Get Started

Install

Install an Appstrate instance and the CLI, choose an infrastructure tier, and connect to an instance from another machine.

Install an instance

curl -fsSL https://get.appstrate.dev | bash

This downloads the appstrate CLI binary for your OS and architecture, verifies its minisign signature and SHA-256 checksum, and puts it in ~/.local/bin (added to your shell PATH unless you set APPSTRATE_NO_MODIFY_PATH=1). It does not need Bun on the host. Supported: macOS and Linux, on x64 and arm64. On Windows, run it inside WSL2.

Then it depends on where you run it:

  • In an interactive terminal, the script stops after installing the CLI and tells you to run appstrate install. That command asks for the tier and the install directory, for another port only when the default one is taken, and, on Docker tiers, for an optional bootstrap email, the public URL and the agent execution backend (Docker, or Firecracker on a KVM host).
  • Unattended (you pass --yes, CI=true is set, or stdout is not a terminal), it goes on to run appstrate install --yes with the defaults below.
# Unattended install, with overrides
curl -fsSL https://get.appstrate.dev | bash -s -- --yes --tier 1 --dir ~/apps/appstrate --port 4000

With --yes the tier is Tier 2 (PostgreSQL + Redis) when Docker is reachable and Tier 0 otherwise. The flags are those of appstrate install. minisign must be installed to verify the download. The script offers to install it with your package manager, and does so without asking when unattended.

TierRuntimeServicesStorage
0BunNone (PGlite in-process)Filesystem
1DockerPostgreSQLFilesystem
2DockerPostgreSQL + RedisFilesystem
3DockerPostgreSQL + Redis + MinIOS3 (bundled MinIO)

Tier 2 is the recommended single-node production stack. See Progressive Infrastructure for the trade-offs.

bun install -g appstrate   # 1. the CLI on your PATH (Bun 1.3.9 or later)
appstrate install          # 2. bootstrap the instance (interactive)

Use this when you already have Bun and prefer the package manager to a downloaded binary. You can also run it once without installing the CLI: bunx appstrate install. This is the route on native Windows. Upgrade with bun update -g appstrate.

For a manual Docker Compose setup (CI, Kubernetes preparation, custom orchestration), see Self-Hosting / Docker Compose. You edit the compose file and the .env yourself; the installer is not involved.

Whatever the route, the installer writes a .env with generated secrets (and, for Docker tiers, a docker-compose.yml) into the install directory, ~/appstrate by default. It then waits for the healthcheck (up to 120 seconds on Docker tiers) and tries to open http://localhost:3000 in your browser. The default port is 3000 (--port or APPSTRATE_PORT changes it). If it is taken, an install run with --yes picks the next free port, an install run with --tier but not --yes stops with an error, and an interactive install asks you for another port.

Who can sign up

How the first account is created depends on how you installed:

  • Open instance (Tier 0, or a Docker tier where you left the bootstrap email empty). Anyone who can reach the URL can sign up, and each new account creates its own organization.
  • Invitation-only instance (an unattended Docker install, or a bootstrap email given at the prompt or in APPSTRATE_BOOTSTRAP_OWNER_EMAIL). Public sign-up is off. The installer generates a single-use token, prints it with the claim URL at the end of the install, and stores it in .env as AUTH_BOOTSTRAP_TOKEN. Open <APP_URL>/claim, paste the token and enter your name, email and password to create the first owner. When you gave a bootstrap email, the claim accepts that address only. Everyone else joins by invitation. Re-running the installer on an existing install never mints a new token.

The full matrix of options (domain restrictions, platform admins, magic links) is in AUTH_MODES.md. Environment variables are listed in Environment Variables.

Behind a reverse proxy

For a server reached on a public domain, give the installer the public origin so OAuth redirects, CORS and email links are correct:

curl -fsSL https://get.appstrate.dev | bash -s -- --yes --app-url https://appstrate.example.com

The installer does not set up the reverse proxy or TLS. Point your proxy at localhost:<port>. See Self-Hosting and the production considerations.

Manage and upgrade the install

On Docker tiers the CLI wraps Docker Compose: appstrate start, stop, restart, logs -f [service], status and uninstall (add --purge to delete the data too). appstrate self-update upgrades a CLI installed with curl. Upgrading the instance is covered in Upgrading, and the CLI channels in Upgrading the CLI.

To verify the installer before you run it, use curl -fsSL https://get.appstrate.dev/verify.sh | bash. Signature and provenance details are in the self-hosting README.

Drive your instance

Once the instance is up there are several ways to use it. They all work whether the instance is on your laptop or on a remote server.

Webapp and chat

Open the instance URL in a browser: http://localhost:3000 locally, or https://<your-domain> for a deployment. Create or claim your account, add a model, then build and run agents or talk to the chat. See Using Appstrate / Webapp.

CLI

If you installed with curl the CLI is already on your machine. To install only the CLI, with no instance:

curl -fsSL https://get.appstrate.dev | APPSTRATE_NO_LAUNCH=1 bash   # or: bun install -g appstrate

Then sign in to any instance:

appstrate login --instance http://localhost:3000       # local
appstrate login --instance https://appstrate.acme.com  # remote

The CLI uses a device flow: it prints a code and a URL, you approve in the browser, and it stores a short-lived access token and a rotating refresh token in your OS keyring. A profile (instance URL, pinned organization and space) is kept in ~/.config/appstrate/config.toml. Use --profile <name> to keep several instances side by side. See CLI.

Coding agents and MCP clients

appstrate code sync brings your spaces' skills and agents into Claude Code and Codex (Skills and coding agents). Any MCP client can also connect to an organization's MCP endpoint (MCP clients).

Next steps

On this page