- Check the prerequisites.
- Run the installer.
- Sign in to Web.
- Configure the domain and HTTPS.
- Set a default model.
- Issue a Project API key.
- Add sandbox capacity.
Prerequisites
- Linux amd64 with Python 3.9 or newer, and curl. No GitHub account or CLI is needed.
- Docker Engine with Docker Compose 2.26.0 or newer (
docker compose version). - An account that can run
dockerand write to its home directory. Ordinary users and root both work; the installer never calls sudo. - A free port each for initial Web access (8080) and Core (8091, on loopback), and free ports 80 and 443 once you turn on HTTPS; see ports. Docker must be able to publish them; the installer does not change host policy.
- A DNS hostname that points to this host, before you connect applications, nodes, E2B or self-hosted machines. You can install and sign in first.
Install
- checks its settings and the ports it needs, then the host, and loads the Core, Web, PostgreSQL and HTTPS gateway images;
- creates the installation directory,
~/.oac/core, with the Core key,config.jsonand theoacmanagement command; - starts the services with Docker Compose. The gateway serves Web on all IPv4 interfaces, at the port the installer prints; Core stays on loopback and PostgreSQL stays private;
- selects the microsandbox sandbox backend at the Standard size. It adds no node.
Sign in to Web
-
Open the console address the installer printed, such as
http://SERVER_IP:8080, or your public URL if you passed one. Behind NAT, use the IP address your browser reaches. Until a domain is set, Web accepts IP addresses only, not host names. -
Sign in with the Core key, the installation’s administrator credential. Web has no user accounts.
Configure the domain and HTTPS
Applications, nodes and sandboxes reach Core at one HTTPS address, the public URL. The initial HTTP address serves only Web.- Point the hostname’s A/AAAA records to this host, allow inbound ports 80 and 443 from the internet, and keep other programs off those ports.
- In Web, open System, choose Configure domain and HTTPS, enter the hostname, such as
core.example.com, and choose Apply.
oac status and finish it with oac apply.
The same operation from a terminal:
Set a default model
Core-hosted Sessions without their own model provider use their harness’s default model. On System, under Default model configuration, find the harness marked Default (Codex unless you changedcore.default_harness) and choose Set. Enter the model ID, the protocol, and the provider’s base URL and API key. MiniMax Code also needs the context window and max output tokens. See default models.
Issue a Project API key
- On Projects and keys, choose Create project, then Issue key. The dialog shows the key once: copy it and keep it safe. Its How to call card shows the API base URL and sample requests.
- Give the key and the API base URL to the application developer. They continue with the quickstart.
Add sandbox capacity
Sessions need somewhere to run:- Nodes run the microsandbox backend the installer selected: add a node from Web’s Nodes page. Docker nodes need
--sandbox dockerat installation, or a reset to change the backend. - E2B, which needs no nodes: change the sandbox configuration in Web, or choose it during installation.