chain-nodes\u002F4.result-file",{"title":202,"path":203,"stem":204},"Permission gate","\u002Freference\u002Fpermissions","4.reference\u002F4.permissions",{"title":206,"path":207,"stem":208,"children":209},"Agent harnesses","\u002Freference\u002Fharnesses","4.reference\u002F5.harnesses\u002Findex",[210,211,215,219,223],{"title":10,"path":207,"stem":208},{"title":212,"path":213,"stem":214},"Unattended runs","\u002Freference\u002Fharnesses\u002Funattended-runs","4.reference\u002F5.harnesses\u002F2.unattended-runs",{"title":216,"path":217,"stem":218},"Agent profiles","\u002Freference\u002Fharnesses\u002Fagent-profiles","4.reference\u002F5.harnesses\u002F3.agent-profiles",{"title":220,"path":221,"stem":222},"Harness files","\u002Freference\u002Fharnesses\u002Fharness-files","4.reference\u002F5.harnesses\u002F4.harness-files",{"title":224,"path":225,"stem":226},"Fallback and escalation","\u002Freference\u002Fharnesses\u002Ffallback-and-escalation","4.reference\u002F5.harnesses\u002F5.fallback-and-escalation",{"title":228,"path":229,"stem":230},"Inbound triggers","\u002Freference\u002Ftriggers","4.reference\u002F6.triggers",{"title":232,"path":233,"stem":234},"HTTP API","\u002Freference\u002Fhttp-api","4.reference\u002F7.http-api",{"title":236,"path":237,"stem":238},"MCP tools","\u002Freference\u002Fmcp-tools","4.reference\u002F8.mcp-tools",{"title":240,"path":241,"stem":242},"Events","\u002Freference\u002Fevents","4.reference\u002F9.events",{"title":244,"path":245,"stem":246,"children":247},"Project","\u002Fproject","5.project",[248,250,254,258,262,266],{"title":10,"path":245,"stem":249},"5.project\u002Findex",{"title":251,"path":252,"stem":253},"Architecture","\u002Fproject\u002Farchitecture","5.project\u002F1.architecture",{"title":255,"path":256,"stem":257},"Contributing","\u002Fproject\u002Fcontributing","5.project\u002F2.contributing",{"title":259,"path":260,"stem":261},"Security","\u002Fproject\u002Fsecurity","5.project\u002F3.security",{"title":263,"path":264,"stem":265},"Data and privacy","\u002Fproject\u002Fdata-and-privacy","5.project\u002F4.data-and-privacy",{"title":267,"path":268,"stem":269},"Status and support","\u002Fproject\u002Fstatus-and-support","5.project\u002F5.status-and-support",{"id":271,"title":206,"body":272,"description":1164,"extension":1165,"links":1166,"meta":1167,"navigation":1168,"path":207,"seo":1169,"stem":208,"__hash__":1170},"docs\u002F4.reference\u002F5.harnesses\u002Findex.md",{"type":273,"value":274,"toc":1155},"minimark",[275,279,284,315,351,425,449,452,781,785,850,897,912,918,942,970,995,1023,1027,1034,1062,1065,1151],[276,277,278],"p",{},"A harness is one agent runtime described as data; this page lists the six Kraft ships and what each supports.",[280,281,283],"h2",{"id":282},"in-this-section","In this section",[285,286,287,295,305,310],"ul",{},[288,289,290,294],"li",{},[291,292,293],"a",{"href":213},"How each harness runs unattended",": the mode each CLI runs in when nobody can answer a prompt.",[288,296,297,299,300,304],{},[291,298,216],{"href":217},": named model tiers a task selects with ",[301,302,303],"code",{},"profile:",".",[288,306,307,309],{},[291,308,220],{"href":221},": the YAML file that describes one harness.",[288,311,312,314],{},[291,313,224],{"href":225},": where a launch goes next, and which harness runs an escalation turn.",[276,316,317,318,322,323,326,327,333,334,338,339,342,343,346,347,350],{},"A ",[319,320,321],"strong",{},"harness"," is one agent