How to Connect Action Gateway to Harness Runtimepublic

Last verified 1 Oct 2026

DigitalOcean Harness Runtime provides managed, hardware-isolated microVM sandboxes with built-in tools such as Chromium to run harnesses and execute arbitrary code. Rich lifecycle APIs preserve conversational history and working state across sessions, letting you pause, resume, and fork work to control costs and adapt to the nonlinear nature of agentic workflows. Scale complete agents such as Claude Code or use sandboxes independently for code execution, all through the same service. See What You Can Build for example use cases.

Harness Runtime connects an agent to Action Gateway through its YAML environment spec. Give the agent access to the full catalog or select specific tools, preload the tools it needs immediately, and set permissions for their execution.

For an agent running outside Harness Runtime, use the standalone Action Gateway quickstart instead.

Prerequisites

Choose Action Gateway Tools

Choose full-catalog access or a specific selection. Use only one do.actions entry in your environment spec; the following configurations are alternatives.

Use the Full Action Gateway Catalog

For general-purpose agents whose tasks may need tools from different providers, add do.actions without a tool list to the tools block in your existing environment spec:

tools:
  - do.actions

The agent can discover and invoke any tool in the Action Gateway catalog without you listing each one in advance. Action Gateway exposes its three meta tools, action_search, action_invoke, and action_code, rather than loading every tool definition into the model’s context. The full catalog is available, but it is not preloaded.

Full-catalog access does not bypass permissions or authorize provider accounts. Keep your permissions policy in place and authorize the providers whose tools the agent needs. For an agent with a defined workflow, use a specific selection to limit its available tools.

Select and Preload Specific Tools

To limit access, configure the do.actions entry with the tools the workload needs. The fields serve different purposes:

  • tools restricts which Action Gateway tools the session can access, including through search, invocation, and code execution.
  • preload_tools exposes selected tools directly to the model with their input schemas, so the agent can call them without first searching.
  • permissions controls whether a tool runs without approval, requires approval, or is denied. Selecting or preloading a tool does not grant permission to run it.

For guidance on when to preload tools instead of searching, see Preloading Tools in Action Gateway.

The following Claude Code example selects web research and Jira tools, but preloads only exa_web_search and exa_web_fetch. It allows web research and Jira reads without approval and requires approval for Jira changes. Keep any other settings your existing environment needs, such as credentials and workspace configuration:

name: research-jira-agent
description: Web research and Jira with web research tools preloaded
agent: claude-code

tools:
  - do.actions:
      tools:
        - exa_web_search
        - exa_web_fetch
        - jira_list_issues
        - jira_get_issue
        - jira_create_issue
        - jira_update_issue
        - jira_add_comment
        - jira_transition_issue
      preload_tools:
        - exa_web_search
        - exa_web_fetch

permissions:
  default: ask
  rules:
    - tool: do.actions/exa_web_search
      action: allow
    - tool: do.actions/exa_web_fetch
      action: allow
    - tool: do.actions/jira_list_issues
      action: allow
    - tool: do.actions/jira_get_issue
      action: allow
    - tool: do.actions/jira_create_issue
      action: ask
    - tool: do.actions/jira_update_issue
      action: ask
    - tool: do.actions/jira_add_comment
      action: ask
    - tool: do.actions/jira_transition_issue
      action: ask

Action Gateway still exposes its three meta tools: action_search, action_invoke, and action_code. The preloaded web tools appear alongside them. The agent can discover and invoke the selected Jira tools through the meta tools without loading every Jira tool definition into its initial context.

Keep the preload list short to limit the tool definitions in the model’s context. Each entry must be an individual tool in the tools selection. Harness Runtime YAML does not accept Toolbelt references in preload_tools.

If you do not need preloading, the shorthand do.actions: [exa_web_search, exa_web_fetch] still selects tools without exposing them directly. To select a Toolbelt, reference its name and version. Replace <toolbelt-name> and <version> with the Toolbelt’s published reference:

tools:
  - do.actions: ["toolbelt:<toolbelt-name>@<version>"]

Configure Tool Permissions

Use do.actions/<tool-name> to target an Action Gateway tool in permissions.rules. In the example, allow permits web research and Jira reads, while ask requires approval before creating, updating, commenting on, or transitioning an issue. Use deny to block execution of a matching tool. These rules apply whether the agent calls a tool directly or through a meta tool.

The claude-code and codex adapters support Action Gateway approval prompts. Approval handling differs for other adapters, so verify the behavior of any ask rules with the adapter you deploy. See Permission Policies and Configure Agent Permissions.

A directly configured, non-gateway MCP server is a different integration. Its inline host must be covered by the agent’s egress configuration. Action Gateway catalog tools use platform-managed networking.

Start and Verify the Agent

Save the environment spec, then start the session. Replace <your-environment-spec>.yaml with its filename. launch creates the sandbox, starts the agent, and attaches your terminal:

doctl harness-runtime launch <your-environment-spec>.yaml

Ask the agent to perform a read-only task with a tool whose provider you have authorized. Confirm that it discovers and invokes the tool under the intended permission policy and uses the intended actor’s connection.

For the web research and Jira example, ask the agent to search the web and list Jira issues without making changes. Confirm that it can call the preloaded web tools directly and discover the selected Jira tools. Before relying on approval rules, test a Jira change against a test issue and reject the approval request to confirm that the change does not run.

To select tools when creating an environment through the Control Panel, use the creation flow described in Create an Environment Using a Coding Adapter.

We can't find any results for your search.

Try using different keywords or simplifying your search terms.