# K1 daemon library 0.10.5
`kcode-k1-daemon-lib` is the library-only composition root exposing `run(PathBuf) -> ExitCode`. Startup creates the multithreaded runtime, prompts once for the protected Vault passphrase, opens established state beneath `<k1_root>/state`, preserves readiness, slow-start, invite-stock, safe-error, and graceful-shutdown behavior, then binds `127.0.0.1:4450`.
K1Http owns signing, authentication, replay protection, CORS, `nosniff`, body collection, and authenticated `/api` nesting. The daemon opens current Access at `state/access`, concrete Profiles at `state/access-profiles`, one private Authority Filters facade at `state/authority-filters`, and authority-scoped launch-node bindings at `state/launch-nodes`.
Launch-node startup composes the raw binding store with shared Access and Groups, then mounts the signed Access-protected lookup, create, and update routes. Launch-node HTTP resolves request-local authority filters through the shared Filters facade and uses the same GPT-5.6 Sol authorization model as Chat. Binding authorization remains separate from referenced Kmap-node authorization; the API returns only the visible Access-Kmap node identity.
Chat, Persons, Audio, and Audio Artifacts receive immutable request-local access contexts backed by the shared Filters facade. The daemon selects GPT-5.6 Sol for Chat and launch-node authorization, Gemini 3.1 Pro for Persons authorization, and GPT-5.6 Terra for Audio authorization. People receives the same facade for private Filter management but does not select or persist a product filter. Audio and Audio Artifacts share the same Audio context helper.
This clean cutover selects Access 0.6.0, Access Full Audio 0.9.1, Access Launch Nodes 0.2.0, Access Persons 0.3.0, Access Profiles 0.6.0, Authority Filters 0.2.0, Chat Service 0.6.0, Full Audio 0.3.7, HTTP Access Context 0.2.0, HTTP Audio 0.3.0, HTTP Audio Artifacts 0.3.0, HTTP Chat 0.5.0, HTTP Launch Nodes 0.2.0, HTTP People 0.9.0, HTTP Persons 0.3.0, and Launch Nodes 0.3.0. Chat selects HTTP Chat 0.5.0, Chat Service 0.6.0, and Provider Config 0.1.4, including the service’s Chat Persistence 0.3.0 and Chat Thread Main Actor 0.7.0 chain. The service opens exclusively at `state/chat-v2`. Chat opens shared Kmap at `state/kmap`. Its Codex profile registers exactly one native tool named `call_ktool`; a generic base instruction explains that one inner Ktool is selected through `name` and receives JSON-object `arguments`. Inner Ktool names and argument contracts remain supplied by the user or conversation and are not separately advertised. The profile does not directly register `CurrentTime` or any Kmap operation. Existing Chat Thread Actions dispatch still supports inner `CurrentTime` plus the five user-prompted Kmap operations. This is the codec-v2 clean-reset boundary: the daemon does not read, delete, migrate, transform, or fall back to old `state/chat` data, so those old bytes remain inert. Chat snapshots preserve generic five-field boxes, including `hidden_type` and `hidden_contents`; the hidden fields are exposed to authenticated clients, omitted from the provider projection only for token efficiency, and are not secret.
Provider composition remains Gemini 3.1 Pro plus one isolated Codex app-server with Audio on GPT-5.6 Terra and Chat on GPT-5.6 Sol. Startup preserves the current Audio projection at `state/audio-classification-v2`, every unrelated state path, listener, origins, Vault, Accounts, Invites, provider behavior, and public `run` API.
Startup reports fixed secret-safe stages, including `Launch Nodes` and `Access Launch Nodes`, with the existing bounded safe child detail for Codex Adapter, Audio Classification, and Chat. Public daemon startup is blocking and process-lifetime; checks start no listener or provider. Publication proves the package composition only; local dependency selection, rebuild, restart, deployment, signed traffic, privacy behavior, and live launch-node outcomes require separate evidence. This release performs no state deletion or migration, provider call, browser update, target provisioning, Kmap-node loading, live canary, or live traffic.