Connect a machine
A LogiShell node is a computer that accepts work: terminals and agent sessions open on it from the browser, from your phone, and from the desktop app. The machine dials out to the control plane, so it never opens an incoming port.
Three systems, one page: macOS, Linux, Windows.
Step 0. Get the code
In the app: Settings → Devices → Pair new compute. On the phone: Devices
→ Get the install line. From an agent with the MCP door: the pair_node tool.
The card hands you a command with a fresh code in it and a switch for the
operating system. The code is one-time and lives ten minutes. You never
need it twice: the pairing is stored in node.json on the machine itself.
Step 1. Run one command
macOS and Linux, any shell:
curl -fsSL 'https://app.logishell.com/install/node' | sh -s -- \
--control 'https://app.logishell.com' --pair '<code>'
Windows, PowerShell:
& ([scriptblock]::Create((irm 'https://app.logishell.com/install/node.ps1'))) -Control 'https://app.logishell.com' -Pair '<code>'
The command does the same three things everywhere. It downloads the right
build of lb-node, checks its sha256 (no match, nothing is installed), pairs
once with the code, and then installs a service whose own command line no
longer contains the code.
| System | What survives a reboot | Log |
|---|---|---|
| macOS | LaunchAgent com.logishell.node, starts at login, comes back after a crash | ~/.logishell/node.log |
| Linux | systemd user unit logishell-node (system unit under root) | journalctl --user -u logishell-node -f |
| Linux without systemd | nothing: a background process, and the installer says so | ~/.logishell/node.log |
| Windows | scheduler task LogiShell node | %LOCALAPPDATA%\LogiShell\install.log |
Already have lsh on that machine? Then it is one line without curl:
lsh onboard --node <code>.
Useful flags: --name '<name in the list>' (hostname by default) and
--foreground (-Foreground on Windows), which keeps the node in that window
and installs no service, for a one-off check.
Step 2. Approve it
Pairing is not permission. A freshly paired machine lands as pending, and
the hub answers nothing but /healthz for it until you approve it in
Settings → Devices. That is deliberate: anyone holding a pair code can
pair, so the last word belongs to a person who is already signed in.
An agent can do the same through the MCP door with approve_node, and
list_nodes is where you see which id is still pending.
Step 3. What you should see
The installer ends with paired and a line naming the service it created. In
Settings → Devices the machine appears with its operating system,
architecture, an online dot, and the AI providers it found on itself (claude,
codex, gemini). From there it can carry terminals and agent sessions.
When it does not work
- The machine is online but refuses work. It is still pending. Approve it.
- The code expired. Ten minutes passed. Mint a new one, the machine is not broken.
- Nothing appears in Devices. Read the log from the table above. The node dials out, so the usual cause is an outbound proxy, not a firewall rule you forgot to open.
- Windows and you want it to survive sign-out. The PowerShell installer
registers the task as S4U. The
lsh onboard --nodepath registers an at-logon task instead, and says so.
Next: put an agent on that machine.