Learn · Lesson 4 of 7 · 4 min
Enroll machines without a browser
A server or CI runner can join without anyone opening a browser. A node auth key carries its enrollment settings and tags.
Decide how the machine should join.
Open Keys → Node Auth Keys. Here’s an example for short-lived CI runners.

ci- Expires in
- 30 days
- Reusable
- On · used by multiple runners
- Ephemeral
- On · removed on disconnect
- Auto approve
- On · no approval queue
The key is shown once. Save it in your secret manager.
Two commands. No browser.
Inject the saved key as BG_AUTH_KEY in your job environment, then run:
baseguard login --auth-key "$BG_AUTH_KEY"
baseguard connectThe runner arrives with its tag.
ciThe key assigns the tag. Your network rules determine what the runner can reach.
For persistent servers, leave Ephemeral off. For a fleet sharing one key, enable Reusable.
A few useful details
Defaults. Reusable and Ephemeral are off by default. Node Auto Approve is on. An expiry of 0 means the key never expires.
Single-use keys. A consumed key cannot enroll a second machine. Use a reusable key when multiple machines share the enrollment workflow.
Expiration. Expired keys cannot enroll machines. Rotate the secret before the key expires.
Ephemeral nodes. When the node disconnects, its entry and name are removed. Use this for temporary jobs.
Next, give your private services names people can remember.