runtime, described as data — a fact about a CLI, not\ncode. An ",[301,324,325],{},"agent"," task in ",[291,328,330],{"href":329},"\u002Freference\u002Fconfiguration\u002Flibrary-and-chains#libraryyaml-reusable-components",[301,331,332],{},"library.yaml","\nnames a harness ",[335,336,337],"em",{},"profile"," in its ",[301,340,341],{},"harness:"," field, and ",[301,344,345],{},"harnesses.yaml"," says\nwhich harness (the profile's ",[301,348,349],{},"provider",") that profile runs:",[352,353,358],"pre",{"className":354,"code":355,"language":356,"meta":357,"style":357},"language-yaml shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","spec_author: { kind: agent, harness: claude, prompt: \"...\", produces: spec }\n","yaml","",[301,359,360],{"__ignoreMap":357},[361,362,365,369,373,376,379,381,385,388,391,393,396,398,401,403,406,409,412,414,417,419,422],"span",{"class":363,"line":364},"line",1,[361,366,368],{"class":367},"swJcz","spec_author",[361,370,372],{"class":371},"sMK4o",":",[361,374,375],{"class":371}," {",[361,377,378],{"class":367}," kind",[361,380,372],{"class":371},[361,382,384],{"class":383},"sfazB"," agent",[361,386,387],{"class":371},",",[361,389,390],{"class":367}," harness",[361,392,372],{"class":371},[361,394,395],{"class":383}," claude",[361,397,387],{"class":371},[361,399,400],{"class":367}," prompt",[361,402,372],{"class":371},[361,404,405],{"class":371}," \"",[361,407,408],{"class":383},"...",[361,410,411],{"class":371},"\"",[361,413,387],{"class":371},[361,415,416],{"class":367}," produces",[361,418,372],{"class":371},[361,420,421],{"class":383}," spec",[361,423,424],{"class":371}," }\n",[276,426,427,428,431,432,434,435,437,438,441,442,444,445,448],{},"Every agent task Kraft ships names ",[301,429,430],{},"claude",". To run a task on another\nharness, make sure ",[301,433,345],{}," has a profile for it (the shipped file has\n",[301,436,430],{}," and ",[301,439,440],{},"codex",") and change the task's ",[301,443,341],{}," to that profile's id.\n",[291,446,447],{"href":96},"Switch a task to another harness"," walks through it.",[276,450,451],{},"Kraft ships six harnesses:",[453,454,455,471],"table",{},[456,457,458],"thead",{},[459,460,461,465,468],"tr",{},[462,463,464],"th",{},"id",[462,466,467],{},"Binary",[462,469,470],{},"Notable gaps",[472,473,474,488,543,616,689,717],"tbody",{},[459,475,476,481,485],{},[477,478,479],"td",{},[301,480,430],{},[477,482,483],{},[301,484,430],{},[477,486,487],{},"Full capability set.",[459,489,490,494,499],{},[477,491,492],{},[301,493,440],{},[477,495,496],{},[301,497,498],{},"codex exec",[477,500,501,502,505,506,509,510,513,514,437,517,520,521,524,525,528,529,533,534,537,538,542],{},"No ",[301,503,504],{},"restrict_tools",", ",[301,507,508],{},"approval_channel",", or ",[301,511,512],{},"autocompact"," — a profile or task asking for one of those is rejected at load. ",[301,515,516],{},"deny_tools",[301,518,519],{},"allowed_tools"," work through a ",[301,522,523],{},"PreToolUse"," hook passed with ",[301,526,527],{},"-c"," and trusted for that launch only, answered by the ",[291,530,532],{"href":531},"\u002Freference\u002Fpermissions#codex","permission gate","; web search never reaches it. Tokens, the thread id and a usage-limit stop are read off its ",[301,535,536],{},"--json"," log; it reports no cost, and no reset time for a limit, so ",[291,539,541],{"href":540},"\u002Fconcepts\u002Fcaps-and-budgets#harnesses-that-report-no-cost","the dollar caps estimate it"," on