Local-only, self-hosted, and Hosted
KB-1 has three operating modes.
Local-only daemon
Section titled “Local-only daemon”Local-only daemon mode is the open-source solo/developer path. The daemon runs on your machine and Cloud login is not required.
Use it when you want maximum custody and can manage access, backups, and runtime yourself. The open-source daemon does not model Cloud users, organizations, team presence, or org permissions. It serves the local UI, API, and MCP endpoint to clients that can reach that machine, or a private network you deliberately trust.
Self-hosted full experience
Section titled “Self-hosted full experience”Self-hosted full experience keeps the vault engine on your machine while people and agents log into KB-1 Cloud.
Use it when you want local custody plus organization identity, signed entry, relay, team access, and agent access from machines that are not colocated with the daemon.
Hosted full experience
Section titled “Hosted full experience”Hosted full experience uses the same KB-1 Cloud login surface, but KB-1 operates the vault engine in a hosted environment.
Use it when you want KB-1 to manage lifecycle and durability for you.
The shared rule
Section titled “The shared rule”The full team experience starts with KB-1 Cloud login. The hosting choice only decides where the vault engine runs.
If a workflow needs users, orgs, remote teammates, remote agents, or Cloud MCP, it is no longer just the open-source daemon. It is the Cloud-connected self-hosted path or Hosted path.