One command on the host.
Cookbox needs a POSIX SSH endpoint and at least one supported multiplexer. Linux is the full target; WSL 2 works when SSH terminates inside Linux, and macOS is a reduced preview. Everything below runs as the user Cookbox will log in as — never as root by habit.
The short path: QR pairing
This is the normal route, and the one New connection in the app walks you down.
- In the app, tap New connection and choose where the host runs, the network route, and which multiplexers and agent CLIs to install.
- On the host, run the short command the page shows:
curl -fsSL https://cookbox.ai/pair | sh - It prints a QR code. Scan it with the app. Name, login user, address and SSH port fill themselves in, and the host receives the installer flags and your public key.
- The host prints what it is about to install and the public key it received. Compare it on screen, then confirm.
- Save the connection in the app and compare the SSH host-key fingerprint the first time you connect.
The pairing expires after five minutes and never carries a password or a private key. Treat a live QR code like a five-minute password: anyone who can photograph it can pair with that host.
The long path: the installer by hand
The same installer, run with the flags spelled out. The app shows this command behind the fold on the same page, filled in with your key.
curl -fsSL https://cookbox.ai/install | sh -s -- \
--install --mode direct --muxes tmux,zellij --agents claude,codex \
--public-key 'ssh-ed25519 AAAA… cookbox'
--describe prints what would happen and installs nothing. The installer:
- supports apt, dnf, pacman and Homebrew;
- installs OpenSSH, the multiplexers and agent CLIs you asked for, and the usual upload and probe tools;
- appends the public key once and repairs SSH file permissions;
- installs the Cookbox skill for a detected Claude Code or Codex CLI;
- installs and persists
mpson Linux x86_64; - configures only the network route you chose.
Agent authentication stays separate: run claude, codex or cursor-agent login on the host after installing. The phone's private key never leaves the app.
Network routes
--mode decides what the host exposes and what you type into the app's Host field. core installs no route at all.
| Mode | Public exposure | Address in Cookbox |
|---|---|---|
direct | SSH TCP, and UDP 50000:50009 | The VPS public IP or DNS name |
wireguard | UDP 51820 | 10.88.0.1 |
awg2 | A randomised AmneziaWG 2 UDP port | The address in the printed AWG2 profile |
tailscale | Nothing from Cookbox | The Tailscale IPv4 or MagicDNS name |
A private route prints a second QR code when it finishes — scan that one with the WireGuard or AmneziaWG app. Tailscale gives the host a new address that does not exist until the installer has run, so the app leaves Host empty on purpose and you paste the tailnet address in afterwards.
The moshpit control port 40404 stays on loopback and is reached through SSH. Direct mode opens the UDP data range publicly; the private modes restrict it to their own interface or container. One UDP port is used per live moshpit session.
Windows through WSL 2
Native Windows is not a Cookbox host: Windows sshd with wsl.exe as the shell does not give the POSIX exec, uploads, process metadata and multiplexer behaviour Cookbox expects.
- Run
wsl --install, open the Linux distribution once, and make sure systemd is active. - In the app choose Linux PC / WSL, which selects Tailscale.
- Run the generated command inside the WSL terminal.
- Copy the WSL node's IP from the Tailscale app into the app's Host field.
macOS preview
Turn on System Settings → General → Sharing → Remote Login, then run the installer. Terminal sessions, uploads and SSH forwarding work. Agent and activity probes, port discovery and packaged moshpit do not.
Check the result
- Connect from the app and compare the pinned SSH host fingerprint.
- Create a session, leave it, and reopen it.
- Upload a small file, and open one forwarded service from View.
- On Linux x86_64 with
mpsinstalled, confirm the terminal saysmp. Anywhere else,sshis the expected answer.
If the host sits behind a provider firewall, mirror the rules the installer printed. A local UFW or firewalld rule cannot open the provider's edge.
Uninstall
An installation records its own mode, SSH port and public key, so removing it needs no flags:
curl -fsSL https://cookbox.ai/install | sh -s -- --uninstall
That removes the Cookbox-owned moshpit, route state and skills. It keeps OpenSSH, system packages, multiplexers, agent CLIs and any shared Tailscale enrollment, and it removes AmneziaWG resources only when Cookbox created them.