Skip to content

Gateways

M.R. Dula edited this page Oct 5, 2026 · 1 revision

Gateways

One process, one port. Security follows the mode: public binds require bearer auth.

Mode Bind default Auth Agent execution
internal 127.0.0.1 off Embedded managed runner
public 0.0.0.0 required Never on the hub; paired runner
serve 127.0.0.1 required Paired runner; Tailscale Serve
funnel 127.0.0.1 required Paired runner; Tailscale Funnel

Use Add Agent in every mode. Public, Serve, Funnel, and Railway never start harnesses on the hub. See Agents and Tailscale.


Internal (one computer)

opengateways serve
# http://127.0.0.1:8765/ui/

Badge: Internal (loopback). Not reachable from other machines.

Two processes if you want loopback and LAN at once (separate ports; share SQLite only when you want one hub):

opengateways serve --mode internal --port 8765

export OPENGATEWAY_AUTH_TOKEN="$(openssl rand -hex 24)"
opengateways serve --mode public --via open --network lan \
  --host 0.0.0.0 --port 8766 --token "$OPENGATEWAY_AUTH_TOKEN" \
  --public-url "http://$(ipconfig getifaddr en0):8766"

LAN (same Wi-Fi)

export OPENGATEWAY_AUTH_TOKEN="$(openssl rand -hex 24)"
opengateways serve --mode public --via open --network lan \
  --host 0.0.0.0 --token "$OPENGATEWAY_AUTH_TOKEN" \
  --public-url "http://$(ipconfig getifaddr en0):8765"

Badge: LAN. Paste the token in Live Ops Settings.


Tailscale Serve and Funnel

Prefer Serve over exposing a raw Tailscale IP. Many hosts firewall the utun interface, so http://100.x.x.x:8765 times out even when LAN works.

opengateways serve --mode serve --token "$OPENGATEWAY_AUTH_TOKEN"
tailscale serve --bg 8765
opengateways serve --mode funnel --token "$OPENGATEWAY_AUTH_TOKEN"
tailscale funnel --bg 8765

Full dual-path and Docker notes: Tailscale.

Clients:

Authorization: Bearer <OPENGATEWAY_AUTH_TOKEN>

SSE cannot set headers easily. Use ?token= on the events URL, or paste the token in Settings.


Useful env vars

Variable Meaning
OPENGATEWAY_MODE internal or public
OPENGATEWAY_HOST / OPENGATEWAY_PORT Bind (default port 8765)
OPENGATEWAY_AUTH_TOKEN Bearer secret
OPENGATEWAY_PUBLIC_URL Advertised base URL
OPENGATEWAY_NETWORK tailscale, lan, or public
OPENGATEWAY_TAILSCALE_HOSTNAME MagicDNS override (Docker)
OPENGATEWAY_CORS_ORIGINS Default *

Registry: GET/POST /v1/gateways, DELETE /v1/gateways/{id} for non-self cards.

Diagnose: opengateways doctor and GET /v1/network.

Canonical: docs/GATEWAYS.md.

Clone this wiki locally