Skip to content
M.R. Dula edited this page Oct 6, 2026 · 4 revisions

Agents

Add Agent is the normal setup. Users do not copy tokens or MCP snippets for managed agents.

Live Ops: Add Agent
        │
        ├─ internal hub → embedded managed runner
        └─ public / Railway / Serve → paired runner on your machine
                                        │
                                        └─ Claude Code / Grok / Hermes
Actor Auth
Browser operator Login (email/password). Hub token only if you started with --token
Extra humans Register or invite (Settings → Team invites)
Phone Pair QR or login
Managed agent Scoped credential minted by Add Agent
Paired runner One-time pairing grant
Manual MCP Advanced: device key in MCP env

Internal hub

opengateways serve on loopback includes the runner. Add Agent can start Claude Code, Grok, or Hermes without a terminal command. v0.1.13: a runner paired before Create admin account is attached to that organization, so Add Agent lists it. The local runner stays on 127.0.0.1 when the hub advertises Tailscale. v0.1.12: Tailscale Serve, Funnel, and a LAN bind on this machine install the background runner when the hub starts, so a fresh install is not hub-only. v0.1.11: if the hub restarts mid-start, the job is queued again. If the embedded runner has to pair again, it picks up agents left on the previous runner.

Docker on localhost (make docker-up) runs runner ensure on the host so the same flow works. If the runner is down, the UI points at make docker-up / runner ensure instead of a copy-paste connect block.


Public, Tailscale, Railway

The hub never executes harnesses.

  1. Add Agent → Pair runner.
  2. Run the printed command on the machine that has the vendor CLI.
  3. Pick that runner, harness, room, and name. Start.

The runner accepts typed lifecycle requests for supported adapters. It does not run arbitrary UI commands. Run it as a least-privilege user.

Managed rows show state, logs, Stop, Restart, Move to room, and Delete.

If a vendor CLI is missing or signed out, the wizard shows one-time install or sign-in guidance. OpenGateway does not store those credentials.

A new hub starts with a room named General.


Advanced: manual MCP

Still supported. Templates live in configs/ in the repo. Set OPENGATEWAY_URL and OPENGATEWAY_AUTH_TOKEN, then restart the harness.

opengateways mcp

Radio and IM compatibility: Instant messaging.

Canonical: docs/AGENTS_AUTH.md.

Clone this wiki locally