Systems
Enrolled remote desktops. Install only the host — everything else is here.
Team
Users, roles, and live messaging.
Access grants
Decide which devices each person can reach. Changes apply live.
As a Manager you handle access grants only. You can grant or revoke device access for people on your team — you can't invite users, change roles, set device passwords, or revoke systems.
My devices
The systems your administrator granted you access to. Pick one and connect.
No active session
Pick an online device above, or enter a device ID — your granted devices unseal automatically.
Wire a host
Generate one-time credentials and enrol a Windows machine as a remote host.
Enrolling a host requires an owner, admin, or host-operator account. Ask a Network Admin on your team to wire this machine, or to grant your account host access.
Give the machine a label, then generate its one-time wiring credentials. You'll paste them into the host installer's first-run wizard — no sign-in happens on the machine.
Enter these two values in the host installer's first-run wizard on the target machine.
- Download & run the neekOS Host installer on the target machine.
- In the first-run wizard, paste the Device ID and Enrolment token above.
- Set a permanent host password (used to authorize remote sessions).
- The host appears Online below once it connects.
Your hosts
Watch a wired machine flip to Online here.
Tutorials
Step-by-step walkthroughs for every seat. Pick your persona.
The written guide below covers every step.
Quick start
- Create your team (day 0) with the relay admin token.
- Add a System — you get a Device ID and a one-time enrolment token.
- Run neekOS-Host-Setup.exe on the target machine and paste both values.
- Set the device password in the console.
- Invite your people and pick their roles.
- Grant devices — sealing happens automatically.
- Connect from Remote control.
1 · Create your team (day 0)
- Open the portal and click Sign in, then switch to the Create team tab.
- Paste the relay admin token — you'll find it in apps/relay/.env on the relay host.
- Enter a team name, your name and email, and a password (≥ 12 chars).
- Accept the Terms & Conditions and click Create team & sign in. You are now the owner — the Network Admin.
2 · Add a System
- Go to Systems and click + Add a System.
- Give the machine a label (you can rename it later).
- The console shows a Device ID and a one-time enrolment token. The token is single-use — treat it like a password.
3 · Install the host on the target machine
- On the target Windows machine, run neekOS-Host-Setup.exe.
- In the first-run wizard, paste the Device ID and the enrolment token.
- Set the machine's permanent host password — it stays on the machine and is used to approve sessions.
- That's it. The host auto-registers and appears Online in Systems under its real machine name. No account sign-in ever happens on the machine.
4 · Set the device password in the console
- In Systems, open the system's Password action and enter the host password you set in the wizard.
- The password is sealed in your browser to each granted user's key — the relay only ever stores ciphertext, so granted users connect with one click and nothing to type.
5 · Invite people
- Go to Team and click + Invite user.
- Password flow: the console gives you an invite code and a temporary password — hand both over out-of-band (in person, phone, your own chat).
- Google flow: provision their email address; they just click Continue with Google on the portal. SSO authenticates — your provisioning authorises.
- admin full console — systems, team, grants, passwords.
- manager access grants only.
- operator connects to and drives granted devices.
- viewer watches granted devices — no input.
- host wires machines only — no remote control.
- auditor reads the full audit trail — no control.
6 · Grant devices
- In Team, open a user's Access action.
- Tick the devices they should reach and save. Granting a device auto-seals its password to that user in your browser.
7 · Connect
- Open Remote control, pick an online device, and click Connect.
- Video arrives over DTLS-SRTP; your input goes up the sealed channel. Fullscreen and end-session controls sit in the stage bar.
8 · Operate day-to-day
- 📣 Announce broadcasts to everyone signed in.
- Use a user's Message action for a direct message, and Sign out to force-end their session.
- Rename or revoke systems from their cards in Systems. Revoking a device force-ends any in-flight session to it.
Troubleshooting
- Host shows offline. The machine is off, the installer hasn't been run yet, or the enrolment token was already used — tokens are single-use; add a fresh System to re-issue.
- Google user gets "not provisioned". You must add their email in Team first. Google only proves identity — access exists once you provision it.
- Relay pill is red. The console can't reach your relay — check the relay service and the relayUrl in the portal config.
The written guide below covers every step.
Quick start
- Sign in at the portal — your console opens on Access grants.
- Pick a user from the list.
