Prepare the service first
Obtain a version-compatible endpoint, enrollment details and client credential from the relay operator. Use the installation instructions bundled with that release's official relay kit. Adding an address to OmniTerm does not deploy a relay, enroll an agent or authorize a destination.
The app has two different configuration surfaces. Registering a service in the relay list is not the same as configuring a device-owned, client-to-agent connection.
Register a relay service
Where relay management is enabled, open Proxies & Tunnels → Relays and choose Register Relay Server. Enter Relay Name, Relay URL (host:port) and the client token required by your operator, then choose Register.
The form calls the token optional because not every configuration uses that field. This does not override a service that requires authentication. Never enter an operator-only management credential. The official OmniTerm relay cannot be edited or deleted in this list.
Configure a device-owned route
For an eligible native SSH profile, open Network & Proxy and choose Configure device-owned WebRTC / WebSocket relay. This opens Device-owned relay; it is not offered for browser profiles or account-issued managed targets.
- Obtain the enrolled agent, owner and target details through the operator's trusted setup process.
- Verify the full agent and target SSH fingerprints independently.
- Store the relay token and client private key in the credential store first. Enter their secure-store references, not the secret values, in this dialog.
- Select Transport for new connections and review the optional customer-owned TURN and public STUN settings.
- Choose Apply to profile, save the host, and test a new authenticated connection.
Changes apply to new connections, not an already running session. Remove; use direct network removes this profile's device-owned route; it does not shut down the relay service.
Verify the actual workflow
A reachable endpoint is not proof that an agent is online or that destination authentication works. Test a terminal, then the specific file or forwarding operation you need. A relay kit does not automatically supply a cloud workspace or sharing service.
Keep credentials out of screenshots and shared URLs. Do not disable certificate checks. A restart can interrupt active sessions; a token change does not by itself prove every existing connection has stopped. Use explicit termination controls and confirm the result when urgently removing access.
See transport selection and troubleshooting for distinguishing reachability, authentication and capability failures.