How to Connect Action Gateway to Harness Runtimepublic
Last verified 1 Oct 2026
DigitalOcean Harness Runtime provides managed, hardware-isolated microVM sandboxes with built-in tools such as Chromium to run harnesses and execute arbitrary code. Rich lifecycle APIs preserve conversational history and working state across sessions, letting you pause, resume, and fork work to control costs and adapt to the nonlinear nature of agentic workflows. Scale complete agents such as Claude Code or use sandboxes independently for code execution, all through the same service. See What You Can Build for example use cases.
Harness Runtime connects an agent to Action Gateway through its YAML environment spec. Give the agent access to the full catalog or select specific tools, preload the tools it needs immediately, and set permissions for their execution.
For an agent running outside Harness Runtime, use the standalone Action Gateway quickstart instead.
Prerequisites
- A working environment spec from the Harness Runtime Quickstart.
- Access to Action Gateway.
- Funds in at least one balance for Harness Runtime. Some Action Gateway tools, including Exa web search and web fetch, also require prepayment, but not every tool does.
- Provider authorization for any tools you plan to use that require a connection.
Choose Action Gateway Tools
Choose full-catalog access or a specific selection. Use only one do.actions entry in your environment spec; the following configurations are alternatives.
Use the Full Action Gateway Catalog
For general-purpose agents whose tasks may need tools from different providers, add do.actions without a tool list to the tools block in your existing environment spec:
tools:
- do.actionsThe agent can discover and invoke any tool in the Action Gateway catalog without you listing each one in advance. Action Gateway exposes its three meta tools, action_search, action_invoke, and action_code, rather than loading every tool definition into the model’s context. The full catalog is available, but it is not preloaded.
Full-catalog access does not bypass permissions or authorize provider accounts. Keep your permissions policy in place and authorize the providers whose tools the agent needs. For an agent with a defined workflow, use a specific selection to limit its available tools.
Select and Preload Specific Tools
To limit access, configure the do.actions entry with the tools the workload needs. The fields serve different purposes:
toolsrestricts which Action Gateway tools the session can access, including through search, invocation, and code execution.preload_toolsexposes selected tools directly to the model with their input schemas, so the agent can call them without first searching.permissionscontrols whether a tool runs without approval, requires approval, or is denied. Selecting or preloading a tool does not grant permission to run it.
For guidance on when to preload tools instead of searching, see Preloading Tools in Action Gateway.
The following Claude Code example selects web research and Jira tools, but preloads only exa_web_search and exa_web_fetch. It allows web research and Jira reads without approval and requires approval for Jira changes. Keep any other settings your existing environment needs, such as credentials and workspace configuration:
name: research-jira-agent
description: Web research and Jira with web research tools preloaded
agent: claude-code
tools:
- do.actions:
tools:
- exa_web_search
- exa_web_fetch
- jira_list_issues
- jira_get_issue
- jira_create_issue
- jira_update_issue
- jira_add_comment
- jira_transition_issue
preload_tools:
- exa_web_search
- exa_web_fetch
permissions:
default: ask
rules:
- tool: do.actions/exa_web_search
action: allow
- tool: do.actions/exa_web_fetch
action: allow
- tool: do.actions/jira_list_issues
action: allow
- tool: do.actions/jira_get_issue
action: allow
- tool: do.actions/jira_create_issue
action: ask
- tool: do.actions/jira_update_issue
action: ask
- tool: do.actions/jira_add_comment
action: ask
- tool: do.actions/jira_transition_issue
action: askAction Gateway still exposes its three meta tools: action_search, action_invoke, and action_code. The preloaded web tools appear alongside them. The agent can discover and invoke the selected Jira tools through the meta tools without loading every Jira tool definition into its initial context.
Keep the preload list short to limit the tool definitions in the model’s context. Each entry must be an individual tool in the tools selection. Harness Runtime YAML does not accept Toolbelt references in preload_tools.
If you do not need preloading, the shorthand do.actions: [exa_web_search, exa_web_fetch] still selects tools without exposing them directly. To select a Toolbelt, reference its name and version. Replace <toolbelt-name> and <version> with the Toolbelt’s published reference:
tools:
- do.actions: ["toolbelt:<toolbelt-name>@<version>"]Configure Tool Permissions
Use do.actions/<tool-name> to target an Action Gateway tool in permissions.rules. In the example, allow permits web research and Jira reads, while ask requires approval before creating, updating, commenting on, or transitioning an issue. Use deny to block execution of a matching tool. These rules apply whether the agent calls a tool directly or through a meta tool.
The claude-code and codex adapters support Action Gateway approval prompts. Approval handling differs for other adapters, so verify the behavior of any ask rules with the adapter you deploy. See Permission Policies and Configure Agent Permissions.
A directly configured, non-gateway MCP server is a different integration. Its inline host must be covered by the agent’s egress configuration. Action Gateway catalog tools use platform-managed networking.
Start and Verify the Agent
Save the environment spec, then start the session. Replace <your-environment-spec>.yaml with its filename. launch creates the sandbox, starts the agent, and attaches your terminal:
doctl harness-runtime launch <your-environment-spec>.yamlAsk the agent to perform a read-only task with a tool whose provider you have authorized. Confirm that it discovers and invokes the tool under the intended permission policy and uses the intended actor’s connection.
For the web research and Jira example, ask the agent to search the web and list Jira issues without making changes. Confirm that it can call the preloaded web tools directly and discover the selected Jira tools. Before relying on approval rules, test a Jira change against a test issue and reject the approval request to confirm that the change does not run.
To select tools when creating an environment through the Control Panel, use the creation flow described in Create an Environment Using a Coding Adapter.