KDCube

Engineering

Deep dives from building an event-first, multi-user AI platform.

45 articles · latest 2026-07-03

Search covers titles, summaries, tags and full article text.

Setting Up Platform Authority In KDCube

KDCube can turn a browser user into a platform user through Cognito, multiple Cognito pools, a local SimpleIDP, or an application-hosted login. These are not interchangeable — they differ in who proves the user, which credential is written, and which verifier accepts it. This overview puts all methods side by side, anchored on one contract: Connection Hub...

platform-authoritycognitomulti-cognitosimpleidpapplication-hosted
2026-07-03

Your Application As A Platform Authority

Sometimes the product already has a login page, a branded sign-in, or an upstream proof like Google. An application can host the platform login and consent screens while Connection Hub owns the authority registry and KDCube still verifies a standard platform session. This piece walks the split: the app hosts the door, Connection Hub registers what the doo...

connection-hubauthority-registryapplication-sessionplatform-logindelegated-credentials
2026-07-02

The Conversation Is a Lane

A conversation is an ordered event lane. One bus, two consumption models — live ReAct folding and run-to-completion turns — fenced at every seam.

event busevent lanereactive turnssupersessionwake vs body
2026-07-02

Authenticated MCP In KDCube: Delegated Credentials, Not Shared Secrets

An external client speaks MCP and wants a KDCube service. The lazy answer — a shared secret — fails the moment you ask whose data it acts on, what it may do, who pays, and how to turn one connection off. KDCube's answer is a delegated credential: a bearer KDCube issues, scopes to one resource, narrows to consented tools and grants, and records back to the...

MCPoauthdelegated-credentialsconnection-hubpkce
2026-06-30

The Three Memory Realms

A user's memory here is not one store but three folds , each a different aspect: mem holds curated durable entities (what is true), conv records the temporal stream with its production context (what happened, when & where), and cnv gathers cross-world references on a focus board (what is kept at hand). Formed differently, meaning different things, designe...

memorymemconvcnvrecall
2026-06-29

Protecting KDCube Surfaces With Managed Credentials

Your MCP handler should never see an unauthorized call. A managed surface declares its auth in descriptors; one shared Connection Hub guard then runs a fixed sequence of fail-closed checks — credential valid → authority → resource (exact) → tool allowed → grants present → tool consented — before the bundle handler is ever called. This Deep piece walks the...

connection-hubmanaged-credentialssurface-guarddescriptorsMCP
2026-06-29

Delegating A KDCube Service To An External App

You have an external app and you want it to reach one KDCube service. Connecting it issues a delegated credential — carrying only the resource grants and selected operations/tools you approved, recorded as a durable consent edge that keeps the app as its own actor and you as the grantor. This Deep piece walks the connect → consent → delegated-credential f...

connection-hubdelegated-credentialconsentMCPleast-privilege
2026-06-29

Connected Identities Are Not One User Id

The same person is not the same as one user_id . They arrive through many channels, each with its own verified identity. The platform keeps those ids separate , links them into a family , and asks two different questions of that family: who is this for? and what may this execution do? This Deep piece defines the foundational vocabulary the rest of the Con...

connection-hubidentityconnection-edgesidentity-familyauthority-projection
2026-06-29

The Scene: A Host for Cooperating App Surfaces

The browser control plane where independent app surfaces become one workspace: mounted widgets, claimed events, context drag, provider-owned actions.

sceneapp surfacesevent claimssurface commandscontext drag
2026-06-24

Named Services: The Interface Between Agents And App Realms

An app owns a realm — task:, mem:, cnv: — with its own schema, search, actions, and rendering. Named services let any hosted agent enter that realm without learning any of its private domain rules. The agent gets one generic interface; the provider remains the owner of meaning. This Deep piece walks the four agent surfaces, the pull/read materialization p...

named-servicesreact agentprovider realmobject refmaterialization
2026-06-24
← Newer31–40 of 45Older →