# Launch-node Ktools
`SetLaunchNodeKtool::new` receives the shared `K1AccessLaunchNodes` facade. `launch(context, profile_id, policy, arguments)` accepts only a strict JSON object with required string fields `target` and `node_id`. The target follows the launch-node target-name contract, and the node ID is exactly one lowercase 24-hex Access ID. The operation derives `Authority::User(context.user())`, delegates create-or-update behavior to Access Launch Nodes, and returns exactly `success`.
`SetLaunchNodeKtool::get_launch_node` creates the companion `GetLaunchNodeKtool` over the same facade. Its `launch(context, arguments)` accepts exactly `authority_kind`, `authority_id`, and `target`. `authority_kind` is lowercase `user` or `group`; `authority_id` is one canonical lowercase 24-hex UserId or GroupId; and `target` follows the existing exact case-sensitive target-name contract. It delegates once to Access Launch Nodes lookup. Success is compact JSON containing one visible Access ID as `node_id`; the raw Kmap NodeId is never returned.
Malformed JSON, missing, duplicate or additional fields, invalid target names, invalid authority kinds, and invalid authority IDs return exactly `invalid SetLaunchNode arguments` or `invalid GetLaunchNode arguments` for the selected operation. Lookup preserves Access Launch Nodes concealment: missing, filtered, hidden, wrong-subsystem, or otherwise inaccessible bindings and referenced nodes return `launch node is unavailable`. Other Access and storage failures retain their complete safe strings.
Set and Get do not discover authorization, dispatch an inner Ktool name, create or load a Kmap node, advertise native tools, retry, perform network work, or run in the background. Set performs one local create-or-update flow. Get is read-only and performs the existing local binding authorization, raw lookup, and independent referenced-node authorization.