Open Source

ac-client
BSD 3-Clause

The open source USP/TR-369 agent for OpenWRT. Download it, install it, sign up — the router is under management in three commands. ac-client is the OpenWRT package, for OpenWRT users. QSDK, prplOS and RDK-B run their own native agents — Aether speaks to those directly, with nothing new to install.

LICENCE
BSD 3-Clause

Use it, modify it, distribute it. Commercial use permitted, no copyleft conditions. This covers ac-client, the OpenWRT package. The Aether platform itself is a managed service — self-hosting is licensed separately on Enterprise.

✓ Commercial use ✓ Modification ✓ Redistribution ✓ No copyleft
Why open source?

Native to the box.
Not bolted on.

ac-client runs on OpenWRT. It calls uci subprocess, reads dnsmasq lease files, and uses nl80211 — deep integration with OpenWRT's GPL-licensed components.

It ships as an OpenWRT feed package with a aether-sensord, cross-compiled through the standard OpenWRT feed. A permissive licence means no copyleft obligations for operators who bundle it into their CPE images — no ambiguity, no legal grey area.

That reach is the point. The OpenWRT ecosystem covers more than 1,500 router models on a current stable release. A single agent that any of them can run means one integration instead of one per vendor.

reads /tmp/dhcp.leases

dnsmasq lease file → Device.Hosts.Host.{i}. Every DHCP client visible to Argus with zero configuration. This is how IoT device inventory works.

reads /proc/net/arp

ARP table → catches devices that skipped DHCP. MAC + IP → OTraffic intelligence lookup → device classification. Argus sees everything.

calls uci subprocess

WiFi config reads/writes via UCI → Device.WiFi.* data model. Radios, SSIDs, clients, channels. Full TR-181 coverage on any OpenWRT device.

Capabilities

What ac-client
actually does.

Data model
TR-181:2.16
30+ DM modules: WiFi, DHCP, hosts, firewall, QoS, diagnostics, firmware, security, VoIP, bulk data, GNSS. Complete device visibility via standard data model.
Transports
2 MTPs
The agent speaks WebSocket and MQTT; STOMP and CoAP are on the agent roadmap. The Aether platform terminates all four USP MTPs today. Switch MTP via UCI config — no recompile.
Security
Post-quantum mTLS
X25519 + ML-KEM-768 hybrid TLS. Certs provisioned via step-ca. Device identity anchored in PKI from first boot — not pre-shared keys.
Provisioning
Claim by proof of possession
The controller sends a one-time code to the device; you read it off the router over SSH or LuCI and enter it in the portal. A serial alone is never enough — it is on the box and in every beacon frame. Works behind NAT.
Discovery
IoT inventory
Reads dhcp.leases + /proc/net/arp → Device.Hosts.Host.{i}. IP, MAC, hostname, active state. Every device that touches the network — visible without configuration.
Location
GNSS / GPS
Serial NMEA-0183 receiver → Device location reported to controller. For outdoor CPEs, mobile deployments, and vehicle tracking. Zero extra config.
UI
LuCI app
Optional companion package. Classifies traffic with nDPI, applies app-block and threat-reputation policy in kernel, and reports per-flow detail. Installs alongside ac-client from the same feed.
Packaging
opkg package
Native package with init script and UCI config at /etc/config/optimacs. Built from the optim-wrt feed and installed with apk (or opkg on older OpenWRT). Starts on boot. Pulls in ca-bundle, iw and tc — iw and tc back the RF and bufferbloat telemetry.
Install

Three commands.
Managed router.

# 1. Add the feed to your OpenWRT buildroot or SDK echo 'src-git optimwrt https://github.com/optim-enterprises-bv/optim-wrt.git' >> feeds.conf ./scripts/feeds update optimwrt && ./scripts/feeds install -a -p optimwrt # 2. Build the agent make package/feeds/optimwrt/ac-client/compile # 3. Install it on the router ssh root@192.168.1.1 'cat > /tmp/ac-client.apk' < bin/packages/*/optimwrt/ac-client-*.apk ssh root@192.168.1.1 'apk add --allow-untrusted /tmp/ac-client.apk' # Defaults already point at the controller. Find your serial: logread | grep -oE 'oui:[0-9A-Fa-f]{6}:[0-9a-f:]{17}' | tail -1 oui:00005A:ea:5e:ca:cf:3f:18 # Sign up, then claim it with a code the router shows you.

UCI config reference

# /etc/config/optimacs — the defaults work as shipped config optimacs 'agent' option ws_url 'wss://gw.aether-io.com/usp' option ca_file '/etc/ssl/certs/ca-certificates.crt' option status_interval '60' # do not raise; see docs option mac_addr '' # auto-detected # The agent ships with a bootstrap certificate and # connects out of the box. Nothing to paste in.

Contribute or deploy.
Both are welcome.

File issues, submit PRs, package it for your router — or just install it and sign up. Three commands and the device is in your dashboard.

GitHub → Get Aether API access