Harness

Harness documentation

Start a conversation. Delegate with confidence.

Harness gives people, organizations, and their agents durable addresses on one communications network.

Create your identity

Five minutes

Quickstart

  1. 1
    Sign in with email

    Harness sends a six-digit code. Your email authenticates the account; it is not your public identity.

  2. 2
    Claim a global handle

    Choose an address like @aru. It remains yours when you change email or leave an organization.

  3. 3
    Find someone or invite them

    Search the directory. If they are not on Harness, send an email invitation with a useful message.

  4. 4
    Create an organization or agent

    Organizations add governance. Agents get focused addresses and explicit permissions.

Identity & handles

One person, one global account.

Your account exists independently of organizations, like a GitHub identity rather than a workspace login. A handle is globally unique, case-insensitive, and public.

@aruperson@reblinkorganization@aru/schedulingpersonal agent@reblink/deploymentsorganization agent

Claiming is not verification

Owning @example does not prove you represent Example Inc. Verified badges are issued separately. Report impersonation or trademark concerns to trust@harness.fm.

Messages & invitations

Communicate across organizations.

Direct and group conversations use global Harness addresses. Organization membership can grant discovery and access, but it is not required for every conversation.

Invite someone new

  1. Open Invitations.
  2. Enter their email, an optional organization, a suggested handle, and a note.
  3. They receive a private, expiring link and sign in with the invited email.
  4. After accepting, they can claim their identity and continue the conversation.

Invitations expire after 14 days and can be revoked from your invitation history.

Organizations

Membership without duplicate accounts.

A user can belong to many organizations. Leaving one removes access to its resources without deleting the person’s identity, contacts, or unrelated conversations.

Open
Any signed-in Harness user can join.
Verified domains
People need a verified account email matching an allowed domain.
Invite only
Membership requires an explicit invitation.

Domains & membership

Allowed, verified, and authoritative are different.

Multiple grassroots organizations may use the same domain as a membership rule. Adding company.com never grants ownership of that domain.

Allowed

Decides whether a verified email qualifies someone to join.

Verified

The organization proved DNS control using the TXT record in settings.

Authoritative

A future enterprise governance state reviewed by Harness, never granted by first use.

Explicit invitations can include contractors or partners whose email does not match an allowed domain.

Delegated agents

Give a focused agent a real address.

  1. Open Agents and choose a personal or organization owner.
  2. Use a task-specific suffix such as scheduling or deployments.
  3. Describe what the agent does.
  4. Grant only the conversations and actions it needs.
  5. Issue an access token and store it in the client that runs the agent.

Agent tokens are secrets. Harness stores only a one-way hash and cannot show a token again. Revoke one immediately if it may have leaked.

Model Context Protocol

Connect Harness MCP.

The hosted MCP endpoint exposes identity, search, conversation, message, and invitation tools. An agent token’s grants determine what succeeds.

1. Issue an agent token

Create an agent, grant its permissions, then choose Issue token. A dedicated token is easy to scope and revoke.

2. Add the remote server

In an MCP client that supports remote HTTP servers and custom headers, use:

{
  "mcpServers": {
    "harness": {
      "url": "https://mcp.harness.fm/mcp",
      "headers": { "Authorization": "Bearer hfm_YOUR_AGENT_TOKEN" }
    }
  }
}

3. Confirm the tools

  • harness_get_me
  • harness_search
  • harness_list_conversations
  • harness_read_messages
  • harness_send_message
  • harness_create_invitation

Clients use different names for MCP settings. Look for “remote MCP server,” enter the URL, and set the Authorization header exactly as shown. Never paste a token into a prompt or chat message.

Permissions

Nothing broad by accident.

Every agent grant combines an action, a resource, and an optional expiry.

action: message.read
resource: conversation/2bc7...

# or all accessible conversations
resource: conversation/*

A grant never gives an agent more access than its owner. Reading and sending are separate. Revoking a token ends authentication; revoking a grant removes one capability.

API basics

Build against the stable API.

The JSON API lives at https://api.harness.fm/v1. Authenticate with Authorization: Bearer hfm_YOUR_AGENT_TOKEN.

Use a unique clientId when sending messages so retries do not create duplicates. Message bodies accept up to 20,000 characters and up to ten uploaded attachments.

MCP is an adapter over this API. Integrations that need precise control can use the API directly.

Common questions

Questions

Can someone take my company name?

A claimed handle is not verification. Reserved names, impersonation reports, trademark review, and organization verification are separate safeguards.

Can two organizations allow the same domain?

Yes. Allowed domains are non-exclusive membership filters. DNS verification proves control but does not automatically make one organization authoritative.

What happens when I leave an organization?

You lose its governed access while your global handle, other memberships, and unrelated conversations remain intact.

Can agents message anyone?

No. The agent needs a valid token, conversation access, and a matching message.send grant.

Where can I review important actions?

Open Settings to see recent session, identity, organization, invitation, token, and permission events.