the model Kraft launched it with.",[459,544,545,550,555],{},[477,546,547],{},[301,548,549],{},"cursor",[477,551,552],{},[301,553,554],{},"agent -p --trust",[477,556,557,558,561,562,565,566,569,570,573,574,505,576,505,578,580,581,584,585,437,587,520,589,592,593,596,597,600,601,604,605,607,608,611,612,615],{},"Cursor's agent CLI. Runs in ",[301,559,560],{},"--auto-review"," (Cursor's classifier); ",[301,563,564],{},"permission_mode: force"," overrides it. No out-of-band context channel (context goes in the prompt), no ",[301,567,568],{},"effort"," (a model id can carry one, such as ",[301,571,572],{},"'name[effort=high]'","), and no ",[301,575,504],{},[301,577,508],{},[301,579,512],{}," or ",[301,582,583],{},"rate_limit_signal",". ",[301,586,516],{},[301,588,519],{},[301,590,591],{},"preToolUse"," hook Kraft installs in the worktree, answered by the ",[291,594,532],{"href":595},"\u002Freference\u002Fpermissions#cursor",". Tokens and the chat id ",[301,598,599],{},"resume"," takes are read off its ",[301,602,603],{},"stream-json"," log; it reports no cost and names its model \"Auto\", so ",[291,606,541],{"href":540}," only on a launch model ",[301,609,610],{},"prices.json"," lists, and otherwise count it as $0 and warn. An API-key install needs ",[301,613,614],{},"env_passthrough: [CURSOR_API_KEY]"," on the repo.",[459,617,618,623,628],{},[477,619,620],{},[301,621,622],{},"opencode",[477,624,625],{},[301,626,627],{},"opencode run",[477,629,630,631,634,635,505,637,580,639,584,641,437,643,645,646,649,650,653,654,657,658,661,662,664,665,668,669,672,673,676,677,680,681,684,685,688],{},"Needs OpenCode 2.0.0 or newer (not npm's 1.x ",[301,632,633],{},"opencode-ai","); an older one is refused at launch. No out-of-band context channel (context goes in the prompt), no ",[301,636,504],{},[301,638,508],{},[301,640,512],{},[301,642,516],{},[301,644,519],{}," are written into the launch's own OpenCode config, with ",[301,647,648],{},"--standalone",", when the task's policy sets either (",[291,651,532],{"href":652},"\u002Freference\u002Fpermissions#opencode-and-amp-rules-written-at-launch","). ",[301,655,656],{},"model"," is ",[301,659,660],{},"provider\u002Fmodel"," for any provider OpenCode knows. There is no ",[301,663,568],{},": name a variant in the model id (",[301,666,667],{},"openai\u002Fgpt-5.5#high","). Every launch passes ",[301,670,671],{},"--auto",", since ",[301,674,675],{},"run"," otherwise rejects every permission request. Tokens, cost, the session id and a rate-limit stop are read off its ",[301,678,679],{},"--format json"," log. That log leaves out the last step's usage, so Kraft reads the session's totals from ",[301,682,683],{},"opencode session export \u003Csession id>"," when the run ends, and falls back to the log's steps if that fails. A ",[301,686,687],{},"task"," sub-agent's tokens are not in the log.",[459,690,691,696,700],{},[477,692,693],{},[301,694,695],{},"gemini",[477,697,698],{},[301,699,695],{},[477,701,702,703,705,706,708,709,712,713,716],{},"No out-of-band context channel (context goes in-band via the prompt), no ",[301,704,568],{},", no ",[301,707,599],{}," at all (Gemini's ",[301,710,711],{},"--resume"," takes an index or ",[301,714,715],{},"\"latest\"",", not a session id, so the capability isn't declared).",[459,718,719,724,729],{},[477,720,721],{},[301,722,723],{},"amp",[477,725,726],{},[301,727,728],{},"amp -x",[477,730,501,731,733,734,736,737,740,741,744,745,505,747,505,749,580,751,584,753,437,755,757,758,761,762,764,765,600,767,770,771,773,774,776,777,780],{},[301,732,656],{},": Amp picks it. ",[301,735,568],{}," is Amp's mode (",[301,738,739],{},"-m low|medium|high|ultra","). Context goes in-band via the prompt. No ",[301,742,743],{},"permission_mode"," (Amp asks for no approvals), no ",[301,746,504],{},[301,748,508],{},[301,750,512],{},[301,752,583],{},[301,754,516],{},[301,756,519],{}," go into a settings file of the launch's own (",[301,759,760],{},"--settings-file",") when the task's policy sets either (",[291,763,532],{"href":652},"). Tokens and the thread id ",[301,766,599],{},[301,768,769],{},"--stream-json"," log; it reports no cost, so ",[291,772,541],{"href":540}," on the model its log names when ",[301,775,610],{}," lists it. Both command lines pass ",[301,778,779],{},"--no-archive-after-execute",", because an archived thread can't be resumed.",[280,782,784],{"id":783},"capabilities-not-flags","Capabilities, not flags",[276,786,787,788,791,792,505,795,505,798,505,800,505,802,804,805,505,807,505,809,505,811,505,813,804,815,505,817,505,820,505,823,505,825,505,828,831,832,657,834,837,838,841,842,845,846,849],{},"A task's YAML never names a harness's actual CLI flags. It asks for a\n",[319,789,790],{},"capability"," — ",[301,793,794],{},"prompt",[301,796,797],{},"context",[301,799,656],{},[301,801,568],{},[301,803,743],{},",\n",[301,806,516],{},[301,808,519],{},[301,810,504],{},[301,812,508],{},[301,814,599],{},[301,816,512],{},[301,818,819],{},"structured_log",[301,821,822],{},"usage",[301,824,583],{},[301,826,827],{},"writable_dirs",[301,829,830],{},"mcp_config"," — and each harness's own YAML\n(a YAML file per harness) maps that capability onto\nwhatever its CLI actually calls it. ",[301,833,743],{},[301,835,836],{},"--permission-mode acceptEdits|auto|..."," for Claude, ",[301,839,840],{},"-c sandbox_mode=read-only|workspace-write|...","\nfor Codex, ",[301,843,844],{},"--approval-mode default|yolo|..."," for Gemini, ",[301,847,848],{},"--auto-review|--force","\nfor Cursor — one Kraft-side name, four different flags.",[276,851,852,853,855,856,859,860,863,864,804,867,870,871,873,874,580,877,880,881,884,885,889,890,892,893,896],{},"Codex's options are all ",[301,854,527],{}," config keys. Codex\nruns in its \"approve for me\" mode by default, Claude's ",[301,857,858],{},"auto"," counterpart: the\nsandbox is ",[301,861,862],{},"workspace-write",", and a sandbox escalation the model asks for goes\nto Codex's automatic reviewer (",[301,865,866],{},"approval_policy=on-request",[301,868,869],{},"approvals_reviewer=auto_review","), not to a human. A ",[301,872,743],{}," of\n",[301,875,876],{},"read-only",[301,878,879],{},"danger-full-access"," (a harness profile's ",[301,882,883],{},"defaults:"," or a task)\nchanges the sandbox. The reviewer stays on in every mode. Under Kraft's\n",[291,886,888],{"href":887},"\u002Freference\u002Fconfiguration\u002Frepos#sandboxed-workers","docker sandbox"," the default\nbecomes ",[301,891,879],{}," (",[301,894,895],{},"container_permission_mode","): Codex's own\nsandbox cannot start inside a container, and the container is the boundary.",[276,898,899,900,505,902,505,904,906,907,804,909,911],{},"Three capabilities are required — ",[301,901,794],{},[301,903,797],{},[301,905,822],{}," — since no\nagent dispatch can be built without them. Two are non-invocable —",[301,908,822],{},[301,910,583],{}," — they describe what Kraft reads back out of a session\n(from its