On this page
How it works
The install script generates an RSA-2048 key on the agent host, uploads only the public key, and keeps device.key mode 600 next to docker-compose. site-main wraps exporter URLs and passwords with RSA-OAEP + AES-256-GCM. GET /api/agent/config returns ciphertext; only the agent unseals it.
Lost device.key
There is no recovery. On the install or profile card, confirm LOST_KEY to clear the registered public key, then re-enter exporter addresses and credentials. Never paste the private key into the dashboard or support chat.
Secondary agents
Copy device.key from the primary host and re-run the installer with AGENT_DEVICE_KEY_FILE pointing at that file. A second generated key is rejected (HTTP 409).