Services
kabactl server starts several services in one process. This page lists them, then shows how to keep the server running in the background.
What the server runs
Section titled “What the server runs”| Service | Listens on | Purpose |
|---|---|---|
| HTTPS API | 0.0.0.0:28832 | Everything the client asks the engine to do. |
| SOCKS5 proxy | 0.0.0.0:28833 | Browsing and terminal traffic, with ad blocking, Safe Browsing and exit routing. |
| Tor SOCKS5 | 127.0.0.1:28834 | The same proxy with every connection forced through Tor. |
| Cluster endpoint | QUIC, no fixed port | The encrypted mesh between your devices. See cluster & mesh. |
The API and proxy ports are fixed in kabactl 0.87; --bind, --port and the port keys in config.toml are not applied. Both listen on all interfaces, so on a machine with a public address, restrict them with your firewall:
# example: allow only loopback to reach the API and proxysudo ufw deny 28832/tcpsudo ufw deny 28833/tcpThe cluster does not need either port open. Peers reach each other through the mesh endpoint, which makes outbound connections and uses a relay when a direct path is not possible.
HTTPS API
Section titled “HTTPS API”The API is served with the certificate in certs/. It answers GET /health without authentication; everything else needs a session token (issued at sign-in and valid for jwt_exp_time seconds) or an API key. API keys start with kaba_ and are stored hashed.
Areas of the API:
| Area | Routes under | Used for |
|---|---|---|
| Accounts and sessions | users, session, auth, api-keys | Sign-in, profile, API keys |
| Devices and groups | devices, groups, cluster | Peers, invites, eviction |
| Policies and settings | policies, settings | Model policies and preferences |
| Browsing data | frames, visits, sitedata | Saved frames, history, per-site data |
| Memory | memories, trajectories, ontology | Memories, learning data, the tool-loop knowledge graph |
| Models | engine, loras, training, vision, voice | Inference, adapters, training, image description, speech |
| Tools | sandbox, tool, term, files, folder | Containers, tool runs, terminals, file access and sync |
| Network | tor, exposed-services, media | Tor control, service exposure, media controls |
| Security | security, vault | Safe Browsing database, password vault |
| System | health, sys/gpu, ws | Liveness, GPU information, the event WebSocket |
This is an internal API for the client and may change between releases. A stable public API reference is not published yet.
SOCKS5 proxy
Section titled “SOCKS5 proxy”The client sends browsing traffic through the proxy so that one place can apply blocking and routing.
- Local connections (from
127.0.0.1) need no credentials. - Remote connections must authenticate with username
kabaand a signed token as the password. A username ofkaba:<pane-id>ties the connection to one pane, which is how per-pane Tor works. - Requests are checked against the ad-block lists and the Safe Browsing database.
- If an exit node is selected (Settings → Devices → Use as exit), traffic is tunneled to that peer over
kaba/exit/v1and leaves from its network.
curl --socks5-hostname localhost:28833 https://example.comTor support is built in (no separate Tor install). It can be turned on for all browsing, for one pane, or automatically for chosen domains. Exposed services can also be published as onion services. In the client: Settings → Security & Privacy → Tor routing, or the pane menu.
Exposed services
Section titled “Exposed services”A node can publish a local host:port to the mesh under a name, either private (reachable with an access token) or public (announced to the public directory and searchable). Protocols are http, https and tcp. In the client this is Hippocampus → Services → Expose. See protocols.
Other things the server does
Section titled “Other things the server does”- Terminals. Spawns shells for terminal panes, locally or for a peer, and records sessions as memories with secrets redacted.
- Sandbox. Runs tool-loop commands in containers. See security.
- Vault. Stores saved logins and passkeys, or delegates to
passor 1Password. - Voice. Speech-to-text and text-to-speech models, provisioned at start when built with voice support.
- Media. Reads and controls media players on the machine for the header media controls.
Run as a service
Section titled “Run as a service”There are two ways to keep the server running. Use one, not both.
Built-in daemon
Section titled “Built-in daemon”kabactl service startkabactl service statuskabactl service stopstart detaches the server and writes kabactl-service.pid and kabactl-service.log in the storage directory. stop sends SIGTERM and waits before forcing the process down.
systemd (Linux)
Section titled “systemd (Linux)”kabactl service install --systemd # per-user unitsudo kabactl service install --system --systemd # system-wide unit| Per-user | System-wide | |
|---|---|---|
| Binary | <storage>/bin/kabactl, symlinked into ~/.local/bin | /usr/local/bin/kabactl |
| Unit | ~/.config/systemd/user/kabactl.service | /etc/systemd/system/kabactl.service |
| Runs as | you | a dedicated kaba user, created if missing |
| Data | your storage directory | /var/lib/kaba |
| Logs | journalctl --user -u kabactl | journalctl -u kabactl |
Both units run kabactl server in the foreground so systemd supervises the process, restart on failure with a 5 second delay, and give up after 10 restarts in 5 minutes.
The system unit is hardened: no new privileges, read-only system directories, private /tmp and devices, no access to home directories, only IPv4, IPv6 and Unix sockets, and write access only to /var/lib/kaba.
systemctl --user status kabactlsystemctl --user restart kabactlTo remove everything install created:
kabactl service uninstall # per-usersudo kabactl service uninstall --systemmacOS and Windows
Section titled “macOS and Windows”service install copies the binary to the managed location and prints the line to add to your PATH. There is no launchd or Windows service integration in kabactl 0.87; use kabactl service start, or let the client manage the engine (Settings → Run In Background).
Logs and diagnostics
Section titled “Logs and diagnostics”| What | Where |
|---|---|
| Server log | <storage>/kabactl-server.log (rotating) |
| Daemon output | <storage>/kabactl-service.log |
| More network detail | start with KABA_DEBUG=1 |
| Crash and memory bundle | start with --trace or KABA_TRACE=1; see <storage>/perf/CURRENT |
| Health check | kabactl doctor |
A --trace bundle contains the environment, allocator statistics, memory samples, an event log and any panics. It is packed into perf/<run>.tgz on shutdown so you can attach one file to a bug report.