Getting started
Create an account, verify its email address, create the organization, enroll one Ubuntu 24.04 gateway, create a VPN user and device, then issue the first single-use profile.
DOCUMENTATION
Documentation follows the actual system boundaries and avoids steps for products or client applications that do not exist.
Create an account, verify its email address, create the organization, enroll one Ubuntu 24.04 gateway, create a VPN user and device, then issue the first single-use profile.
Create the intended server record first. Run the reviewed node installer with its short-lived one-use registration token, unique VPN subnet, management CIDR, and node-specific mutual-TLS identity. Verify the agent, helper, firewall, OpenVPN, and heartbeat before issuing access.
Use a VPN identity separate from SaaS accounts. Set expiry, device, concurrent-session, bandwidth, and server-access limits before sharing credentials through an approved channel.
Install a maintained OpenVPN-compatible client, download the profile once from the device record, import it locally, and enter the separate VPN username and password when prompted.
Install OpenVPN from the maintained distribution repository, keep the downloaded profile owner-readable only, and connect using the distribution's supported OpenVPN service or command-line workflow.
Install a maintained OpenVPN-compatible client from the official platform store and import the device-specific profile. Do not copy one device's profile to another device.
Review tenant isolation, SaaS authentication, device PKI, node mutual TLS, signed commands, profile encryption, audit retention, and the documented residual risks before production use.
Check node heartbeat, server access, user and device state, credential expiry or revocation, capacity and concurrent-session limits, then correlate the request, audit, command, and session identifiers without exposing secrets in logs.
Create a scoped API key only for the operations an integration needs. The raw key is displayed once; store it in a secret manager, set an expiry, monitor last use, and revoke it immediately if exposed.
READY TO EVALUATE?