kodachi://tools/faq/case-files
CLASSIFIED KNOWLEDGE BASE // 08 DOSSIERS

Case Files

247 investigated questions across eight dossiers: install, boot, editions, dashboard, AI, network, and security. Search every folder at once, jump to the most common issues, open a case for the full finding, and follow the cross-references. Verify anything against the documentation, ISO, and source before changing privacy settings.

247 total cases 8 dossiers verified vs docs / ISO / source Applies to the Kodachi 9.x line - Desktop / Terminal / Binary Pack Last updated 24 June 2026
[ 0.000000 ] mounting case archive ... [ ok ] [ 0.000041 ] indexed 247 answers across 8 folders ... [ ok ]
Verify ISOOpen the integrity answer before installing. LUKS nukeUse the correct installer path for boot-time nuke. DNS repairFix resolver issues without blindly dropping tunnels. Threat modelNo tool guarantees absolute anonymity by itself.
triage
// pinned dossier

Most common issues

surfaced by the cases people open most
01Getting Started25 cases
What Kodachi is, the threat model, trust, and which edition to pick

On first boot you reach the Kodachi-branded LightDM login (default credentials kodachi / Security4All; use the greeter's keyboard/language selector first if needed), then the dark XFCE desktop loads with the Conky real-time system monitor. The Kodachi Dashboard then auto-launches and shows a welcome screen for terms acceptance, dashboard mode selection (Full, Lite or Circle), optional startup privacy settings and network detection, and it offers AutoShield as the guided first-boot setup route. Automatic first-boot operations include binary deployment verification, DNSCrypt auto-configuration, online authentication, system status collection and Conky initialization. AutoShield is the Dashboard's countdown-driven setup wizard, not a separately launched program.

Yes. Every Kodachi security service is a standalone CLI-first Rust binary, so the full suite works headless with no dashboard. The Kodachi Terminal Server edition is terminal-only by design (no GUI at all), built for hardened servers and headless deployments, and exposes the same binaries (health-control, tor-switch, dns-switch, routing-switch, workflow-manager, and more) directly from the command line.

Yes. On the desktop edition the "Kodachi Rofi Actions" menu gives keyboard-driven access to security operations, network controls, services, and utilities without using the mouse. The launcher is bound to Ctrl+K (it runs /usr/local/bin/kodachi-rofi-actions). The broader application/rofi launcher is also bound to Super+R, Alt+F1, Alt+F3, Ctrl+Escape, and a tap of the left Super key. On the Terminal edition everything is driven from the shell.

It is a set of keyboard-driven Rofi menus installed to /usr/local/lib/kodachi-rofi/. The Actions menu is the primary dispatcher and opens sub-menus: Favorites (quick-launch tools), Network (VPN connect/disconnect, Tor toggle, DNS switching, routing mode), Services (start/stop/status for Tor, DNSCrypt, firewall), and Utilities (cleanup, MAC randomization, hostname change, panic triggers). Launch it with Ctrl+K.

Yes. On first login the AutoShield welcome script detects whether DNSCrypt has been configured (via a marker file), and if not it auto-configures encrypted DNS, retrying up to 3 times with short delays. It writes a marker so it does not reconfigure on later logins, and it auto-recovers if systemd-resolved hijacks DNS. You can force reconfiguration with kodachi-autoshield.sh --force-dns-setup.

Yes. Kodachi delivers a fully prepared, hardened environment with built-in privacy tools ready from the very first boot. On the Desktop edition the Kodachi Dashboard auto-launches at login and presents AutoShield, its guided first-boot wizard, which runs a multi-step security hardening sequence; you can re-open it any time from the dashboard header. The overview describes Kodachi as providing out of the box what would take most users months of setup to build correctly.

Yes. Kodachi 9 ships KAICS (an 8-binary plain-English CLI) and an ai-gateway for policy-firewalled agent execution. It uses a 7-tier engine (TF-IDF, ONNX, ONNX-Classifier, Local LLM, Mistral.rs, GenAI/Ollama, then Claude) and is offline-first, with optional cloud routing only via VPN or Tor. On Desktop, the AI Chat button is available in Circle, Lite and Full modes to explain commands or suggest sequences without leaving your tab.

