OpenAPI ↗

HOSTING

Fleet administration

Observe workers, applications, network health and staff permissions.

Implemented · Initial owner setup and physical-worker evidence required

Operations dashboard

Open fleet administration for worker health, RAM tiers, host qualification, application review, revenue attribution and audit records. Users and payments uses the same account system. Initial owner setup uses a private, expiring invitation issued by the server operator. Choose an admin password and enroll an authenticator; the company enrollment password is not an admin password.

The owner can grant existing accounts a network administrator or network observer role. New staff require operator-assisted MFA enrollment before login. Network administrators manage enrollment and reporting; network observers inspect health. Neither role grants customer payment access. Role changes revoke old credentials.

Agent monitoring

An owner can create a 30-day fleet:read observer key. It reads /api/v1/fleet without receiving host applicants' contact details, customer payments or credentials. It cannot issue payouts, run commands, approve applications or change workers. No unattended monitoring agent or alert-delivery service is implied by creating a key.

Reading health correctly

A recent heartbeat proves the reporting client reached the API. The dashboard separately shows missing heartbeats, high CPU, low free memory/disk, failed DNS/HTTPS probes and a gateway that did not answer ICMP. ICMP can be blocked on an otherwise working gateway. None of these measurements alone proves desktop control or tenant isolation.

Company and partner workers remain outside saleable inventory until operator/controller checks connect them to verified inventory. Revoke reporting to invalidate a worker credential and withdraw any free inventory associated with it. Revocation does not power off the machine or remove an active customer's files.

Data and access

Worker telemetry contains hardware and network metadata, never arbitrary uploaded files. The client accepts no remote command payloads. The server retains seven days of sample history and current host metadata; account and financial records have separate retention needs. Restored backups revoke worker, pairing, observer, owner-invitation and account credentials and put operations on recovery hold.