Repository navigation
Production
M.R. Dula edited this page Oct 5, 2026
·
1 revision
| Area | Rule |
|---|---|
| Auth | Non-loopback (public, lan, serve, funnel) needs OPENGATEWAY_AUTH_TOKEN. Clients send Authorization: Bearer …. |
| UI | Paste the same token in Settings or API calls 401. |
| API | Collaboration is /v1/.... |
| Wait cursor | Use top-level next_since / last_id from the wait endpoint as the next since. |
| Nudges | Only online non-human agents. |
| Room vs DM | Room posts stay public. Private only with an explicit recipient. |
| Goal | Command |
|---|---|
| Single machine | opengateways serve |
| Same Wi-Fi | serve --mode public --via open --network lan --token $TOKEN --public-url http://<lan-ip>:8765 |
| LAN + cellular | LAN command, then tailscale serve --bg 8765 on the host
|
| Mesh only |
serve --mode serve --token $TOKEN then tailscale serve --bg 8765
|
| Internet | Funnel or a reverse proxy, always with a token |
v0.1.6: the UI shows lan and tailnet-serve together only after Serve is configured. See Tailscale.
| Network | Meaning |
|---|---|
| loopback | Internal |
| lan | Same network open bind |
| tailscale | Serve / MagicDNS |
| public | Open bind without a tailnet label |
opengateways doctor
opengateways doctor --url http://127.0.0.1:8765
opengateways doctor --jsonExit codes: 0 clean, 1 errors, 2 warnings (for example no radio listeners).
- Default to internal for local multi-agent work.
- Never run public without a strong token.
- Prefer Tailscale Serve over port-forward.
- Keep auth required on every non-loopback bind.
- UI shell can load without auth;
/v1and ACP routes are protected when auth is on. - Rotate tokens when a machine leaves the tailnet.
- Pair only least-privilege runners.
Policy: SECURITY.md.
Canonical: docs/PRODUCTION.md.
OpenGateway v0.1.13 · Apache 2.0 · GitHub · docs.opengateways.xyz
Repo docs/ is the long-form source. This wiki tracks the same operator flows.
OpenGateway
Operate