Skip to main content
This section covers Harness Runtime deployed with AgentKit CLI agentkit harness deploy, including invocation, sessions, artifacts, memory, and optional scheduled tasks The deployment baseline is AgentKit CLI 0.54.0. Default KeyAuth deployments pin VeADK 1.0.8 and AgentKit SDK 0.8.0; inherited endpoints were verified with Google ADK 2.2.0. The CLI does not pin an exact ADK version; query GET /version for the installed version. Shared OAuth deployments use SDK 0.8.2 and have the authentication and override restrictions described below

Choose an invocation endpoint

Sessions use the application name harness_agent. The deployed Harness name identifies the Runtime and is not a replacement for the application name in session paths. Query GET /list-apps to confirm the loaded application /get_agent_config is not an endpoint of the CLI deployment. harness_merge, harness_enhance, harness.mcp, and selected_skills are also not supported request fields for this deployment

Connect to the service

Start the local development server from a configured Harness project. See Harness commands to prepare model credentials, dependencies, and harness.yaml
The local URL is http://localhost:8000. For cloud calls, use the Runtime URL returned by agentkit harness deploy and the authentication required by that deployment The following example targets a KeyAuth deployment with a Runtime API key. Set HARNESS_URL to the Runtime URL and HARNESS_API_KEY to its access credential. This credential is separate from model API keys and MCP service credentials
Omit Authorization for a local server without gateway authentication. Shared OAuth deployments require the configured user-pool JWT and a user ID matching the verified identity. /run and /run_sse without general overrides require an existing session; /invoke checks and creates the session

Request overrides

Only fields explicitly supplied in harness apply to the request. Omitted fields inherit the deployment configuration. Model defaults shown in schema tables do not mean that omission resets the deployed setting MCP servers use the following structure. protocol defaults to streamable-http and also supports sse. endpoint must be an HTTP(S) URL without user information or a fragment; api_key is optional and must not contain line breaks
When using general overrides with /run_sse, use the top-level app_name, user_id, session_id, and new_message fields shown in this section. Other inherited endpoints use the field names displayed on their individual pages; do not rename all fields globally See Scheduled jobs for setup, scheduling behavior, and execution management

Deployment restrictions

Shared OAuth requests return 411 without a valid Content-Length and 413 when the body exceeds the limit. Application requests return 503 until Runtime identity is bound; a successful health probe alone does not mean agent invocation is available

Responses and availability

HTTP 200 from an SSE endpoint means that the response stream has started; the stream may still contain an error event. /harness/invoke can also return an error result with HTTP 200, so inspect its error field Artifact, memory, development evaluation, and debugging endpoints are inherited from the installed SDK/ADK versions. Operations can fail when evaluation dependencies or backend configuration are missing; development endpoints should not be public application entry points. WebSocket /run_live and A2A use separate protocols and are outside this HTTP operation list
Invocations use deployed models, tools, and cloud resources and may incur charges. Sessions, artifacts, memory, and traces may contain user data. The interactive request panel sends real requests; delete and replace operations modify real data. Confirm the address, access rights, and target before sending a request
Last modified on September 19, 2026