# Admin app (https://optakt.ai/docs/admin-app)

The admin app runs in a terminal. Open it on your agent's machine:

```bash
optakt
```

Log in with your email and password. The login is kept, so next time it opens where you were; a session unused for thirty days expires.

## Finding your way [#finding-your-way]

- The top line shows the version and which deployment you are on. The line below shows who you are and the current **agent scope**. `tab` moves to the next scope, on every screen.
- Two rows at the bottom list every key that works on the current screen. A key that does not apply tells you why.
- `↑↓` moves, Enter opens, `Esc` goes back, `q` quits. Ordinary destructive actions ask for `y` to confirm. Permanently deleting a scope requires a typed confirmation, its bot and group disconnected, and the last remaining admin making the request.

## Screens [#screens]

| Screen | What you do there |
| --- | --- |
| **Home** | See the current scope at a glance. `n` creates a new agent scope, `a` archives it, `o` restores it, `x` deletes it for good. |
| **Models** | Set the reasoning (`r`) and utility (`u`) models. See [Models](/docs/models). |
| **Members** | Add users to the scope (`a`), change their role (`c`), remove them (`d`), or leave (`l`). |
| **Integrations** | Connect model providers, Telegram, Voyage AI and ElevenLabs (`a`), disconnect (`d`), reconnect (`c`). For Telegram, `b` binds a group and `u` unbinds it. |
| **Secrets** | Create (`c`), replace (`p`), rename (`n`), destroy (`d`), lock (`l`) and unlock (`u`). See [Credentials](/docs/credentials). |
| **Spaces** | See every conversation of the scope, set a space's own models (`r`, `u`), archive (`a`) and restore (`o`). |
| **Users** | Owner only: add users (`a`), reset a password (`r`), delete (`d`), transfer ownership (`t`). |
| **Profile** | Edit your name and email (`e`), change your password (`p`), link your Telegram account (`l`). |
| **Settings** | Rename the scope (`n`), replace the licence key (`l`). On your agent's machine itself the owner can also upgrade (`u`) and tune the database (`t`). |

An archived scope or space keeps receiving messages but starts no new work, until it is restored.

## Users and passwords [#users-and-passwords]

Your password unlocks your part of the vault and is never stored. A new user gets a generated four-word password, shown once; until they change it, they can only use Profile. Resetting a password issues a new one the same way. Anything protected only by the old password is lost; a shared scope can recover through another admin. The app refuses a reset that would strand a scope's secrets and tells you to add an admin or reset while the user is logged in.

## From another computer [#from-another-computer]

The admin app connects to a local service by default. To manage your agent from another Linux or Mac computer, open an SSH tunnel to your agent's machine and connect through it:

```bash
ssh -L 9631:127.0.0.1:9631 your-server
optakt
```

Or turn on remote access during the install (the *Remote access* field, for example `0.0.0.0:9633`) and connect over TLS:

```bash
optakt --host your-server --port 9633
```

On first contact the app shows the server's certificate fingerprint and asks you to compare it with the output of `sudo optakt fingerprint` on the server. Once you confirm, it remembers the server, the way SSH does.
