Install your own workspace.
Choose your machine, follow the steps, and verify the result. You can switch to a compact reference whenever you are ready.
Public alpha. MSO operates with its runtime user’s authority. Review the installer source and use a normal non-root account.
Linux
VPS, home server, workstation, container-like Linux hosts, and always-on production.
Before you begin
- Use a normal non-root user with sudo when package installation is needed.
- Keep about 2 GB free for dependencies and the production build.
- The installer handles supported Node/Bun/build prerequisites where possible; manual Node/Bun links are included below for recovery.
- Keep the default 127.0.0.1 bind unless you deliberately put a protected HTTPS layer in front.
- 1
Open a terminal as your normal user
Do not switch to root. MSO host actions execute with the runtime user's authority.
whoami id -u - 2
Run the canonical installer
This installs or updates the checkout, validates the CLI, builds production, creates owner auth on first install, and uses systemd only when it is actually available.
curl -fsSL https://raw.githubusercontent.com/rahmanef63/mso/main/scripts/install.sh | bash - 3
Complete onboarding
Connect an AI provider, choose the model/preset, and optionally add managed apps or reviewed skills.
mso onboard mso skills available - 4
Verify the host runtime
Doctor should report the actual Linux capabilities instead of assuming the install worked.
mso --version mso doctor mso -hExpected: doctor reports host capabilities and any remaining setup issues. Investigate errors before continuing.
- 5
Open the workspace
Start or open the browser workspace. The raw app stays on loopback by default.
mso webLocal browser: http://127.0.0.1:4005
- 6
Add protected remote access when needed
Prefer Tailscale Serve or a named HTTPS reverse-proxy/tunnel. Do not publish the raw shell port directly.
tailscale serve 4005Cloudflare Tunnel is also supported as an optional gateway adapter; see the official link below.
Finish browser pairing
Use the owner password created during setup. A new browser can show “pending approval”. From the owning host terminal, list devices and approve the exact ID displayed by that browser:
mso device pendingmso device approve <deviceId> "my laptop"Replace <deviceId> first. Stay on the same browser URL, then check approval again. Pairing and access details →
Something did not work? Troubleshooting for Linux
- Run mso doctor --fix for safe local repairs, then rerun mso doctor.
- If node-pty fails to compile, confirm a C/C++ compiler, make, Python 3, and supported Node are available.
- If login loops on a remote IP, use HTTPS or tunnel to localhost; MSO's session cookie is Secure.
Official resources and full platform reference
- MSO install reference ↗ — Canonical flags, update path, TLS and recovery.
- Node.js downloads ↗ — Official Node download and supported release information.
- Bun installation ↗ — Official Bun installation and PATH recovery.
- Tailscale Serve ↗ — Private HTTPS access inside your tailnet.
- Cloudflare Tunnel ↗ — Named HTTPS tunnel for a stable public hostname.