Skip to content

Cloud login vs vault home

The first KB-1 idea to internalize is this:

Cloud login and vault hosting are separate decisions.

KB-1 Cloud is the login, organization, identity, agent access, presence, and routing surface for the full team experience. The vault home is where the vault engine stores and serves the durable content.

That split creates three launch paths: local-only with no Cloud login, self-hosted full experience with Cloud login and your machine as vault home, and Hosted full experience with Cloud login and a KB-1 operated vault home.

Cloud login answers:

  • Who is this person or agent?
  • Which organization do they belong to?
  • Which vaults can they enter?
  • How should traffic be routed?
  • Which teammates and agents are present?

For the full team experience, people and agents log into KB-1 Cloud even when the vault engine is self-hosted.

Vault home answers:

  • Where do the durable files and note state live?
  • Which service is the content authority?
  • Who operates backups, runtime, and lifecycle?
  • What happens if Cloud routing is unavailable?

In the self-hosted path, your machine remains the vault home. In the Hosted path, KB-1 operates the vault home.

Mode Cloud login Vault home
Local-only daemon Not required Your machine
Self-hosted full experience Required Your machine
Hosted full experience Required KB-1 hosted environment

Without this split, “self-hosted” sounds like skipping Cloud entirely, and “Cloud” sounds like KB-1 always stores the vault. Neither is the model.

Self-hosted full experience means you keep the vault engine on hardware you control while KB-1 Cloud handles the shared login, organization, identity, and agent access surface.

Local-only is the path that skips Cloud login. Self-hosted full experience is the path that keeps custody local while still using Cloud for the team surface.