Skip to content

Coding Harnesses

Implemented and selectable: the dashboard and delegate_coding_task accept per-run harness and model choices; the approved choice is passed to the runtime. The image installs OpenCode 1.18.31, Claude Code 2.1.277, Codex 0.155.0, and Devin CLI 3000.10.31. Harness tests cover selection, argv/config/env construction, provider allowlists, and event parsing. These tests do not prove the CLIs can complete a task end to end.

Verification status: VERIFICATION.md records one local wrangler dev end-to-end exercise with OpenCode on 2026-09-19. The provider call returned 401, so model inference and successful task completion were not verified. The 2026-09-24 verification says no live cloud end-to-end run has been performed. Claude Code, Codex, and Devin have unit coverage only; no local or cloud harness end-to-end run is recorded for them.

Credential boundary: OpenCode, Claude Code, and Codex use API-key provider traffic through AI Gateway; subscription credentials are not proxied. OpenCode now supports xAI/Grok (xai/<model>) through the same BYOK egress path. Devin uses its own DEVIN_API_KEY service credential.

OpenCode

Default. Multi-provider (google / anthropic / openai / xAI). Use a model such as xai/grok-4; dummy key in the container; Sandbox egress swaps in the AI Gateway BYOK credential.

Read OpenCode Guide →

Claude Code

anthropic/* models, e.g. anthropic/claude-sonnet-4-6. Stream format: --print --output-format stream-json.

Read Claude Code Guide →

Codex

openai/* models, e.g. openai/gpt-5.3-codex. Stream format: codex exec --json.

Read Codex Guide →

Devin CLI

devin/* models (default devin/swe-2); uses Devin’s CLI and service API key.

Read Devin Guide →

Cursor CLI

Not currently an installed or selectable harness. Cursor CLI requires its own Cursor API-key/authentication path, which is not wired into the approved-run credential egress boundary; the Cursor logo on the marketing page is not an integration claim.

Per-run selection overrides the deploy default AGENT_HARNESS. Unsupported harness/model pairs are rejected while preparing the approval, before execution. The Dockerfile’s version checks establish that binaries report versions during image build; they are not an end-to-end test. registry.npmjs.org is not on the egress allowlist, so npm install inside a run is refused.