Envd
The native daemon that exposes files, commands, processes, and ports over the Environment Interaction Protocol.
Envd (a13n-envd) serves the Environment Interaction Protocol (EIP) over stdio, HTTP(S), or an outbound reverse WebSocket connection.
Connect Agents through Harness Environment Providers, or use the Python EIP client directly.
Choose your path
| Situation | Start here |
|---|---|
| Using Harness UI | Harness UI execution permissions |
| Trying a local EIP Environment without a model | Local Envd example |
| Installing a matching native executable | Installation |
| Running an agent development container | Sandbox image |
| Operating your own daemon or EIP transport | Configuration and transports |
| Diagnosing access or missing methods | Execution boundaries and troubleshooting |
| Connecting through an Environment Provider | Remote Envd |
| Implementing an EIP client or Provider | Python EIP client |
| Managing Sessions, retained output, and uncertain results | Sessions and output |
What it provides
- Read, write, search, and transfer files.
- Run commands, send input, read output, and stop processes.
- Inspect ports and wait for them to open.
- Optionally observe and control a shared desktop (computer use).
- Check operation results, cancel work, and inspect failures.
- Discover available operations for each platform and configuration.
One daemon serves a Device and multiple independent Sessions. Each Session owns its operations, processes, retained output, transfers and evidence. Working directory is a default, not an access boundary. Mutually untrusted workloads need separate Host-enforced outer boundaries; EIP Sessions do not isolate workloads from each other.
Try Local Envd
The repository's Environment Provider example exercises file operations through a private Envd Device without a model, cloud account, or server. From the repository root:
cargo build --locked --package a13n-envd
cd examples/environment-provider
uv sync --locked
uv run environment-provider-example local_envd \
--executable ../../target/debug/a13n-envdThe example creates its own working directory, starts a private daemon over stdio, creates one Session for its adapter, and verifies that closing the adapter preserves that directory. The example's LocalEnvdProviderRuntime then closes the daemon. For Agent integration, supply a fresh Local Envd adapter to Harness with DynamicEnvironmentCapability; Harness integration shows that boundary. A Host can reuse its LocalEnvdProviderRuntime across adapters, but each adapter opens an independent Session.
Configure LocalEnvdLaunchConfiguration on that runtime when you need execution identity, Sandbox grants, egress mode, executable roots, shell profiles, or limits. Envd manages Session workers; the Host owns outer container or VM isolation. See execution boundaries and Session credential references.
Lifecycle and ownership
Device discovery opens no Session. Session preparation checks fixed cwd, required methods and readiness. Cancellation or failure of one adapter cannot close a healthy shared Device. See daemon lifecycle.
Reference topics
| Topic | Guide |
|---|---|
| Build the matching binary | Build the matching binary |
| Install a published binary | Install a published binary |
| Isolation behavior | Isolation behavior |
| Minimal standalone configuration | Minimal standalone configuration |
| Enable commands | Enable commands |
| Carrier profiles | Carrier profiles |
| Validate from this repository | Validate from this repository |
| Troubleshooting | Troubleshooting |
| References | References |