Documentation
Quickstart
From nothing to an SSH session on a machine behind NAT, in about five minutes and one install command.
This is the managed path: Kino Cloud picks the relay and handles credential rotation. If you would rather run the relay yourself, do this first anyway — then see Self-hosting.
1. Install Kino SSH Manager#
Grab a build for your platform from the
releases page.
Linux ships an AppImage, a .deb, and an .rpm; there are Windows and macOS
builds too.
On first launch you set a master password. It derives the key for the local vault (Argon2 → AES-256-GCM) and it is never transmitted anywhere. There is no recovery — if you lose it, the vault is gone.
2. Turn on agent mode and paste an account key#
Agent mode is off by default. In the app:
- Settings → Kino Agent → Enable agent connections.
- Set Kino Cloud URL to
https://kino.dpdns.org. - Create an account key here in the dashboard — Account
keys → New key — and copy it. It looks like
kck_…and is shown exactly once. - Paste it into Settings → Kino Agent → Kino Cloud → Account key.
The key is stored encrypted in the vault. You are not signing in to anything from the app; the key is the credential. See Credentials and tokens for what it can and cannot do.
3. Add the machine#
Either in the dashboard (Machines → Add machine) or from the app’s host
editor once the account key is in place. Give it a name you will recognise —
homelab-pi, work-vm.
You get back a one-time install command:
curl -fsSL https://kino.dpdns.org/install/kce_… | sudo sh
Fetching the link is safe; running it is what claims the machine
Opening the URL in a browser just shows you the script. The enroll key is
consumed the first time the script actually runs, when it POSTs to
/api/agents/exchange. Preview it before you pipe it to a shell — you
should do that with any install one-liner.
4. Run it on the target machine#
SSH in the old-fashioned way, or sit at the keyboard, and run the command.
==> Registering this machine with https://kino.dpdns.org
==> Machine 'homelab-pi' registered (agent id: 6b1d…)
==> Installing kino-agent 0.1.1 (x86_64-unknown-linux-gnu)
==> Downloading binary
==> Downloading installer
==> kino-agent installed and started
What that did:
- Traded the one-time
kce_…enroll key for a long-livedkca_…agent key and an initial short-lived relay token. - Installed the binary at
/usr/local/bin/kino-agentand a hardened systemd unit at/etc/systemd/system/kino-agent.service. - Wrote the credentials to
/etc/kino-agent/kino-agent.env, readable by root only. - Started the service, which discovered the fastest healthy relay and parked on it.
The machine should show as Live on the Machines page within a few seconds. If it does not, see Troubleshooting.
Windows has no SSH server by default
The agent forwards to 127.0.0.1:22 on the machine it runs on. On Windows
you must install and start OpenSSH Server first, or every session will
fail at the last hop.
5. Connect#
In Kino SSH Manager, add a host, choose connection mode Kino Agent, and
pick the machine from the list. Fill in the SSH username and whatever
credential that machine’s sshd expects — a password, a key, or your agent.
Hit connect. The first time, you will be asked to accept the host key, exactly as OpenSSH would ask; it is pinned per agent id from then on.
What you now have#
- No inbound port was opened anywhere.
- Your machine holds a
kca_…key that only ever buys 24-hour relay tokens. Delete the machine here and its access is dead within a day — immediately, for new sessions. - Your laptop holds an account key and an agent id. It never learns a relay password.
Next#
- Kino SSH Manager — everything the app does beyond this.
- kino-agent — service management, logs, uninstall.
- Credentials and tokens — what each secret is for.