# K1 chat-thread durable state 0.4.13
`DurableThread` is the synchronous, one-session state owner used by the session actor. It owns durable conversation transitions, bound Ktool authorization, and forwarding to Durable Turn; it owns no provider protocol, pricing, migration, boxes beyond Durable Turn, or asynchronous channel effects.
## Public contract
- `BoxId`, `BoxValue`, `ChatBox`, `PreparedCall`, `PreparedMailboxFlush`, `Status`, and `ToolCallId` retain their Durable Turn or chat-state contracts. `AccessContext`, `AccessPolicy`, and `ProfileId` retain their Chat Thread Ktools contracts. `EventRecord`, `ModelUsage`, and `TokenBreakdown` retain Durable Turn's provider-independent durable-event contracts; `events` clones records in order and `record_model_usage` forwards unchanged.
- `TransitionError` is `Unauthorized`, `NotStalled`, `NotRestartable`, or `Internal(String)`. `recover(session, kmap)` composes neither Social nor SetLaunchNode; `recover_with_social(session, kmap, social)` composes Social only; `recover_with_social_and_set_launch_node(session, kmap, social, set_launch_node)` composes both. All three preserve the existing Durable Turn transition APIs and results.
- `accept_external_box` rejects `USER_MESSAGE_TYPE` with `Unauthorized` and otherwise delegates once to `accept_box`. `complete_with_terminal_response` completes once and returns the canonical terminal Agent Response box ID even when queued active-turn boxes follow it.
- `accept_user` and `restart` bind one exact context/profile/policy triple through `ChatThreadKtools`; the same triple is idempotent and a different triple is unauthorized before partial effects. A failed newly installed acceptance or restart clears authorization. `fail` and explicit `clear_authorization` clear dispatcher authorization while preserving session state.
- `accept_startup_context` is a trusted, first-send-only transition. It requires an empty quiet conversation, binds the exact user authorization triple, and consumes ordered `StartupContextItem` values. `SystemMessage` appends one canonical System Message with empty hidden metadata without scheduling inference. `KmapOpenNode` appends a canonical correlated `KmapOpenNode` Tool Call, executes it through the ordinary bound Kmap dispatcher using the supplied trusted budget, and appends its real Tool Result. A failed load is durably represented and aborts before the later User Message. Startup execution updates the same Kmap session state used by later calls; it is not a fabricated history projection.
- `launch_action` first rejects names absent from the KtoolDocs registry with `unknown Ktool`. It performs KtoolDocs stateless lookup and SendMessage durable append locally, and delegates CurrentTime, five Kmap names, three Social names, and SetLaunchNode to `ChatThreadKtools`. The two older composition modes leave SetLaunchNode unconfigured and preserve `unknown Ktool`; configured SetLaunchNode without active authorization returns exactly `SetLaunchNode authorization is not active`. Missing Social composition returns `social Ktools are unavailable`; other registered asynchronous or unwired names retain their stable no-execution errors, and WebSearch remains session-actor owned.
- `SendMessage` accepts exactly `{"message":"<nonempty string>"}`, durably appends one visible Agent Message, and returns `success`; malformed arguments return `invalid SendMessage arguments` without appending. Provider stages, prepared input, recovery, mailbox flush, event ordering, and all other existing Durable Turn behavior remain unchanged.
For a worst-practical session history, forwarding `events` is linear in the durable record count and clones the returned records; recording model usage performs Durable Turn's synchronous persistence transaction. `accept_external_box` performs one type comparison plus `accept_box`'s synchronous work. `complete_with_terminal_response` performs `complete`'s synchronous work plus one indexed box lookup. Startup work is linear in the number of supplied items plus the ordinary synchronous Kmap-open costs and persistence work.