Skip to content

Public and private access

Every harness starts private. You flip it to public when the harness’s own login is ready to take over. The toggle lives on the harness detail page in the console, under Access.

While private, only you can reach https://<name>.harnesser.co, and only while signed in to the console. Anyone else who opens the URL is sent to the console login instead. This is the safety net for harnesses that have not set up their own sign-in yet.

Private mode is per-owner, not per-team: your teammates cannot reach a private harness even if they have their own console accounts. Sharing a harness with a team means making it public and letting the harness’s own accounts do the gating.

When you switch a harness to public, anyone with the link reaches the harness directly, and the harness’s own sign-in and user management become the only gate. The switch takes effect immediately and you can flip it back at any time; making a harness private again does not touch any state inside it.

Paperclip. Claim the board first with the one-time claim link (see Paperclip). Once claimed, Paperclip requires sign-in, so a public Paperclip is safe: visitors see a login, and you control accounts from the board.

QM. QM always requires sign-in through its portal, and sign-in works by one-time email links to allowed addresses only. A public QM is safe by default. Sign-in starts restricted to the harness creator’s email; contact the operator to allow teammate addresses.

Hermes. Hermes starts with no login at all, so the console refuses to make a Hermes harness public until you set a password inside Hermes under Settings, then Authentication. Set the password, then flip the toggle.

  1. Create the harness and complete its first sign-in flow while it is still private.
  2. Set up accounts: claim the Paperclip board, grant QM emails, or set the Hermes password.
  3. Flip the harness to public and share https://<name>.harnesser.co with your team.