Kodachi 9 provides 25 auto-documented Rust binaries plus bundled companion runtimes, covering routing, Tor, DNS, integrity, host security monitoring, health/emergency control, authentication and a local AI stack. On Desktop the Kodachi dashboard orchestrates 600 generated commands across 25 Rust binaries with no GUI freezing. The Terminal edition ships the same 28-binary pack in /opt/kodachi/dashboard/hooks/ (20 core + 8 AI); the Conky telemetry display itself is a Desktop add-on.

No. Kodachi is a hardened privacy and security operating system, not a standalone VPN provider. A VPN is only one component; Kodachi also bundles Tor routing, DNS leak protection, anti-forensics tools, multiple tunneling protocols, and hardened defaults. The docs explicitly say it should not be compared to a normal VPN subscription because it is an integrated OS-level stack rather than a single tunnel service.

Kodachi is a Debian 13-based distribution shipping failover VPN, Tor routing, DNS protection, encrypted crypto wallets, full-disk encryption utilities, a hardened browser, and an integrated dashboard, all working from first boot. The stated value is delivering out of the box what would otherwise take most users months of manual setup and trial-and-error to assemble and harden correctly.

Choose Desktop (full XFCE on Debian 13, ~5GB) for daily privacy-focused computing with a GUI. Choose Terminal (minimal live ISO, 2.4GB, Debian 13) for testing the toolchain, headless privacy deployments, or running a dedicated SOCKS proxy gateway on old hardware or a VM. Choose the Binary Suite to run the signed Rust binaries on an existing Debian-based system. All are free for personal use and share the same underlying privacy stack.

Yes. Run it as a live USB (no traces, nothing written to disk) or in a VM (VMware/VirtualBox/QEMU). The Terminal edition is explicitly described as a safe isolated environment to test the full binary suite without affecting your main system. Take a VM snapshot before experimenting so you can roll back.

If you are new, the best way to learn Kodachi is inside a virtual machine, not on your real hardware. Install VMware Workstation Pro (now free for personal use), then run two instances side by side: one booted from the live ISO and one installed into its own VM. Take a VM snapshot before you experiment so you can roll back to a clean state at any time, then play, test and learn as much as you want with zero risk to your host machine. This is how the developer runs it day to day. Only install Kodachi on bare metal (your physical drive) if you genuinely need it as your everyday daily-driver OS. For the safe-testing options see Can I try Kodachi safely without affecting my main system?, and for every supported run method see Can I run Kodachi purely from a USB or SSD?

Kodachi is built in the open: the Rust binaries, dashboard, and live-build tooling are on GitHub, so it can be read, built, and audited. Every Rust binary, ISO, and the binary tarball are cryptographically signed with a published public key, and a regularly refreshed signed warrant canary is maintained. It is built by a named maintainer, Warith Al Maawali (digi77.com), the same person since 2013, and is independently tracked on DistroWatch.

Kodachi is provided for legitimate privacy protection, security research, and educational purposes only and must not be used for illegal or criminal activities. Users are solely responsible for compliance with all applicable laws in their jurisdiction, and the developers disclaim all liability for misuse. Anyone intending unlawful use is told to discontinue use immediately.

No tool guarantees absolute anonymity. Kodachi gives a strong integrated stack (VPN, Tor, proxies, DNS controls, anti-leak enforcement) and hardened defaults from first boot, but real anonymity still depends on your configuration and behavior - which routing mode you select and your OPSEC. The docs frame it as giving real control and protection and teaching better habits, not as automatic, absolute anonymity.

No. The free tier uses the same binaries, the same OS-level hardened stack, and the same updates as the paid plans. The only differences are backend infrastructure quality, commercial usage rights, and priority support - not the software or its security capabilities.

