Skip to main content
For onboarding a new FDE. (New engineer? Go to the engineer guide.)
You need an authenticated khal session with superadmin rights. Not sure? Run the mint command — a clear permission error tells you fast.
1

Mint a single-use invite

Superadmin-only, @namastex.ai addresses only. Minting is what creates the engineer’s identity — there’s no account to set up first.
The code is shown once (the platform keeps only its SHA-256 hash). Copy it now; if you lose it, mint a fresh one.
2

Hand it off securely

Send it over a channel you’d trust with a password — not a public channel or an archived screenshot. It’s single-use: the engineer’s first khal fde enroll consumes it.
3

Approve their SSH lease

After they enroll and request a workstation, its SSH lease sits behind the Deploy Ledger until you approve it. Get their instance ID (from their khal fde status), then approve through your khal fde admin tooling.No certificate authority — once approved, access is just the engineer’s own SSH key plus Tailscale.
Until you approve, their khal fde ssh returns “not approved yet” — expected, just your turn.
Your job is mint and approve. You don’t set passwords or certs (the engineer’s SSH key is the credential), pick a hostname (Tailscale does), or provision the VM (that’s the engineer’s khal fde instance).