structured log or a result file), not an argv it constructs.",[276,913,914,915,917],{},"One is filled by Kraft, never by a task: ",[301,916,827],{},", the directories\noutside the worktree that a worker must write. There are two:",[285,919,920,931],{},[288,921,922,923,926,927,930],{},"the directory holding the launch's ",[301,924,925],{},"$KRAFT_RESULT_PATH","\n(",[301,928,929],{},"$KRAFT_HOME\u002Frun\u002Fresults",");",[288,932,933,934,937,938,941],{},"the worktree's git common dir, where every commit writes. For a linked\nworktree that's the main checkout's ",[301,935,936],{},".git",". Kraft asks git for it\n(",[301,939,940],{},"git rev-parse --git-common-dir",") and leaves it out when git has none.",[276,943,944,947,948,951,952,955,956,958,959,962,963,966,967,969],{},[301,945,946],{},"{value}"," is one JSON array of absolute paths, such as\n",[301,949,950],{},"[\"\u002Fhome\u002Fme\u002F.kraft\u002Frun\u002Fresults\",\"\u002Fhome\u002Fme\u002Fsrc\u002Fapp\u002F.git\"]",". It's for a CLI whose\nown sandbox would refuse to write outside the worktree. Codex binds it to\n",[301,953,954],{},"-c sandbox_workspace_write.writable_roots={value}"," (TOML reads the JSON array\nas an inline array). Its ",[301,957,862],{}," sandbox writes only the workspace\nand ",[301,960,961],{},"\u002Ftmp",", so without the grant a codex worker on a default install\n(",[301,964,965],{},"~\u002F.kraft",") can write neither its result file nor a commit. Kraft grants both\ndirectories outright, because Codex's automatic reviewer is not relied on for\neither one. A harness\nthat doesn't declare ",[301,968,827],{}," gets nothing extra.",[276,971,972,973,976,977,980,981,983,984,987,988,991,992,994],{},"Another is filled by Kraft only for a ",[291,974,975],{"href":887},"sandboxed","\nlaunch with ",[301,978,979],{},"network:",": ",[301,982,830],{},", the CLI's MCP servers as one JSON object,\n",[301,985,986],{},"{\"mcpServers\": {\"kraft\": {\"type\": \"http\", \"url\": \"http:\u002F\u002Fkraft\u002Fmcp\"}}}",": Kraft's\nown server for that session, reached through the sandbox's route out, since the\nMCP server registered on your machine is out of the container's reach. Claude\nbinds it to ",[301,989,990],{},"--strict-mcp-config --mcp-config {value}",", so that server is its\nonly one and its ",[301,993,508],{}," tool is answered there.",[276,996,997,998,1001,1002,657,1004,1007,1008,1011,1012,1015,1016,1018,1019,1022],{},"Some harnesses declare ",[301,999,1000],{},"values:"," on a capability — a closed vocabulary the\nCLI itself would reject (Codex's ",[301,1003,568],{},[301,1005,1006],{},"minimal, low, medium, high, xhigh",",\nClaude's is ",[301,1009,1010],{},"low, medium, high, xhigh, max",") — checked at load time, and\n",[301,1013,1014],{},"always:"," — the value Kraft uses when nothing else is supplied (Gemini's\n",[301,1017,743],{}," defaults to ",[301,1020,1021],{},"yolo",", since a headless worker has nobody to\nanswer an approval prompt).",[1024,1025,1026],"h3",{"id":723},"Amp",[276,1028,1029,1030,304],{},"Amp needs credentials a headless process can use. See ",[291,1031,1033],{"href":1032},"\u002Fguides\u002Fadding-a-harness#set-up-amp-or-cursor-credentials","Set up Amp and Cursor credentials",[285,1035,1036,1042,1049],{},[288,1037,1038,1039,304],{},"Kraft's token counts for an Amp run are the thread's own, message by message.