Public and private access
Choose how other devices reach your OE server. Ordinary chat on your LAN does not need a public URL.
| Need | Connection |
|---|---|
| Devices at home | Your server’s LAN address |
| Your own devices away from home | Private network access, such as Tailscale |
| Telegram webhooks or outside callers | A reachable public HTTPS URL |
| Google/Microsoft sign-in | A registered callback URL; localhost can work from a browser on the OE host |
A public HTTPS domain can use Cloudflare Tunnel or your own reverse proxy. A dashboard address still requires a signed-in OE profile. Uploaded-document sharing is between OE users; enabling a tunnel does not publish your files.
Cloudflare Tunnel
Use an owner/admin OE account, a Cloudflare account, and a hostname you can configure there. Follow Cloudflare’s tunnel setup to create a remotely managed tunnel and a public hostname route.
- In Cloudflare, route the chosen hostname to
http://localhost:3737, or the actual local OE port shown in its Public Access panel. The connector runs alongside OE, so this address is from the connector’s point of view. - Copy that tunnel’s connector token. OE needs the token, not the entire installation command Cloudflare displays.
- Open Settings → System → Public Access (Cloudflare Tunnel) in OE.
- Select Cloudflare Tunnel, paste CF Tunnel Token, and enter the Public hostname you configured, such as
oe.example.com. - Choose Save, then Start if it is not running. OE downloads
cloudflaredon first start when needed. - Wait for the running status, open the displayed HTTPS address, and confirm that you can sign into your OE account.
The tunnel is shared across the installation. Stop stops its process; select Off and save to disable the configured public exposure. The panel shows startup errors if its token, hostname, or origin route is incorrect.
Private Mesh: Tailscale
Open Settings → System → Private Mesh (Tailscale) as owner/admin. The panel shows installation status, tailnet IP, and MagicDNS name.
If setup is needed, use its auth-key and sudo-password fields, or choose Ask the coordinator instead for the guided OE Admin flow. Enter credentials through those setup controls. Confirm Joined to tailnet, then connect your other device to the same tailnet and open OE using the displayed address and OE’s port. OE login is still required.
A private tailnet does not make a webhook publicly reachable by Telegram. Browser microphone/USB features still need HTTPS or localhost. See Troubleshooting.
Telegram
- Create a bot with Telegram’s @BotFather using
/newbotand copy its token. - Open Settings → Profile → Telegram and save that token.
- Register a webhook using your public HTTPS OE address in the Telegram panel.
- Open your bot in Telegram and send
/startto complete the connection. - Send a short question and confirm a reply from your primary assistant or ensemble coordinator.
Each OE user connects their own bot. A Cloudflare tunnel is one way to provide the public address; your own reachable HTTPS reverse proxy can also do so. Keep that address available for incoming webhook delivery.
OAuth callbacks and reverse proxies
Register the exact callback URLs used by your OE origin. See Email & calendar for Google and Microsoft setup. If using a reverse proxy, pass the correct forwarded protocol and support WebSocket connections as well as normal HTTP requests. Node agents should use the complete HTTPS server address when pairing through it.
Common problems
- Public site does not load: check the tunnel state and its Cloudflare hostname route before changing OE credentials.
- OAuth redirect mismatch: compare the scheme, hostname, port, and callback path with the provider’s registration.
- Telegram receives no reply: check the registered webhook’s public URL, that you sent
/start, and that your assistant has a working chat model. - Dashboard shows another layout: dashboard slugs belong to the currently signed-in profile. See Display dashboards.