KDCube now prepares every app under its own supervised lifecycle. A slow checkout, hook, index, or UI build makes that app temporarily unavailable without making an otherwise healthy processor look dead.
A vector is a pure function of query, model and dimension — so every repeated search re-pays for an answer the system already has. The obvious fix is to remember it on the index object, and in a runtime where turns hop between workers it catches the one repeat that rarely happens. What the shared cache needs instead: a key that carries the model, a value ...
A teammate opens a browser, asks the resident agent to change a file in a git-backed store, watches the work happen as steps, reviews the diff on a desk beside the chat, and commits — under their own identity, with only the capabilities they granted.
Your app publishes a service. Discovery indexes it. An agent asks for it — and gets an error about a permission nobody has heard of. Nothing is broken: three of the four decisions that make a service usable have not been taken yet, and each belongs to someone else.
Run multiple websites locally on one KDCube, route each by alias or host, and expose the same routes through ngrok.
How KDCube apps choose among local operations, named services, Data Bus, jobs, conversation ingress, MCP, REST, and widgets.
Configure API, MCP, and widget enablement, visibility, auth, and API CSRF from code defaults, descriptors, or the Apps dashboard.
A map of KDCube serving, Data Bus, communication, venv, provider, and isolated-execution runtimes — and the explicit contract at each crossing.
A hosted agent does not carry a session, restore a conversation, keep a file, or survive a worker restart on its own. Two different memories do that for it — one the platform owns, one the agent owns — and the line between them is the whole story.
An agent loop can choose a next action. It cannot, by itself, bind a user identity, serialize concurrent messages, preserve files, restore a conversation on another worker, enforce a grant, account for a model call, or isolate generated code. KDCube supplies that operating layer around the agent — without requiring the agent's reasoning core to become a K...
How a service resolves the approving user's connected credential through the Connection Hub broker - per call, at the trusted boundary, no token in your code.
My agents act on users' Gmail and Slack every day - external agents like Claude Code included - and none has ever held a provider token. Every access is something the user granted, granular and on demand, and it takes two acts they control: connect the account, and permit the agent. Here is the whole machine, fence by fence.