\nThey match ",[301,1040,1041],{},"amp threads export",[288,1043,1044,1045,1048],{},"Amp's bill (",[301,1046,1047],{},"amp threads usage",") can count a few requests that aren't in the\nthread, and it's the only place Amp reports cost, so Kraft records none.",[288,1050,1051,1052,1054,1055,1057,1058,1061],{},"An agent profile can't select ",[301,1053,723],{},": a profile needs a model for the\nprovider, and Amp takes none. A task on ",[301,1056,723],{}," sets ",[301,1059,1060],{},"effort:"," itself.",[1024,1063,1064],{"id":549},"Cursor",[285,1066,1067,1079,1108,1124,1141],{},[288,1068,1069,1072,1073,1075,1076,1078],{},[319,1070,1071],{},"Mode."," Kraft runs ",[301,1074,325],{}," in ",[301,1077,560],{},", Cursor's Smart Auto: a\nserver-side classifier runs the tool calls it judges safe and refuses the\nrest. Without a mode, print mode only proposes edits and applies none.",[288,1080,1081,1084,1085,1088,1089,1092,1093,1096,1097,1100,1101,1104,1105,1107],{},[319,1082,1083],{},"Config directory."," Every launch sets ",[301,1086,1087],{},"CURSOR_CONFIG_DIR"," to\n",[301,1090,1091],{},"$KRAFT_HOME\u002Frun\u002Fharness-config\u002Fcursor\u002F",", a directory Kraft owns. Your own\n",[301,1094,1095],{},"~\u002F.cursor"," is never read or changed. Before each launch Kraft writes\n",[301,1098,1099],{},"cli-config.json"," there with commit attribution off, because with it on\nCursor adds a ",[301,1102,1103],{},"Co-authored-by: Cursor"," trailer to every commit and the\nclassifier refused those commits. The file adds no permission rule. The\ndirectory is shared by all launches, not one per launch, because ",[301,1106,711],{},"\nhas to find the chat an earlier launch wrote. A sandboxed item gets one of\nits own, inside its sandbox home.",[288,1109,1110,1113,1114,437,1116,1118,1119,1121,1122,304],{},[319,1111,1112],{},"Tool policy."," ",[301,1115,516],{},[301,1117,519],{}," go through a ",[301,1120,591],{}," hook. See ",[291,1123,1064],{"href":595},[288,1125,1126,1129,1130,1133,1134,1137,1138,1140],{},[319,1127,1128],{},"Login."," The login lives in the OS keychain, not the config dir. With an\nAPI key instead, name ",[301,1131,1132],{},"CURSOR_API_KEY"," in the repo's ",[301,1135,1136],{},"env_passthrough",": the\nonly way a ",[291,1139,975],{"href":887},"\nworker, which has no keychain, logs in.",[288,1142,1143,1146,1147,1150],{},[319,1144,1145],{},"Usage."," Tokens come off the log's closing ",[301,1148,1149],{},"result"," line, one per run:\nuncached input, output, and cache reads and writes. Cursor reports no cost,\nso Kraft records none, only an estimate when it can price the launch model.",[1152,1153,1154],"style",{},"html pre.shiki code .swJcz, html code.shiki .swJcz{--shiki-light:#E53935;--shiki-default:#F07178;--shiki-dark:#F07178}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":357,"searchDepth":1156,"depth":1156,"links":1157},2,[1158,1159],{"id":282,"depth":1156,"text":283},{"id":783,"depth":1156,"text":784,"children":1160},[1161,1163],{"id":723,"depth":1162,"text":1026},3,{"id":549,"depth":1162,"text":1064},"Which agent CLIs Kraft runs, what each supports, and how a task picks one.","md",null,{},{"title":10},{"title":206,"description":1164},"oTrLkgwNi5cGD_0sc4BBCvJB45i685IUpFR5saHGFes",[1172,1174],{"title":202,"path":203,"stem":204,"description":1173,"children":-1},"What Kraft's permission gate does per harness, how it decides, and the keys that configure it.",{"title":212,"path":213,"stem":214,"description":1175,"children":-1},"The permission mode each harness runs in when no one can answer a prompt.",1790824539986]