# K1 WebCode service
`K1WebCodeKtoolService` binds every family to a backend-selected `Authority`. Create persists a brand-new versionless document in the KTO-backed workspace subsystem. Docs and Open select an optional exact published SemVer or unpublished 12-byte ID; default Docs uses only the highest published version, while default Open uses the latest workspace unless its authored bytes are already represented by a public version. Multiple workspaces remain directly addressable.
Overwrite validates the current session handle and authority, then always submits one workspace transaction. Published or already-published authored source branches to a new unpublished ID; dirty unpublished source retains its ID and advances its revision. Check always runs a fresh Podman check, using the exact public SemVer or a deterministic private draft version. Publish requires an unused SemVer, runs a fresh exact-version check, preserves one exact source Object, reauthorizes disclosure, publishes through the immutable public projection, and returns a handle for the new public version.
Public SemVer Docs/Open need no workspace authorization; every unpublished read and every mutation/check/publication revalidates current authority. Session handles are process-local. Workspaces and public source are authoritative; the per-user Web coding cache is disposable. Operations perform no retry, migration, deployment, or background work.