Skip to main content

exe.dev

Goal: Velaclaw Gateway running on an exe.dev VM, reachable from your laptop via: https://<vm-name>.exe.xyz This page assumes exe.dev’s default exeuntu image. If you picked a different distro, map packages accordingly.

Beginner quick path

  1. https://exe.new/velaclaw
  2. Fill in your auth key/token as needed
  3. Click on “Agent” next to your VM and wait for Shelley to finish provisioning
  4. Open https://<vm-name>.exe.xyz/ and authenticate with the configured shared secret (this guide uses token auth by default, but password auth works too if you switch gateway.auth.mode)
  5. Approve any pending device pairing requests with velaclaw devices approve <requestId>

What you need

  • exe.dev account
  • ssh exe.dev access to exe.dev virtual machines (optional)

Automated Install with Shelley

Shelley, exe.dev’s agent, can install Velaclaw instantly with our prompt. The prompt used is as below:

Manual installation

1) Create the VM

From your device:
Then connect:
Tip: keep this VM stateful. Velaclaw stores velaclaw.json, per-agent auth-profiles.json, sessions, and channel/provider state under ~/.velaclaw/, plus the workspace under ~/.velaclaw/workspace/.

2) Install prerequisites (on the VM)

3) Install Velaclaw

Run the Velaclaw install script:

4) Setup nginx to proxy Velaclaw to port 8000

Edit /etc/nginx/sites-enabled/default with
Overwrite forwarding headers instead of preserving client-supplied chains. Velaclaw trusts forwarded IP metadata only from explicitly configured proxies, and append-style X-Forwarded-For chains are treated as a hardening risk.

5) Access Velaclaw and grant privileges

Access https://<vm-name>.exe.xyz/ (see the Control UI output from onboarding). If it prompts for auth, paste the configured shared secret from the VM. This guide uses token auth, so retrieve gateway.auth.token with velaclaw config get gateway.auth.token (or generate one with velaclaw doctor --generate-gateway-token). If you changed the gateway to password auth, use gateway.auth.password / VELACLAW_GATEWAY_PASSWORD instead. Approve devices with velaclaw devices list and velaclaw devices approve <requestId>. When in doubt, use Shelley from your browser!

Remote Access

Remote access is handled by exe.dev’s authentication. By default, HTTP traffic from port 8000 is forwarded to https://<vm-name>.exe.xyz with email auth.

Updating

Guide: Updating