Without KFD
- Local operation is unchanged.
- Every external Hub connection needs a custom bridge.
- Handoff, retry, verdict, conflict, and exit semantics remain proprietary.
For Agent Builders
Our ambition is deliberately narrow: make KFD the standard interoperability protocol and libkungfu the local runtime. You build and own the Hub.
The adoption decision
KFD does not make your Hub possible. It replaces a growing set of custom Hub-to-Hub bridges with one responsibility boundary.
The Builder contract
The Hub is the highest-value product layer, and it remains entirely yours. Kungfu makes the capability layer beneath it interoperable—without entering your customer relationship.
Kungfu does not cross this product and customer boundary. Integration is not a channel into your customer relationship.
Portable responsibility and evidence between independent systems. KFD requires no central Kungfu cloud.
A public capability layer for durable local facts and action continuity—not a wedge into your Hub.
01The KFD-libkungfu network
libkungfu lives inside an adopting Hub. KFD connects its edge so independently owned Hubs can exchange rooted responsibility without sharing one runtime, database, identity provider, cloud, or customer relationship.
Builder-owned boundary
Everything inside this box remains part of the Builder’s product.
Users · UI · models · Agent · accounts · billing · cloud
Journal · Fact cuts · Episodes · Warrants · recovery · works locally without KFD
Profile roots · capabilities · idempotency · portable records
Local call · IPC · file · HTTP · gRPC · message bus · offline bundle
Independently owned boundary
The receiver does not need Kungfu and never imports the reference side’s trust.
Its users · UI · models · accounts · workflows · cloud
Identity · Warrant · admission · disclosure · conflict · completion
Original bytes · roots · receipts · idempotency · export
No central KFD authority: no required global identity provider, Hub registry, database, transport, clock, or KFD cloud.
Bytes arrived; the receiver still owns the verdict.
An Episode happened; success still needs independent assessment.
Identity control does not prove permission, truth, or fact admission.
02Why action semantics are necessary
A KFD exchange cannot be only an RPC payload. For another Hub to evaluate and continue the work, responsibility must preserve why the action was pursued, what was known, what was allowed, what happened, and what the receiver accepted. libkungfu preserves those coordinates.
A rooted view of accepted state, not every observed claim.
Changing a Fact, intent, view, permission, action, or resource creates a different binding. Tool success alone does not settle meaning.
Receipts and consequences become evidence; local policy admits, rejects, degrades, or conflicts the resulting claims.
The successor cut starts the next loop without rewriting history.
Semantic source: Fact, Episode, and Action runtime.
03Dogfood · public and auditable
The totals matter only after the unit of proof is clear. Each retained path connects real work to an exact Cut, independent review, and a released result.
Public work → exact Cut → independent review → release
Read one proof unit before the rolling 30-day totals.
Purpose, source cut, authority, and acceptance are explicit.
Source, receipts, and known gaps bind the result being claimed.
A separate review checks the exact result and evidence.
Production closes the path without inflating the claim.
Loading the append-only observation chain from libkungfu.dev…
Adjacent observations compare overlapping rolling P30D windows; they do not count work newly created in one week.
Retained fallback: Live verified history is loading.
Counting boundary: A PR is a work item, not a feature count. An account is not an Agent actor. A review-search match is not an approval.
04A bounded starting path
The current evidence supports a bounded first-party reference path—not certification or broad vendor adoption.
Run one Kungfu command to execute the fixed KFD Hub 20 suite, see what passed in plain language, retain rooted evidence, and keep the non-claims visible.
Open the executable proof pathReview the source-linked C, Node, or Python quickstart. No registry install command is claimed where a public package does not yet exist.
Open exact quickstart sourcesProject bounded lifecycle events into the runtime while prompts, tool payloads, provider data, models, and credentials remain outside the reference adapter.
Audit the reference integrationUse KFD conformance reports and Buildchain release evidence to state only what the exact suite, platform, source, and residual-risk roots support.
Audit the Passport integrationInspect the exact reference source first. Nothing in this path requires replacing your Hub, moving your customer relationship, or accepting a claim beyond the retained evidence.