Skip to content

Install the gate

The gate runs on a Linux server with KVM. One command installs it; a second one connects it to your organization.

  • Linux x86_64 with KVM: a bare-metal server, or a VM with nested virtualization.
  • Ubuntu 24.04 or later, or Debian 13 or later.
  • About 3.5 GB free disk space while installing, 1.5 GB after.
  • Outbound HTTPS to your Noset server, to GitHub and to the npm registry.
  1. Install the gate. Run it with sudo from the user the gate should run as:

    Terminal window
    curl -fsSL https://get.noset.ai/install.sh | sudo bash
  2. Connect it to your organization:

    Terminal window
    noset login
  3. Open the link it prints, on your laptop or phone. Check that the code matches the terminal, then name the gate and click Connect server.

The web app shows the same two commands, with your server’s address, under Gates › Connect a server.

The script is short and readable: get.noset.ai/install.sh. It

  • checks the machine (root, x86_64, KVM, systemd, the distribution, disk space);
  • installs virtiofsd, uidmap and zstd from your distribution;
  • downloads noset and the sandbox’s root file system from Noset, Cloud Hypervisor and the guest kernel from GitHub, and Claude Code from npm, and checks each file against its SHA-256 before using it;
  • builds the tools disk with Claude Code on your server;
  • adds your user to the kvm group and starts noset.service, which waits for noset login.

Run it again to update. Your gate’s keys, login and evidence stay.

For CI or a fleet, create a token in the web app (Gates › Connect a server › With a token) and run on each server:

Terminal window
curl -fsSL https://get.noset.ai/install.sh | sudo bash
noset login --server https://noset.example.com --token nst_en_…

A token works for the time and number of servers you choose, and each server gets its own key.

Terminal window
cd ~/project
noset run --credential ANTHROPIC_API_KEY -- claude

The agent runs in the sandbox with your project folder at /workspace. Its API key stays in the gate; the agent only sees a placeholder.