
# The local daemon

The local daemon is the process that does work on your machine for
Ethen Code. It is a loopback-only server: it listens for the desktop app
and the web zone on your machine, never for the network. It is not
released yet; it ships inside the desktop bundle, never as a separate
download.

## What it does

- Sole executor. Terminals and tool runs are spawned by the daemon and
  contained to trusted repositories. Terminals never receive credential
  environment variables.
- Pairing. The daemon generates a pairing token and shares it with the web
  zone; every non-health request carries the token back.
- PTY terminals. Daemon-local terminal sessions back the console terminal
  surfaces. PTY allocation can fail on hosts without PTY devices; the
  daemon reports terminal-unavailable and keeps serving rather than
  crashing.
- Local models. The daemon serves the local-model routes — runtime status,
  installed-model list, model details, approval-gated pull with progress,
  and resume-safe cancel — against a loopback-only Ollama.
- Housekeeping. Instance lock, sleep/wake handling, crash recovery, and
  readiness checks keep one healthy daemon per machine.

## What it is not

- Not a network service. There is no port to open, forward, or share.
- Not a separate install. It arrives inside Ethen Desktop Code as bundled
  resources.
- Not a credential store. Secrets stay out of terminal environments by
  design.

## Trust model

Repositories must be trusted before the daemon runs work in them, and
sandboxing constraints apply where the platform supports them. Exact
mechanics follow the branch implementation and will be documented with the
release.

## Related guides

- [Install Ethen Code](./install)
- [Ethen Code desktop](./desktop)
