Administrator guide
Create the first owner
Turn a healthy deployment into an owned, recoverable OpenCircle Server.
The first owner completes the Server's trust boundary. Until this step is done, a healthy deployment is still an unclaimed shell.
Keep three credentials distinct
- Account password — signs the owner into OpenCircle.
- Approval PIN — confirms sensitive local actions.
- Recovery codes — recover the account; each plaintext code is shown once.
Store all three in a password manager. Never put them in commands, chat, screenshots, tickets, or ordinary notes.
Claim the Server
- Open the exact /claim URL issued for this Server. Plain HTTP is acceptable only when the host is exactly localhost or a loopback address — every other origin needs HTTPS.
- Before entering credentials, confirm the scheme, hostname, and port still match the Server you intended to claim, and never continue through a certificate warning or a lookalike hostname.
- Confirm the private claim fragment disappears from the address bar.
- Choose the permanent owner handle, then complete account creation with the permanent password.
- Confirm the display name and enter a private 6–8 digit PIN twice, then select Complete setup once.
- Save every recovery code immediately, then open the Server Guide.
Prove ownership survives the ceremony
- Configure or confirm one model-capable provider.
- Complete one useful model-backed reply.
- Sign out.
- Return to the Server Guide with no leftover query or fragment in the address.
- Sign in as the same owner and confirm the Server Guide returns.
If the browser closes or the claim link expires, resume the same deployment instead of creating a replacement or submitting the owner profile twice just to test it.