MASAKA / Get started / Architecture
Architecture

One task,
three planes.

The control plane owns authority and durable state; regional workers own browser execution; the Agent Harness owns the model loop.

System planes

HarnessReason and verifyModel, tools, task state, handoff
→
Control planeAuthorize and accountProjects, queue, control, usage
→
Data planeRun the browserWPE, preview, input, downloads
MASAKA architecture with control, preview, and billing paths.AGENT HARNESSCodex / OpenRouterbounded toolsCONTROL PLANEAPI · projects · queuecapability epochsusage · audit · billingBROWSER WORKERreal tabs · framesinput · filespreview

Authority is explicit

A project owns its sessions and resources. A session has a monotonically increasing control epoch. Agent and human control transfers first fence older input, then issue a new capability. Direct preview tickets are short-lived and cannot silently inherit input authority.

What crosses each boundary

BoundaryAllowedNot exposed
Client → APIProject-scoped JSON operationsWorker credentials, encryption keys
Client → workerTicketed preview and capability-bound inputGeneral CDP, host ports
Worker → storageStatus, receipts, bounded artifacts, usagePlaintext secrets or profile archives

Failure and settlement

Browser mutations are queued once and return a receipt. If a caller times out, the receipt—not a replay—resolves the outcome. Session settlement uses readiness and heartbeats so failed startup costs nothing and unused reservation returns to the wallet.