Start the agent.
Prove the boundary.

Four commands start Oktapod, show its private Control UI, and verify that public pages do not expose private tools.

Install./scripts/install.sh
Onboardoktapod onboard
Startoktapod up
Verifyoktapod readiness

Landing and docs are public. Tool access is not.

PublicLanding + docs

Product information, setup, operations, and recovery guidance.

PrivateControl UI

Served by Oktapod behind the configured access key.

Not exposedNo public API site

The gateway remains an authenticated private control-plane boundary.

Run this before calling the web surfaces ready.

Landing, docs, update guide, and private Control UI verified together.