From a flashed router
to a managed device.
Add the feed, build the agent, install it, claim the device. Every command below was run against a live OpenWRT router before it was published.
Add the feed
The packages are built from source in your own OpenWRT buildroot or SDK.
There is no public binary repository yet, so opkg install ac-client
will not find anything — you build it.
Build
ac-client alone gets the router managed. aether-sensord
adds traffic classification, app blocking and threat reputation — it reads
packet payload and is consented separately.
Install
The defaults in /etc/config/optimacs already point at the
controller, and the agent ships with a bootstrap certificate — there is no
token to paste in. Confirm it connected with
logread | grep ac-client; a healthy agent sends a heartbeat
every 60 seconds.
Find your serial
Claim the device
Sign up and verify your email first. Your device list will be empty until you claim — that is expected.
Open My Network and press Claim a device. Enter your serial, then the code your router shows you. That is the whole flow — the API below is the same two steps if you would rather script it, or are onboarding more than one device.
A serial is not a secret. It is printed on the box, it appears in DHCP logs, and it is derivable from a MAC address your radio broadcasts in every beacon frame. If a serial were enough, anyone within WiFi range could bind your router to their account and inherit your WiFi settings, your client list and your traffic history. Reading the code requires SSH or LuCI access — which is what owning the router actually means. The code expires in 10 minutes and allows 5 attempts; an already-claimed device is refused rather than transferred.
Things that fail quietly
Leave it at 60. It is the only periodic traffic on the WebSocket, so it decides whether the connection survives an idle timeout. Cloudflare closes an idle socket at ~126s; at the old default of 300 a board reconnected roughly 28 times an hour.
Must be the public CA bundle. The controller's certificate is publicly issued; pointing this at a private CA breaks the connection at TLS, before anything useful is logged.
Runtime dependencies of the telemetry, not the binary. Strip them from a minimal image and the radio survey and queue statistics report nothing — the RF and bufferbloat views go silently empty.
Stock OpenWRT behaviour, not ours. uci set wireless.radio0.disabled='0' then wifi reload. It is the usual reason a new device shows no RF data.
Full reference, including troubleshooting and per-device certificates, is in the feed README.