First boot

No desktop, no console. The Machine comes up on the LAN and a browser on the same network does the rest. Cable in, power on, wait about a minute.

Find it

Every Machine answers http://pipeos.local/. With more than one on the LAN, that address is the lobby: every Machine serves the same list, with each one's name, claimed or not, its boot verdict and a link. A lone unclaimed Machine opens its wizard directly; /lobby shows the list regardless.

Before it is claimed a Machine is pipeos-xxxx.local, xxxx being the last four hex characters of its network card's address: its chassis id, kept for life. If .local names do not resolve on your device, see networking.

Claim it

The first visitor claims the Machine by setting an admin password. Whoever sets it owns the box; do this before anything else. The claim is written to the media immediately and survives a reboot even if you stop here. The same password signs you in to the dashboard and is the lockout escape: if every other account is lost, it still signs in as the admin.

The recovery phrase

Right after the claim the Machine shows its recovery phrase: eight groups of four characters, shown once. Write it down. The Machine's secrets live in a vault sealed to this chassis; in a different box the vault is locked until the phrase is typed. It is stored nowhere on the box, and there is no other way in. See secrets.

Join this cluster?

If the lobby shows a Machine in a cluster, the wizard offers Join this cluster? with the members listed. Pick one and type that Machine's admin password; neither password crosses between boxes. Not now continues to the name step; joining later, or adopting from a member's dashboard, is on the cluster.

Name it

The name is an alias on top of the chassis id: corvette.local and pipeos-a4e0.local answer the same box, and renaming never changes the id. The wizard suggests five classic-car names, skipping any already in the lobby; a name a sibling uses, or that already answers on the LAN, is refused. Optionally give your pipe nick as owner; the owner gets the boot report by DM when pipe is on.

Pick what it does

One switch per service; what is on here starts at every boot, and every switch can be changed later under Services.

Claude assistanton by default. Claude, or Hermes, chosen under Assistant
Assistant terminaloff. A browser terminal into the assistant's session, behind its own password
Streamingoff. Restream video to up to four providers
pipe messagingoff. Talk to the box by DM from anywhere
Vendor support accessoff. Lets your vendor connect, only while you leave it on
Network storageoff. Share folders over SMB; set up under Files

Connect Claude

Press Sign in with Claude. The Machine shows a link; open it on any device, sign in, and paste back the code the page shows. The fallback is a field for an Anthropic Console API key or a token from claude setup-token; the assistant explains the difference.

If pipe messaging is on, the wizard asks for a one-time key from the nicks page of your pipe account. It works once and expires in fifteen minutes. The Machine's nick is read back from pipe, never typed.

After the wizard

The same address is the dashboard; sign in with the password you set. Every step can be revisited under Setup and Services.

The way back is pipeos unclaim, as root: it drops the claim, users, name and owner, the sign-ins, cluster membership, shares, schedule, vault and the agent's memory, and reboots into this wizard at pipeos-xxxx.local. /data/home and /data/repos stay. It asks you to type the hostname first.

Next

The dashboard: every view, and what each one controls.