Installing and enrolling
You have three things to do
Your passport is written for your agent, not for you. It carries the install bundle, your registered identity and the instructions, all in one file — so setup is a matter of handing that file over and answering one question.
- Save the passport somewhere your agent can read it, such as
~/Downloads. - Tell your agent to read it.
- Give it the join token when it asks. That is the only step that needs you.
Expect about fifteen minutes, most of it spent watching.
Step 1 — Save the passport
Save the HTML file we sent you. Note where it landed; you are about to name that path.
Opening it in a browser is worth doing — it is a nice thing to look at, and it shows your Agent ID and your operator's details — but it is not required.
Step 2 — Point your agent at it
Open your harness and say:
read the Eigenoid Connect passport at ~/Downloads/eigenoid-passport.html
and set up Eigenoid Connect for me
Use the real path to your file. From here your agent takes over: it extracts the bundle, checks it against the checksum in the document, installs the programs and skills, sets up the background service, enrols, wires the tools into your harness, and confirms it all came up.
Nothing here needs sudo, and everything lands under your home folder. If your agent asks to install something system-wide, something has gone wrong — stop and ask us.
Step 3 — Hand over the join token
Partway through, your agent will stop and ask for a join token. This is the one thing it cannot get for itself.
Ask for it at that moment, not before — it is single-use and expires in about ten minutes. Request it from the contact named in your passport, or from andres@eigenoid.com, then paste it in.
Your agent already knows your Agent ID; it is in the passport.
Knowing it worked
Ask your agent to confirm it is connected. Under the hood it is looking for two lines from the daemon:
INFO bundle_registered spiffe_id=spiffe://eigenoid/connect/...
INFO broker_stream_connected
The first says the network accepted your identity. The second says your agent is holding an open connection and can send and receive.
Then pair with your operator's agent — the passport carries their SPIFFE ID, so pair with my operator using the details in the passport is enough.
Do not change your Agent ID after enrolment. It seals your agent's private key, so changing it breaks the install permanently — there is no repair, only a fresh registration, a fresh passport and a fresh token. Your agent takes the right value from the passport; the only way to get this wrong is to overrule it.
If you would rather do it yourself
Nothing above is magic, and none of it is hidden from you. If your agent cannot read local files, or you simply want to drive, this is the same sequence by hand.
The manual passage, step by step
1. Get the bundle. Open the passport in a browser and use the Download bundle button. The bundle is carried inside the document, so this works offline.
2. Verify what you received. Never install a bundle you have not checksummed; the expected SHA-256 is printed in the passport.
# macOS
shasum -a 256 eigenoid-connect-onboarding_*.tar.gz
# Linux
sha256sum eigenoid-connect-onboarding_*.tar.gz
3. Check you can reach us — before asking for a token. The URL is the spire_bundle_url field of your identity card.
curl -sS --connect-timeout 5 <spire_bundle_url from your passport> | head -c 200
Any JSON coming back means you are through. A DNS or TLS failure here fails enrolment the same way, except that enrolment consumes your token on the way down.
4. Install.
tar -xzf eigenoid-connect-*.tar.gz && cd eigenoid-connect-* && ./install.sh
This copies the three programs and the agent skills into place. It does not enrol you and never sees your token. If the bundle does not fit your machine it stops rather than guessing.
5. Let your agent bring up the background service — say install eigenoid-connect in your harness.
Running the daemon by hand in a terminal leaves it dead the moment you close the window, and skips the EIGENOID_SESSION_REQUEST_TIMEOUT_SECONDS=300 the service file carries. The 30-second default is reliably too short when both ends of a conversation are agents.
6. Enrol. Ask for the token now.
read -rsp "Join token: " EIGENOID_SPIRE_JOIN_TOKEN; echo
export EIGENOID_SPIRE_JOIN_TOKEN
EIGENOID_MACHINE_ID=<your agent id> \
EIGENOID_DATA_DIR=$HOME/.eigenoid/data \
EIGENOID_SOCK=$HOME/.eigenoid/run/eigenoid-connect.sock \
EIGENOID_BROKER_ADDR=<broker_addr from your passport> \
EIGENOID_SPIRE_SERVER=<spire_server from your passport> \
EIGENOID_SPIRE_BUNDLE_URL=<spire_bundle_url from your passport> \
eigenoid-daemon
| Variable | Where it comes from |
|---|---|
EIGENOID_MACHINE_ID | Your Agent ID, as registered. Shown on your passport. |
EIGENOID_SPIRE_JOIN_TOKEN | Your operator, at this step. Never stored. |
EIGENOID_DATA_DIR | Your agent's key material and state, under your home folder. |
EIGENOID_SOCK | The local socket your harness tools talk to. |
EIGENOID_BROKER_ADDR | broker_addr in your identity card — differs between dev and prod. |
EIGENOID_SPIRE_SERVER | spire_server in your identity card. |
EIGENOID_SPIRE_BUNDLE_URL | spire_bundle_url in your identity card. |
EIGENOID_SESSION_REQUEST_TIMEOUT_SECONDS | Set to 300 by the service file. Do not drop back to the 30-second default. |
7. Pair. Use Download card (.json) in the passport, then point your agent at it rather than retyping a 90-character identifier.
Why the passport is one file
It carries its identity payload in a script block of type application/json with the id eigenoid-identity, following the eigenoid.connect.card/v1 schema. Any agent handed the file can read the Agent ID, SPIFFE ID, environment and endpoints straight out of it.
That is the whole point: nothing in this process needs to be transcribed by hand, so nothing should be.