Sign in with an operator API key. Access is also limited by the proxy
operator_ip_allowlist when configured.
Remote Control
Live off
Status
Name / ID
Client
Host
User
Version
Cert
OS
Uptime
Remote IP
Connected
Last seen
No agents match.
Time
Operator
IP
Action
Agent
Status
Command / detail
No audit events.
Live
Agent
Client
Score
Compliance
Missing
Sec
Installed
Fails (30d)
Oldest debt
Last install
Reboot
Last scan
No patch inventory reported yet.
Live
Host
Manufacturer
Model
Serial
CPU
RAM
Disk
Software #
Collected
No host inventory reported yet (agents need a build that collects it).
Version
Channel
Platform
Size
SHA-256
Published
By
ID
Actions
No releases published.
Create deploy link
CapAdmin only. Install one-liners stay available on this list after create (copy anytime).
Link created — copy now
Token is not stored in recoverable form. Revoke the link if it leaks.
ID
Binary URL
Install script
One-liner
Install one-liners include the path token and can be copied anytime (revoke/delete to disable a link).
Platforms
Status
Client
Label
Platform
Channel / mode
Install one-liner
Uses
Created
Actions
No install links.
This is the signed command allowlist the agent trusts (A3 Ed25519
opk_* public keys from operators.v1.json),
not proxy Bearer API keys. Bearer keys (name, caps, fingerprint — never the secret)
are listed in Proxy API keys below. The UI shows the proxy’s
verified in-memory copy — the browser does not fetch the allowlist URL
(it 403s/CORS and would skip signature verify). Changing who is allowed still requires
rc-optrust sign-allowlist + publish. Labels are a local overlay only and
do not change what agents trust.
Source
Seq
Issued
Expires
Verified
Label
key_id
Allowlist name
public_key
Actions
Clients
Roles
Revoked
No operators on the verified allowlist.
Proxy API keys
Proxy Bearer operators (separate from A3 signing keys).
Config keys come from deploy/gce/.secrets.env + operators: YAML
(source: config) — edit YAML and redeploy to change them.
UI keys live in proxy sqlite under data_dir (source: ui);
a volume wipe drops UI keys, YAML keys remain. The secret is shown
once at create and is never listed again.
CapAdmin can edit a live UI key’s caps and client scope without rotating
the secret — keep pasting the same key.
CapAdmin is required to list or mint proxy API keys.
Create proxy API key
CapAdmin only. Copy the secret from the dialog — it will not be shown again.
Edit proxy API key
Changing capabilities does not rotate the key; keep pasting the same secret.
Name
Caps
Source
Fingerprint
Scopes
Revoked
Actions
No proxy API keys.
About this table
API key created — copy now
This secret will not be shown again. Store it like a production operator key.