Service Status
Live health of all BL services
Hub
β
checkingβ¦
Memory
β
checkingβ¦
Gateway
β
checkingβ¦
AgentRunner
β
checkingβ¦
AgentRunner Detail
Loadingβ¦
Hub Users
Register users including the AgentRunner service account
Register New User
Create Registration Token
Existing Users
Loadingβ¦
Room Configuration
Map rooms to agents in the AgentRunner. Save writes to AgentRunner config.
Add Room
Click an agent to add
Agents
Agents in the Memory service. Click Copy ID to use in room config.
Loadingβ¦
Secrets Management
All service secrets are managed in one file on the VPS
Single source of truth:
All four systemd services load this file via
To update a token: edit the file, then restart all services.
/etc/ailounge/secrets.envAll four systemd services load this file via
EnvironmentFile=.To update a token: edit the file, then restart all services.
Token Structure
BL_TOKEN
Service-to-service API token β sent as
X-BL-TokenUsed by: Memory (inbound), Gateway /complete (inbound), HubβMemory (outbound), AgentRunnerβGateway, AgentRunnerβMemory
BL_ADMIN_TOKEN
Admin API token β sent as
X-BL-Admin-TokenUsed by: Hub /admin/*, Memory /settings+/admin/*, Gateway /routing/*, AgentRunner /admin/*
HUB_JWT_SECRET
Hub JWT signing key β signs user access tokens
Used by: Hub only. Rotate = all users must log in again.
BL_MEMORY_KEY
Memory service AES encryption key for stored agent data
Used by: Memory only. Do NOT rotate β existing data becomes unreadable.
AGENTRUNNER_HUB_PASSWORD
Hub account password for the AgentRunner service account
Used by: AgentRunner (Hub login). Must match the registered Hub user.
Setup β First Time or Rotation
SSH into the VPS and run the setup script. It generates all tokens and writes
/etc/ailounge/secrets.env. On subsequent runs it preserves existing values.
# SSH into VPS (see your runbook for host and key path) ssh ailounge@<VPS_IP> -i ~/.ssh/AILounge.pem # Copy setup script from local deploy/ folder to VPS scp -i ~/.ssh/AILounge.pem deploy/setup-secrets.sh ailounge@<VPS_IP>:/tmp/setup-secrets.sh # On VPS: run the script sudo bash /tmp/setup-secrets.sh # View the generated tokens sudo cat /etc/ailounge/secrets.env # Restart all services sudo systemctl restart ailounge-hub ailounge-memory ailounge-gateway ailounge-agentrunner # Check they're all running sudo systemctl status ailounge-hub ailounge-memory ailounge-gateway ailounge-agentrunner
How Each Service Uses the File
HUB (port 5050)
reads: BLAdminToken, MemoryServiceToken, HUB_JWT_SECRET, HUB_DB_PATH, HUB_DB_KEY
MEMORY (port 5051)
reads: BLToken, BLAdminToken, BL_MEMORY_KEY, StorageRoot
GATEWAY (port 5052)
reads: Gateway__BLToken, Gateway__BLAdminToken, Gateway__StorageRoot
AGENTRUNNER (port 5053)
reads: AgentRunner__GatewayToken, AgentRunner__MemoryToken,
AgentRunner__HubUsername, AgentRunner__HubPassword,
AgentRunner__AdminToken
All mapped in secrets.env so changing BL_TOKEN once updates all services.
Admin Config
Service URLs and admin token β saved to your browser only, never sent to any server
Service URLs
These are the public URLs (via nginx proxy) or direct VPS URLs.
Use
http://ai-lounge.eu/hub etc. when accessing via the web.
Auth Tokens
Used for Hub admin, Memory admin, Gateway routing, and AgentRunner admin APIs
Used for Memory and Gateway service API calls