First boot
No desktop, no console. The Machine comes up on the LAN and a browser on the same network does the rest. Cable in, power on, wait about a minute.
Find it
Every Machine answers http://pipeos.local/. With more than one on the LAN, that address is the lobby: every Machine serves the same list, with each one's name, claimed or not, its boot verdict and a link. A lone unclaimed Machine opens its wizard directly; /lobby shows the list regardless.
Before it is claimed a Machine is pipeos-xxxx.local, xxxx being the last four hex characters of its network card's address: its chassis id, kept for life. If .local names do not resolve on your device, see networking.
Claim it
The first visitor claims the Machine by setting an admin password. Whoever sets it owns the box; do this before anything else. The claim is written to the media immediately and survives a reboot even if you stop here. The same password signs you in to the dashboard and is the lockout escape: if every other account is lost, it still signs in as the admin.
The recovery phrase
Right after the claim the Machine shows its recovery phrase: eight groups of four characters, shown once. Write it down. The Machine's secrets live in a vault sealed to this chassis; in a different box the vault is locked until the phrase is typed. It is stored nowhere on the box, and there is no other way in. See secrets.
Join this cluster?
If the lobby shows a Machine in a cluster, the wizard offers Join this cluster? with the members listed. Pick one and type that Machine's admin password; neither password crosses between boxes. Not now continues to the name step; joining later, or adopting from a member's dashboard, is on the cluster.
Name it
The name is an alias on top of the chassis id: corvette.local and pipeos-a4e0.local answer the same box, and renaming never changes the id. The wizard suggests five classic-car names, skipping any already in the lobby; a name a sibling uses, or that already answers on the LAN, is refused. Optionally give your pipe nick as owner; the owner gets the boot report by DM when pipe is on.
Pick what it does
One switch per service; what is on here starts at every boot, and every switch can be changed later under Services.
| Claude assistant | on by default. Claude, or Hermes, chosen under Assistant |
| Assistant terminal | off. A browser terminal into the assistant's session, behind its own password |
| Streaming | off. Restream video to up to four providers |
| pipe messaging | off. Talk to the box by DM from anywhere |
| Vendor support access | off. Lets your vendor connect, only while you leave it on |
| Network storage | off. Share folders over SMB; set up under Files |
Connect Claude
Press Sign in with Claude. The Machine shows a link; open it on any device, sign in, and paste back the code the page shows. The fallback is a field for an Anthropic Console API key or a token from claude setup-token; the assistant explains the difference.
If pipe messaging is on, the wizard asks for a one-time key from the nicks page of your pipe account. It works once and expires in fifteen minutes. The Machine's nick is read back from pipe, never typed.
After the wizard
The same address is the dashboard; sign in with the password you set. Every step can be revisited under Setup and Services.
The way back is pipeos unclaim, as root: it drops the claim, users, name and owner, the sign-ins, cluster membership, shares, schedule, vault and the agent's memory, and reboots into this wizard at pipeos-xxxx.local. /data/home and /data/repos stay. It asks you to type the hostname first.
Next
The dashboard: every view, and what each one controls.