| title | Install Core and Web |
|---|
One command installs Core, the Web console and PostgreSQL on Linux, macOS or Windows. Sign in to Web with the Core key, set a default model and issue Project API keys. Applications call Core with those keys. Sessions run in sandboxes on nodes you add, or on E2B.
- Check the prerequisites.
- Run the installer.
- Sign in to Web.
- Configure the public address.
- Set a default model.
- Issue a Project API key.
- Add sandbox capacity.
This page follows the default path. Every flag, existing reverse proxies and offline hosts are in installation options.
- Linux amd64/arm64 or macOS Intel/Apple Silicon with curl; Windows x64 with PowerShell.
- Docker Engine 26 or newer and Docker Compose 2.26.0 or newer. On macOS and Windows, install and start Docker Desktop using Linux containers.
- An account that can run
dockerand write to its home directory. Ordinary users and root both work; the installer never calls sudo. - Free port 8080 for Web. See ports. Docker must be able to publish it; the installer does not change host policy.
- For anything off this machine, the origin in
OAC_PUBLIC_URLmust be the address browsers, nodes and executors use. You can sign in on this machine first.
Sandbox nodes run on Linux amd64. When Core runs on macOS or Windows, connect a Linux node or use E2B.
Linux and macOS:
curl -fsSL https://github.com/MiniMax-AI/OpenAgentCore/releases/latest/download/install.sh | bashWindows PowerShell:
irm https://github.com/MiniMax-AI/OpenAgentCore/releases/latest/download/install.ps1 | iexWhen binding to all IPv4 addresses, the installer uses the private address of the default route if available; otherwise the console address is http://localhost:8080. To choose another reachable origin, pass --public-url; if a reverse proxy already serves this host, use its HTTPS address:
curl -fsSL https://github.com/MiniMax-AI/OpenAgentCore/releases/latest/download/install.sh | bash -s -- --public-url https://core.exampleThe script downloads that release's Compose files, checks their SHA-256, and:
- checks Docker is running Linux containers, meets the required versions, and can publish the chosen port;
- prepares the installation directory,
~/.oac/core, with.envand the nativeoaccommand (oac.exeon Windows); - starts the services with Docker Compose. Web serves the console on port 8080 and forwards
/v1,/api/v1and/docsto Core. Core and PostgreSQL are not published.
The installer prints the console address and Core key. After signing in, configure execution resources and create Projects in Web.
Downloads and configuration checks happen before the installation directory is published. After that, failures preserve the configuration and data and report the failed step; inspect it with docker compose logs --tail 100 in the installation directory. Fix the reported cause and rerun the same command, or specify the installation directory:
curl -fsSL https://github.com/MiniMax-AI/OpenAgentCore/releases/latest/download/install.sh | bash -s -- --install-dir "$HOME/.oac/core"Use your chosen directory if it differs. A rerun uses the saved Compose file and settings; installation flags only apply to new directories. Existing images and containers are reused; missing images are downloaded. To change settings, edit .env and run oac apply. A new release needs a new directory; see version policy.
For insufficient space or quota, free space on the filesystem named by the error. Image-loading failures can also require space in Docker's storage, which may be on a different filesystem.
-
Open the console address the installer printed, the public URL. Web accepts only that host.
-
Sign in with the Core key, the installation's administrator credential. Web has no user accounts.
~/.oac/core/oac core-key --showOn Windows, use
& "$HOME/.oac/core/oac.exe" core-key --show. The same command arguments work on every platform.
Applications, nodes and sandboxes reach Core at one address, the public URL. HTTP is enough on the local network. When you expose Core beyond it, put a reverse proxy in front and set the public URL to the HTTPS origin it serves. E2B guests reach Core from the internet, so they need a public URL that is not loopback.
- Point your reverse proxy at Web.
- Set
OAC_PUBLIC_URLto the HTTPS origin it serves, then runoac apply. See changing the public URL.
Core-hosted Sessions without their own model provider use their harness's default model. On System, under Default model configuration, find the harness marked Default (Codex unless you changed core.default_harness) and choose Set. Enter the model ID, the protocol, and the provider's base URL and API key. MiniMax Code also needs the context window and max output tokens. See default models.
- On Projects and keys, choose Create project, then Issue key. The dialog shows the key once: copy it and keep it safe. Its How to call card shows the API base URL and sample requests.
- Give the key and the API base URL to the application developer. They continue with the quickstart.
Web's Overview tracks these steps in a Getting started checklist.
Sessions need somewhere to run:
- Choose the backend in System → Manage sandbox configuration, then add a node from Nodes. The installer selects none.
Day-to-day operation, backups and upgrades are in Operations.