Getting started
This describes the path as it works on 2026-09-05. Each step names the screen that performs it. Where a step has a shipped screen but an outcome that depends on something else, this page says so instead of predicting the outcome.
1. Subscribe
Pick the plan on Pricing and pay. Payment goes through Stripe Checkout; the account you pay with is the account the box belongs to.
2. Open your account and start configuration
After payment, your account shows a pending configuration card. Following it opens the configuration screen for that payment.
3. Give the box its keys
The configuration screen asks for four things and nothing else: a model provider, a model, your own model API key, and a Telegram bot token. There are no server, SSH or network fields on it — those are not yours to set, because the box is built to a fixed shape. Read Bring your own keys before you paste a key.
Submitting the form is the request that claims a box for you. Your account then shows the box and its state.
4. Read a System before you install it
The Systems catalog lists what you can install. Opening one shows the System's whole manifest and the sha256 digest of its content, together, above the install control — a manifest without its digest is a claim with nothing binding it to the content that was vetted. The egress allowlist inside that manifest is the set of hosts the System asked to reach.
A System that failed vetting is not in the catalog, and the catalog answers “not found” for it exactly as it does for one that was never submitted. One refused System is published anyway, with its reason, on How confinement works.
5. Install
The install control sits below the manifest and the digest, so it cannot be reached without the wall it consents to having been rendered above it. Pressing it records your consent to that digest and creates the install request. The screen then tells you what is true at that moment: the request exists, your server has not changed, and if the install completes the System will appear on it.
The box-side half of an install runs only when provisioning actions are switched on for the environment. They are off by default, and a switch that is off refuses rather than queues silently.
Not shipped yet
These are described so that this page is not read as covering them. None of them is available today.
- A single guided onboarding flow that replaces steps 2 and 3. Today those are two screens, and the account card is the link between them.
- Messages sent to you about any of the steps above. The lifecycle messages are written but the sending domain is not configured, so nothing is sent.
- An end-to-end approval on a real box. See Approvals for exactly which part of that is wired and which part has never run.
Copy status and the documents it was written against: About this copy.