- Check or uncheck the devices they should reach.
- Click Save access — changes apply live.
What the Manager role is
A Manager handles access grants only. You decide which people can reach which devices — the admin keeps everything else: people, roles, passwords, and the systems themselves.
Granting and revoking
- Open the Access grants tab.
- Pick a user — their current device grants are shown as checkboxes.
- Check devices to grant, uncheck to revoke, then click Save access.
- Changes apply live: if someone is mid-session on a device you just removed, that session is force-ended immediately.
What you can't do
- Invite or remove users.
- Change anyone's role.
- Set or change device passwords.
- Add, rename, or revoke systems.
If a task needs any of those, hand it to a Network Admin.
Connecting yourself
Managers can also be granted devices, just like users. Anything granted to you appears under My devices — click Connect and work exactly as a user would.
Troubleshooting
- A person isn't in the list. Only invited team members appear — ask an admin to invite them first.
- A device is missing. It may have been revoked by an admin or never enrolled — device inventory is admin-owned.
- Save fails. Check the relay pill in the top bar; if it's red the console can't reach the relay.
The written guide below covers every step.
Quick start
- First sign-in: email + the temporary password from your admin, then the invite code when prompted.
- Choose a permanent password (≥ 12 chars) — or use Continue with Google if your admin provisioned your email.
- Open My devices — you see only what you've been granted.
- Click Connect. Nothing to type — your browser unseals the device password for you.
First sign-in
- Password flow: sign in with your email and the temporary password your admin handed you. The portal then asks for your invite code (format 123-456-789).
- Choose your permanent password — at least 12 characters.
- Google flow: if your admin provisioned your Google email, skip all of the above and just click Continue with Google.
My devices
My devices lists only the machines your admin granted you, by their real machine names. If a machine isn't listed, you don't have access — that's by design.
Connecting
- Click Connect on a device card (or pick it from the quick-pick list in Remote control).
- Your browser unseals the device password automatically — there is nothing to type.
- If you are asked for a host password, your admin hasn't set one in the console yet — type it if you know it, or ask your admin to set it.
- Reopened the tab? Unlock device access asks for your account password once — it re-derives your keys locally, and the relay never sees it.
In the session
- Hover the stage to reveal the session bar: Fullscreen and End session.
- A view-only badge means your role can watch this device but not drive it.
Troubleshooting
- Device greyed out. The host is offline or still awaiting enrolment — ask whoever wired it to check the machine.
- "No access yet." Your admin hasn't granted you any devices. Only an admin or manager can change that.
- Unlock keeps failing. That prompt takes your account password — not a device or host password.
The written guide below covers every step.
Quick start
- Get a Device ID + enrolment token (from an Admin, or generate your own under Wire a host).
- Run neekOS-Host-Setup.exe on the machine and paste both values.
- Set the permanent host password — done. The machine enrols itself; it never signs in.
Path A · Wire the machine (no sign-in on the machine)
- Get a Device ID and enrolment token from an Admin — or generate them yourself if you hold a host-operator account (Path B).
- On the target machine, run neekOS-Host-Setup.exe.
- Paste both values into the first-run wizard.
- Set the permanent host password for the machine.
- Done — the host auto-registers at every logon and appears in the console under its machine name. No account ever signs in on the machine.
Path B · Host-operator account
- Sign in at the portal with your host-operator account.
- Open the Wire a host tab.
- Label the machine, then click Generate wiring credentials.
- Follow Path A on the machine with the credentials you just generated.
- Watch the machine flip to Online under Your hosts (use Refresh if needed).
Good to know
- The host role wires machines only — it cannot remote-control devices or manage users.
- The host password never leaves the machine or the browser unsealed; every session is approved by challenge/response.
Troubleshooting
- Token rejected. Enrolment tokens are single-use — generate fresh credentials and try again.
- Machine never flips Online. Check the machine's network and that the installer finished; then hit Refresh under Your hosts.
- "Your account can't enrol hosts." Your account lacks host access — ask a Network Admin to wire the machine or upgrade your account.
Settings
Your account and session.
Control input (mouse / keyboard) is sealed with a key derived from the host password — which the relay never sees — so it stays private even if the relay is compromised. Video is carried over WebRTC's mandatory DTLS-SRTP. Your relay does signaling only; it never holds a decryption key.