Sign in with an operator API key. Access is also limited by the proxy
operator_ip_allowlist when configured.
Remote Control
Live off
Name is the operator-assigned registry label (set at enroll/bootstrap; editable).
Host / User / Version / OS / IP come from the live tunnel when online, otherwise the
last values the proxy stored (so offline agents still show what they were).
User is the interactive / console (or RDP) login — not the agent service account.
Multi-session hosts show primary user plus +N; hover for the full list.
When live, user idle is keyboard/mouse silence in that Windows session.
Realtime agents report active immediately on input, and only show idle after a proxy-configured threshold (default 1m of silence).
Idle duration is shown to the minute (not seconds) and live ticks update only that row so text selection elsewhere in the table is kept.
OS may also show host uptime since last reboot (e.g. up 3d 4h) — machine uptime, not agent process age.
Last seen updates on connect, hello, and ~1m heartbeats while online.
Status
Name / ID
Client
Role
Host
User
Version
Cert
OS
Remote IP
Connected
Last seen
No agents match.
Score is a quick health grade (0–100 / A–F) from missing updates, reboot-needed,
security debt, age of the oldest pending update (proxy first seen), and
hard install failures in the last 30 days only (aborted/older history do not score).
Missing is applicable/not-yet-installed inventory.
Installed is successful installs in the agent history window (not lifetime).
Last install is the newest successful history date.
Click a row to open missing KBs + recent history beside the list (or in a modal on a narrow window). CapRead only — force scan via CLI.
Live
Agent
Client
Role
Score
Compliance
Missing
Sec
Installed
Fails (30d)
Oldest debt
Last install
Reboot
Last scan
No patch inventory reported yet.
Version
Channel
Platform
Size
SHA-256
Published
By
ID
Actions
No releases published.
Create deploy link
CapAdmin only. Install one-liners stay available on this list after create (copy anytime).
Link created — copy now
Token is not stored in recoverable form. Revoke the link if it leaks.
ID
Binary URL
Install script
One-liner
Install one-liners include the path token and can be copied anytime (revoke/delete to disable a link).
Status
Client
Label
Platform
Channel / mode
Install one-liner
Uses
Created
Actions
No install links.
This is the signed command allowlist the agent trusts (A3 Ed25519
opk_* public keys from operators.v1.json),
not proxy Bearer API keys. Bearer keys (name, caps, fingerprint — never the secret)
are listed in Proxy API keys below. The UI shows the proxy’s
verified in-memory copy — the browser does not fetch the allowlist URL
(it 403s/CORS and would skip signature verify). Changing who is allowed still requires
rc-optrust sign-allowlist + publish. Labels are a local overlay only and
do not change what agents trust.
Source
Seq
Issued
Expires
Verified
Label
key_id
Allowlist name
public_key
Actions
Clients
Roles
Revoked
No operators on the verified allowlist.
Proxy API keys
Proxy Bearer operators (separate from A3 signing keys).
Config keys come from deploy/gce/.secrets.env + operators: YAML
(source: config) — edit YAML and redeploy to change them.
UI keys live in proxy sqlite under data_dir (source: ui);
a volume wipe drops UI keys, YAML keys remain. The secret is shown
once at create and is never listed again.
CapAdmin is required to list or mint proxy API keys.
Create proxy API key
CapAdmin only. Copy the secret from the dialog — it will not be shown again.
Name
Caps
Source
Fingerprint
Scopes
Revoked
Actions
No proxy API keys.
API key created — copy now
This secret will not be shown again. Store it like a production operator key.