No. There is no registration, no account, and no personal data required - you can authenticate and even pay (via Monero) with no email or phone number. The design goal is to never create useful data in the first place: client traffic is encrypted, the VPS exit nodes are regularly wiped and replaced, and the master node keeps no usage logs, so even in a worst-case compromise there is very little of value to obtain. The same hardening is applied across the client, the VPS nodes, and the master node - a privacy OS is only as good as its backend.

Authentication is what unlocks Kodachi's service-backed features: the built-in VPN nodes, the proxy pool, encrypted DNS and the other cloud-assisted tools. You do not log in by hand, the dashboard signs in automatically as it loads, silently and with no username or password to type, so for most users it simply happens in the background.

It serves two goals that directly benefit you. First, it separates free from premium access, which is what lets the project offer a capable free tier and keep the lights on. Second, it is an anti-abuse gate: by blocking bots, scrapers and anyone hammering the infrastructure, it keeps the shared free nodes fast and usable for everyone. Crucially, it needs no personal data at all, no email, no phone and no name, so it controls access without identifying you (see is authentication tracking me).

No. Authentication exists to distinguish paid from free users, limit abuse, and protect the project from malicious actors - not to monitor you. You authenticate without any personal details (no email, no phone), so your anonymity is preserved. The OS itself runs without authorizing, but the service-backed features won't fully work until you authenticate; it is an anti-abuse gate, not surveillance.

Kodachi's code is published on GitHub at https://github.com/WMAL/kodachios. The full source of versions prior to v9 is public, including Kodachi 8.27 (the last of the 8.x series) together with the full dashboard source. Source is released after major changes or shifts so users can study how Kodachi evolved over time. The Kodachi 9 bash scripts that ship inside the ISO are also hosted on that same GitHub repository.

Study the published code and its history on GitHub at https://github.com/WMAL/kodachios. The full source of pre-v9 releases such as Kodachi 8.27 and the complete dashboard source are there, and the project publishes source after major changes so you can trace how the system evolved across versions. The Kodachi 9 bash scripts bundled in the ISO are also hosted in that repository, so you can read exactly what runs at boot and during setup.

Kodachi is created and maintained by Warith Al Maawali, an independent security engineer who has developed it as a one-person project under the same name since 2013. He builds it openly under his real identity rather than as an anonymous team, and also runs digi77.com. You can see who he is and follow the work directly on LinkedIn at https://om.linkedin.com/in/warith1977 and on X (Twitter) at https://x.com/warith2020, and the full project history is on GitHub at https://github.com/WMAL/kodachios.

Yes. Kodachi publishes a regularly refreshed warrant canary at /tools/warrant.html. A warrant canary is a routinely updated statement that no secret legal orders or gag requests have been received; if it stops being updated or its wording changes, treat that as a warning sign. It is part of Kodachi's transparency model alongside the open source code and the cryptographically signed releases.

It is a short, plain-language agreement, not data collection and not registration. Nothing is sent anywhere; accepting it only writes a local acceptance file. Its real purpose is to protect the developer, and that protection matters precisely because Kodachi is not run by an anonymous team. Most privacy projects hide behind pseudonyms. Kodachi is built openly by Warith Al Maawali under his real identity, which is exactly what lets you verify and trust who is behind it. The trade-off of using a real name is real exposure: if someone uses Kodachi to commit a crime, the author could be wrongly dragged into it. The terms make the boundary explicit. They state that Kodachi's purpose is to protect privacy, that it must not be used for illegal activity, that you should stop immediately if your intent is unlawful, that the developer disclaims all liability for any illegal actions committed by users, that you agree to use it responsibly and legally, that your own data security remains your responsibility, that the software is provided as-is with no warranties, and that the terms may be updated so you should review them. In short, the acknowledgement exists so every user understands that responsibility for how Kodachi is used rests with the user, not with the person who chose to put his real name on a privacy tool.

No matching case files

Try a different keyword, or browse the full documentation.

Before reporting a bug

Please include all of the following so the issue can actually be reproduced:

Didn't find your answer?

The full per-tool guides and CLI reference cover every command in depth.