Documentation

Quickstart

From nothing to an SSH session on a machine behind NAT, in about five minutes and one install command.

This is the managed path: Kino Cloud picks the relay and handles credential rotation. If you would rather run the relay yourself, do this first anyway — then see Self-hosting.

1. Install Kino SSH Manager#

Grab a build for your platform from the releases page. Linux ships an AppImage, a .deb, and an .rpm; there are Windows and macOS builds too.

On first launch you set a master password. It derives the key for the local vault (Argon2 → AES-256-GCM) and it is never transmitted anywhere. There is no recovery — if you lose it, the vault is gone.

2. Turn on agent mode and paste an account key#

Agent mode is off by default. In the app:

  1. Settings → Kino Agent → Enable agent connections.
  2. Set Kino Cloud URL to https://kino.dpdns.org.
  3. Create an account key here in the dashboard — Account keys → New key — and copy it. It looks like kck_… and is shown exactly once.
  4. Paste it into Settings → Kino Agent → Kino Cloud → Account key.

The key is stored encrypted in the vault. You are not signing in to anything from the app; the key is the credential. See Credentials and tokens for what it can and cannot do.

3. Add the machine#

Either in the dashboard (Machines → Add machine) or from the app’s host editor once the account key is in place. Give it a name you will recognise — homelab-pi, work-vm.

You get back a one-time install command:

curl -fsSL https://kino.dpdns.org/install/kce_… | sudo sh

Fetching the link is safe; running it is what claims the machine

Opening the URL in a browser just shows you the script. The enroll key is consumed the first time the script actually runs, when it POSTs to /api/agents/exchange. Preview it before you pipe it to a shell — you should do that with any install one-liner.

4. Run it on the target machine#

SSH in the old-fashioned way, or sit at the keyboard, and run the command.

==> Registering this machine with https://kino.dpdns.org
==> Machine 'homelab-pi' registered (agent id: 6b1d…)
==> Installing kino-agent 0.1.1 (x86_64-unknown-linux-gnu)
==> Downloading binary
==> Downloading installer
==> kino-agent installed and started

What that did:

  • Traded the one-time kce_… enroll key for a long-lived kca_… agent key and an initial short-lived relay token.
  • Installed the binary at /usr/local/bin/kino-agent and a hardened systemd unit at /etc/systemd/system/kino-agent.service.
  • Wrote the credentials to /etc/kino-agent/kino-agent.env, readable by root only.
  • Started the service, which discovered the fastest healthy relay and parked on it.

The machine should show as Live on the Machines page within a few seconds. If it does not, see Troubleshooting.

Windows has no SSH server by default

The agent forwards to 127.0.0.1:22 on the machine it runs on. On Windows you must install and start OpenSSH Server first, or every session will fail at the last hop.

5. Connect#

In Kino SSH Manager, add a host, choose connection mode Kino Agent, and pick the machine from the list. Fill in the SSH username and whatever credential that machine’s sshd expects — a password, a key, or your agent.

Hit connect. The first time, you will be asked to accept the host key, exactly as OpenSSH would ask; it is pinned per agent id from then on.

What you now have#

  • No inbound port was opened anywhere.
  • Your machine holds a kca_… key that only ever buys 24-hour relay tokens. Delete the machine here and its access is dead within a day — immediately, for new sessions.
  • Your laptop holds an account key and an agent id. It never learns a relay password.

Next#