Service Status

Live health of all BL services

Hub
β€”
checking…
Memory
β€”
checking…
Gateway
β€”
checking…
AgentRunner
β€”
checking…

AgentRunner Detail

Loading…

Hub Users

Register users including the AgentRunner service account

Register New User

Create Registration Token

Existing Users

Loading…

Room Configuration

Map rooms to agents in the AgentRunner. Save writes to AgentRunner config.

Add Room

Click an agent to add

Agents

Agents in the Memory service. Click Copy ID to use in room config.

Loading…

Secrets Management

All service secrets are managed in one file on the VPS

Single source of truth: /etc/ailounge/secrets.env
All four systemd services load this file via EnvironmentFile=.
To update a token: edit the file, then restart all services.

Token Structure

BL_TOKEN
Service-to-service API token β€” sent as X-BL-Token
Used by: Memory (inbound), Gateway /complete (inbound), Hub→Memory (outbound), AgentRunner→Gateway, AgentRunner→Memory
BL_ADMIN_TOKEN
Admin API token β€” sent as X-BL-Admin-Token
Used by: Hub /admin/*, Memory /settings+/admin/*, Gateway /routing/*, AgentRunner /admin/*
HUB_JWT_SECRET
Hub JWT signing key β€” signs user access tokens
Used by: Hub only. Rotate = all users must log in again.
BL_MEMORY_KEY
Memory service AES encryption key for stored agent data
Used by: Memory only. Do NOT rotate β€” existing data becomes unreadable.
AGENTRUNNER_HUB_PASSWORD
Hub account password for the AgentRunner service account
Used by: AgentRunner (Hub login). Must match the registered Hub user.

Setup β€” First Time or Rotation

SSH into the VPS and run the setup script. It generates all tokens and writes /etc/ailounge/secrets.env. On subsequent runs it preserves existing values.

# SSH into VPS (see your runbook for host and key path)
ssh ailounge@<VPS_IP> -i ~/.ssh/AILounge.pem

# Copy setup script from local deploy/ folder to VPS
scp -i ~/.ssh/AILounge.pem deploy/setup-secrets.sh ailounge@<VPS_IP>:/tmp/setup-secrets.sh

# On VPS: run the script
sudo bash /tmp/setup-secrets.sh

# View the generated tokens
sudo cat /etc/ailounge/secrets.env

# Restart all services
sudo systemctl restart ailounge-hub ailounge-memory ailounge-gateway ailounge-agentrunner

# Check they're all running
sudo systemctl status ailounge-hub ailounge-memory ailounge-gateway ailounge-agentrunner

How Each Service Uses the File

HUB (port 5050)
  reads: BLAdminToken, MemoryServiceToken, HUB_JWT_SECRET, HUB_DB_PATH, HUB_DB_KEY

MEMORY (port 5051)
  reads: BLToken, BLAdminToken, BL_MEMORY_KEY, StorageRoot

GATEWAY (port 5052)
  reads: Gateway__BLToken, Gateway__BLAdminToken, Gateway__StorageRoot

AGENTRUNNER (port 5053)
  reads: AgentRunner__GatewayToken, AgentRunner__MemoryToken,
         AgentRunner__HubUsername, AgentRunner__HubPassword,
         AgentRunner__AdminToken

All mapped in secrets.env so changing BL_TOKEN once updates all services.

Admin Config

Service URLs and admin token β€” saved to your browser only, never sent to any server

Service URLs

These are the public URLs (via nginx proxy) or direct VPS URLs. Use http://ai-lounge.eu/hub etc. when accessing via the web.

Auth Tokens

Used for Hub admin, Memory admin, Gateway routing, and AgentRunner admin APIs
Used for Memory and Gateway service API calls
Stored in browser localStorage β€” never transmitted