Skip to content
UHPUHPDeveloper Guide
Independent resource · Not affiliated with HarnessRouter · Site data checked 13 Sep 2026

Architecture

Unified Harness Protocol architecture

The core UHP boundary is simple: a client speaks UHP to a server; the server drives one or more complete harnesses behind that interface. UHP 2026-09-12 adds optional Agent Plugins packages inside configured harnesses.

Verified: Protocol: 2026-09-12Static SSG
┌──────────┐ UHP / HTTP ┌──────────┐ internal mechanism ┌──────────┐
│ Client │ ───────────────▶ │ Server │ ────────────────────▶ │ Harness │
└──────────┘ └──────────┘ └──────────┘

Client: the product backend, CLI, CI job or another agent that requests work. A conforming client should not need to know how the server launches a harness.

Server: the protocol implementation. It accepts tasks, drives harnesses and translates execution into UHP objects, events and errors.

Harness: the full runtime with its own agent loop, tools and session state. UHP identifies harness families by stable bases such as codex, claude-code and hermes. A harness still calls a model provider underneath UHP; for how the UHP contract relates to a direct model API such as the OpenAI Responses API, see UHP vs model APIs.

UHP treats configuration as a first-class object rather than assuming that a base name fully defines behavior. A configured harness can combine a base with a default model, instructions, tool restrictions, skills, MCP servers, execution budgets and, in UHP 2026-09-12, optional Harness Plugins.

A Harness Plugin is an Agent Plugins 1.0.0 package bound to that configured harness. The package can contribute skills and MCP servers without rewriting the harness’s direct skills or mcpServers fields. See Harness Plugins for the derivation, composition, stdio-MCP and export rules.

The server assigns each configured harness an id that clients use when submitting work.

ObjectPurposeTypical lifetime
HarnessSaved configured runtime, including optional plugin bindingsUntil deleted
ResponseOne atomic task and its resultServer retention policy
SessionChain of responses sharing context and workspaceUntil deleted/expired
ContainerFile namespace for a sessionWith session
FileInput or artifact in a containerWith container
EventProgress fact in the event streamStreamed and replayable

Plugin packages are configuration attached to a harness rather than a replacement for these task/session objects. The server derives plugin manifest/MCP/skill state from the package and combines enabled plugin components with direct harness components at execution time.

A first task can create a session automatically. Continuation uses the prior response relationship rather than requiring every client to create a session object before doing any work. A session preserves conversational context, working-directory state and the selected configured harness across tasks.

The specification requires a mismatch to fail rather than silently switching to a different configured harness inside the same conversation chain.

UHP uses HTTP/1.1 or later. TLS is required outside loopback development. Normal request and response bodies use JSON; file upload uses multipart form data; downloads use the file media type. Streaming uses Server-Sent Events (SSE).

This choice keeps the client-facing contract web-native while leaving the server free to run local CLIs, containers or remote execution internally.

ClassRequired surface
CoreDiscovery, harness discovery, task execution, streaming, continuation, cancellation and errors.
ExtendedCore plus file input, artifacts and session listing/inspection.
FullExtended plus harness create/update/delete, session sharing and capability-gated Harness Plugins checks when the server advertises that optional surface.

Clients are expected to discover capabilities rather than assume everything above Core exists. A 2026-09-12 server can remain conformant while reporting plugins: false; the plugin-specific P-series checks then skip rather than pass.

Clients authenticate with bearer tokens. UHP requires every object to be scoped to the principal that created it. Cross-principal attempts to read or manipulate another party’s objects should return 404 rather than disclose whether an id exists.

Plugins add another execution boundary: packaged stdio MCP processes execute inside the agent sandbox, and exported packages omit credentials while recording those omissions. See security and Harness Plugins.