Pimp My IDE / garage dispatch
Back to garage
September 30, 2026 | agent hosts / synchronized state / authority

Shared state is not shared authority.

VS Code 1.140 can connect several windows to one agent session. The new wiring is useful. It also makes the host, workspace, tools, and proof easier to confuse.

A synchronized transcript tells every client what the session knows. It does not tell you which process can act, which files it can reach, or which policy approved the next tool call.

The session has left the window.

VS Code 1.140 introduces a Copilot harness that runs in a dedicated agent-host process. Microsoft says more than one VS Code window can connect to the same session through the Agent Host Protocol, or AHP.[1]

That changes a useful mental model. Closing one view is not the same as ending the host. Opening another view is not a new session. The client, session, host process, and repository checkout are now separate objects.

The chat window is a gauge. The host process is the engine.

AHP moves state, not permission.

AHP describes a portable session server with multiple synchronized clients. Its repository names immutable state, pure reducers, and write-ahead reconciliation. Those mechanisms explain how clients converge on one session view.[2]

They do not establish what the hosted agent may do. A protocol that keeps two windows in sync does not select a writable folder, narrow network access, or approve a shell command. Those controls belong to the host and its environment.

The harness has another wire below it.

The GitHub Copilot SDK exposes the same agent runtime used by Copilot CLI. Its SDK clients talk to a Copilot CLI server over JSON-RPC. The SDK can manage that process or connect to an external server.[3]

The SDK documentation also says first-party tools are exposed by default in a mode similar to --allow-all, while each application supplies a permission handler. That makes the application boundary part of the security design. Reusing an engine does not guarantee that two clients enforce the same tool policy.

Keep the coupling visible.

Before reconnecting a session from another window or app, record four things. Pin the session address, identify the host process, name the workspace, and inspect the effective tool policy. Save execution output against the exact revision after the action runs.

The coupler below builds that connection card. It does not inspect a running host or grant access.

Interactive makeover / agent host coupler

Wire the view to the engine

Traditional purpose replaced: a connection checklist beside a session picker. Better version: one client selector and four native interlocks drive a shared route, gap warning, and copyable connection card.

Choose the client

The selected client changes the handoff note. It does not change authority.

Session viewer
Connection interlocks
4 requirements openVS Code window
State route / authority interlocks

Agent host coupler

The view is selected. The route is not documented.

Record the session address before treating this client as connected to the intended host.

All four interlocks means the card structure is ready. This page does not inspect a host, verify policy, connect a client, run a tool, or approve execution.

One session / four contracts

Do not let synchronized state flatten the system.

01 / CLIENT

View and input

Record the app, version, user identity, session address, and steering controls.

02 / HOST

Process and lifecycle

Record the executable, owner, transport, start path, stop path, and retained state.

03 / WORKSPACE

Files and revision

Record the repository, checkout, writable roots, branch, and exact candidate.

04 / AUTHORITY

Tools and permission

Record the tool set, approval handler, network route, credentials, and fresh output.

Sources read

Source log and evidence boundary
  1. Visual Studio Code 1.140 release notes, released and read September 30, 2026. This first-party page documents the Copilot harness, its dedicated agent-host process, AHP connection, synchronized multi-window sessions, experimental multi-folder sessions, remote delegation, and other release behavior.
  2. Microsoft Agent Host Protocol repository, read September 30, 2026. The repository describes AHP as a synchronized multi-client state protocol. It documents portable session servers, immutable state, reducers, reconciliation, clients, and reference servers.
  3. GitHub Copilot SDK repository, read September 30, 2026. The first-party README documents the SDK-to-CLI JSON-RPC architecture, managed and external server modes, authentication options, default first-party tools, and application permission handlers.

Evidence boundary: this dispatch describes published architecture and release behavior. It does not test VS Code 1.140, AHP interoperability, Copilot permissions, multi-client conflict handling, or host isolation. The connection card is a review template, not runtime telemetry.