# K1 daemon library
`kcode-k1-daemon-lib` is the library-only composition root exposing `run(PathBuf) -> ExitCode`. Startup creates the multithreaded runtime, prompts once for the protected Vault passphrase, opens established state beneath `<k1_root>/state`, preserves readiness, slow-start, invite-stock, safe-error, and graceful-shutdown behavior, then binds `127.0.0.1:4450`.
K1Http owns signing, authentication, replay protection, CORS, `nosniff`, body collection, and authenticated `/api` nesting. The daemon opens current Access at `state/access`, concrete Profiles at `state/access-profiles`, and one private Authority Filters facade at `state/authority-filters`.
Chat, Persons, Audio, and Audio Artifacts receive immutable request-local access contexts backed by that shared Filters facade. The daemon selects GPT-5.6 Sol for Chat authorization, Gemini 3.1 Pro for Persons authorization, and GPT-5.6 Terra for Audio authorization. People receives the same facade for private Filter management but does not select or persist a product filter. Audio and Audio Artifacts share the same Audio context helper.
Provider composition remains Gemini 3.1 Pro plus one isolated Codex app-server with Audio on GPT-5.6 Terra and Chat on GPT-5.6 Sol. Startup preserves the current Audio projection at `state/audio-classification-v2`, the Chat root, every unrelated state path, listener, origins, Vault, Accounts, Invites, provider behavior, and public `run` API.
Startup reports fixed secret-safe stages, with the existing bounded safe child detail for Codex Adapter, Audio Classification, and Chat. Public daemon startup is blocking and process-lifetime; checks start no listener or provider. This release performs no state wipe, migration, provider call, browser update, restart, deployment, or live traffic.