Remote access
The stack listens on loopback and does not authenticate: whoever reaches the port is the operator. To use it from another machine, put your own gate in front and tell the orchestrator the name it is reached by:
PUBLIC_BASE_URL=https://<the name people open>The orchestrator serves a request only for a loopback host or that one. A state-changing request or a WebSocket handshake that carries an Origin is served only when that origin is the host the request names, the origin of PUBLIC_BASE_URL, or a loopback origin to a loopback host; a request with no Origin is not a browser's and passes (Security register, SEC-15).
Connector sign-ins return to <PUBLIC_BASE_URL>/api/mcp/oauth/callback; register that URI on the OAuth client or GitHub App you set in .env (Tools and connectors). The provider does not need a path to the box, only the operator's browser does.
A tailnet
With Tailscale on the machine and on your devices, tailscale serve --bg localhost:8080 publishes the app at https://<machine>.<tailnet>.ts.net to the tailnet's members and to no one else. Keep Funnel off. Membership of the tailnet is the gate, and everyone it lets through acts as the same operator.
An authenticating proxy
AUTH_MODE=trusted-header takes each person's identity from the proxy instead. The proxy authenticates them, then sends their email in a header (TRUSTED_HEADER_EMAIL, default X-Forwarded-Email) and a shared secret in X-Guilds-Proxy-Secret (TRUSTED_PROXY_SECRET); a request without the secret is 401. The mode needs three more lines in .env and does not start without them: PUBLIC_BASE_URL, the secret, and OPERATOR_EMAIL, the address the proxy sends for you, which boot gives the box's first user. Boot refuses to start when another user already holds that address.
An email that belongs to no user is 401, so the proxy letting someone through is not enough: you give each other person an account by their email. The app has no screen for it; it is one request through the proxy, signed in as you:
POST /api/users {"name": "ada", "email": "ada@example.com"}The request creates the user and a personal organisation they own. PATCH /api/users/<id> with {"email": …} changes a user's address, and null takes it away; DELETE /api/users/<id> removes them. In this mode the user directory answers the instance administrator, an owner of the organisation Home, and is 404 to anyone else (Users and organisations).