The session has left the window.
VS Code 1.140 introduces a Copilot harness that runs in a dedicated agent-host process. Microsoft says more than one VS Code window can connect to the same session through the Agent Host Protocol, or AHP.[1]
That changes a useful mental model. Closing one view is not the same as ending the host. Opening another view is not a new session. The client, session, host process, and repository checkout are now separate objects.
The chat window is a gauge. The host process is the engine.
AHP moves state, not permission.
AHP describes a portable session server with multiple synchronized clients. Its repository names immutable state, pure reducers, and write-ahead reconciliation. Those mechanisms explain how clients converge on one session view.[2]
They do not establish what the hosted agent may do. A protocol that keeps two windows in sync does not select a writable folder, narrow network access, or approve a shell command. Those controls belong to the host and its environment.
The harness has another wire below it.
The GitHub Copilot SDK exposes the same agent runtime used by Copilot CLI. Its SDK clients talk to a Copilot CLI server over JSON-RPC. The SDK can manage that process or connect to an external server.[3]
The SDK documentation also says first-party tools are exposed by default in a mode similar to --allow-all, while each application supplies a permission handler. That makes the application boundary part of the security design. Reusing an engine does not guarantee that two clients enforce the same tool policy.
Keep the coupling visible.
Before reconnecting a session from another window or app, record four things. Pin the session address, identify the host process, name the workspace, and inspect the effective tool policy. Save execution output against the exact revision after the action runs.
The coupler below builds that connection card. It does not inspect a running host or grant access.