Kimi Code
Kimi Code support is measured on one live 0.42.0 session (2026-09-09): the install path, the three hook registrations, and the print-mode gap below all come from that run, not from a fleet. Ruling pre-action checks are not wired for this host yet.
Install
Adds daimon's capture -> inject loop to Kimi Code from the released package:
daimon hooks install kimi
This copies three hook scripts, plus the modules they share, into the Kimi
config directory, then appends [[hooks]] entries to
~/.kimi-code/config.toml (or $KIMI_CODE_HOME/config.toml when that
variable is set). The config file is backed up before daimon writes to it.
The writer only ever appends or removes daimon's own blocks. It never
rewrites the provider or model tables.
Re-run daimon hooks install kimi after every uv tool upgrade daimon-briefing, same as every other host, so the installed scripts match
the CLI version. Hooks load once, at session start: after installing, start
a new Kimi session. The one already running will not pick up the change.
Requires the daimon CLI on PATH:
uv tool install 'daimon-briefing[pretty]'
What each script does
daimon-kimi-user-prompt-submit.py:UserPromptSubmithook. This is the only channel Kimi gives a hook to put text into the session, so it carries the briefing. Kimi has no session-start injection point (see Limitations below). The model sees the briefing as a user message wrapped in ahook_resulttag, attached to your first prompt.daimon-kimi-session-end.py:SessionEndhook. Serializes the finished session when an interactive Kimi session exits, including the turns after the lastStopcapture. BytesStopalready captured are not re-serialized: the CLI checks the transcript against the last checkpoint before any model call.daimon-kimi-stop.py:Stophook. Runs a throttled capture after each turn. This is crash insurance for an interactive session, and it is the only capture path in print mode, whereSessionEndnever fires (see Limitations).
Limitations
- No briefing at session start. Kimi's
SessionStarthook is observation only, its stdout is dropped. The briefing arrives with your first prompt instead, through theUserPromptSubmithook above. - Print mode never closes.
kimi -psessions stay resumable and never fireSessionEnd, measured twice on a live session. TheStophook is what captures them. On an interactive exitSessionEndruns its own capture regardless of a recentStop, so the turns after the last Stop are not lost; the CLI compares the transcript against the last checkpoint first, so bytes Stop already captured cost a file read, not a second model call. - A resumed session is not briefed again. The briefing marker is keyed
on the session id, so
kimi -ron a session that already received its briefing gets the per-prompt recall injection but no second briefing. Resume itself has not been measured on a live session. - No pre-action checks yet. Kimi's deny channel has not been measured on a live session, so this release ships no check profile for it.
- Hooks load at session start only. Installing does not reach a session already running. Start a new one to pick up the change.
- macOS records the resolved path. Kimi stores the working directory it
resolves to, so a session started under
/tmp/xis recorded as/private/tmp/x. Keep that in mind when you look sessions up by directory.
Transcripts
Kimi writes each session's transcript to
~/.kimi-code/sessions/<workspace>/<session id>/agents/main/wire.jsonl. The
hook payload carries the session id, not a path, so daimon resolves the
transcript by globbing for that session id under the sessions directory.
Subagent transcripts are not merged into the main transcript in this
release.
Kimi is a registered source host: daimon why <item-id> --source and
daimon audit quotes resolve a Kimi checkpoint's transcript the same way
they do for Claude Code, Codex, and Windsurf. Set $KIMI_CODE_HOME and both
commands look under it, matching the install path above. Checkpoints
captured before this host was registered were stamped with an unresolvable
source and stay that way; only checkpoints captured afterward resolve.
why --source goes one step further for Kimi than it does for Codex and
Windsurf: every folded message (each context.append_message/lifecycle row,
and each tool.result) carries a stable id, so a verbatim item captured
after this landed discloses the exact quoted message, the same way it does
for Claude Code, instead of falling back to the stored quote. daimon does
not read a per-message id from Codex or Windsurf transcripts yet, so their
disclosure still falls back. A Kimi checkpoint captured before this landed
carries no message ids either and keeps falling back too.
MCP
daimon hooks install kimi registers the read-only MCP server
automatically: it merges an mcpServers.daimon entry into
~/.kimi-code/mcp.json (or $KIMI_CODE_HOME/mcp.json when set), the file
Kimi's own docs describe for this scope — separate from config.toml, which
carries the hook registration. That entry points at a copied wrapper script
under the Kimi hooks directory, audited by daimon hooks status the same way
as the three hook scripts. daimon hooks remove kimi takes the mcp.json
entry and that wrapper back, together with the config.toml hook entries.
Once the mcp.json entry exists, the recall hint (the per-prompt "you
worked on this before" pointer) names the daimon_recall tool instead of
the daimon recall "..." shell command.
(An earlier version of this page said Kimi reads a project-root .mcp.json
in the same format Claude Code uses. Checked against a live install: the
shape is right — {"mcpServers": {...}} — but the path is not; Kimi
reads ~/.kimi-code/mcp.json, never a project-root file.)
Teach the agent the protocol
daimon skill install kimi # ~/.kimi-code/skills/daimon/SKILL.md
daimon skill install kimi --project # <repo>/.kimi-code/skills/daimon/SKILL.md
Install delivers two skills: daimon (the protocol) and daimon-end, the in-session /daimon-end checkpoint flow, written next to it as ~/.kimi-code/skills/daimon-end/SKILL.md.
Kimi scans both locations for skills. The probe measured where it looks,
not how it ranks the two when both hold a daimon skill, so install to one
scope. Re-run install after upgrading daimon to refresh the content.
Remove
daimon hooks remove kimi
This takes daimon's [[hooks]] entries back out of config.toml and leaves
everything else in the file as it was, line endings included. The one
exception: a file whose last line had no newline gains one, and remove
cannot tell it from one you wrote. The three hook scripts stay where they
are, inert once unregistered. The MCP wrapper (see MCP above) is the
exception: it is deleted along with the mcp.json entry that pointed at
it, since nothing else legitimately points at that file. Checkpoints under
~/.daimon/
are untouched.
Verify
daimon status
daimon status reports capture health for Kimi the same as any other host.
A capture made through the Stop throttle counts the same as one made
through SessionEnd; nothing in the report singles out print-mode sessions.