BBline-X

Setup Keys

A setup key is what a new device presents to join the mesh. It is exchanged once, at enrollment, for a token the agent uses from then on.

The default key is for getting started

BLINEX-DEFAULT-KEY is seeded at startup and valid for a year, so a fresh install works immediately. Create your own keys before production and let it expire unused.

Creating a key

From the Setup Keys page in the dashboard, or over the API. A key can place first-time enrollees straight into groups, which is how a device gets the right access from the moment it appears.

curl -sk -X POST https://your-host:8080/api/v1/setup-keys \
  -H "Authorization: Bearer $TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{"name":"laptops","auto_groups":["Default","staff"],"expires_in_days":30}'

Using one

sudo blinex-agent -setup-key <key>

The agent stores its token and identity under its state directory, so it re-enrolls after a restart without the key. Group membership, device name and advertised routes are operator-managed: re-enrolling preserves whatever you set, rather than resetting it to what the device reports about itself.

Revoking

Deleting a key stops it being used for new enrollments. It does not disconnect devices that already joined — remove those peers directly, which revokes their token as well.

curl -sk -X DELETE https://your-host:8080/api/v1/setup-keys/$ID -H "Authorization: Bearer $TOKEN"