Run a team hub on your own network
Make one workbench or node your team's hub over Tailscale or a VPN, invite people and devices, and share projects without going through Mojo Up.
A team can work together without any platform account. One workbench (or a headless node) on the team's own network becomes the team hub; everyone else's workbenches and nodes join it with an invitation. Projects you share with the team, the task board and the inbox then go through the hub. Nothing goes through Mojo Up.
A team hub puts the workbench in the Teams edition. It is for a workbench that is not signed in to an organisation: a Mojo Up AI Cloud team or an organisation does the sharing a hub would. If you want the team hub alongside a Cloud or organisation sign-in, add it as its own space with Add a team hub of your own in the space switcher. See Sign in and spaces.
Before you start
- A network everyone can reach: a Tailscale tailnet (recommended) or a VPN you already run. The hub listens on the tailnet address only, with a certificate of its own.
- A machine that stays on. The hub must be running and connected while people work.
Make this workbench the hub
Open Settings → Team
Under Team hub, on the row This workbench is the team's hub, choose Make this the hub….
Confirm
The workbench explains that it opens its network listener on the Tailscale address only, with a certificate of its own, and that nobody can use it until you invite them. Choose Make it the hub.
Name the team and check the address
Fill in Team name (what people see when they join). The Address row shows how others reach the hub, for example this machine's Tailscale name, and Certificate fingerprint shows the fingerprint people compare when they join by address. The row's chip says running once the hub is serving.
If the address row says No address yet, connect Tailscale (or your VPN) on this computer.
To stop, choose Stop being the hub. Everyone's devices lose the hub until you turn it on again; the team's projects, boards and people are kept on this computer.
Or run the hub on a node
A headless node can be the hub instead, with no repositories of its own:
mojoup-node hub --name "Our team" --owner "Alex"It binds to the tailnet on port 7431 by default (--bind and --port change that) and prints the address, the certificate fingerprint and, with --name, the owner's first invitation. It runs in the foreground; Ctrl+C stops it. Beside it, mojoup-node hub invite, hub devices, hub approve, hub deny and hub revoke manage the team. See the command line reference.
Invite someone
Create the invitation
On Settings → Team, choose Invite someone…. Give Their name, a Role (Contributor or Viewer) and what they are Joining with (Workbench, Node or Phone). For a second device of someone already on the team, choose Another device. Choose Create the invitation.
Send the invitation line
The workbench shows the Invitation (a line starting mojoup-hub:) and the Code, each with a copy button. Send the line to the person. It works once, for 15 minutes.
Viewers can see the team's projects but cannot change them.
Join a team hub
On the workbench that is joining:
Open Settings → Team
Choose Join a team hub….
Paste the invitation
Paste the invitation line into the field. It carries the hub's address and fingerprint, so there is nothing else to check. Choose Join.
Joining by address. If you only have the hub's https:// address, paste that and type the Code (eight letters and digits, like K7QX-M2PD). The workbench then shows the hub's certificate under Check the fingerprint. Ask the hub's owner to read theirs out from Settings → Team, and choose It matches: join only if every group matches.
A node joins with mojoup-node join --hub '<invitation>'. See Join a node.
Once joined, Settings → Team shows the hub's name and connected. Leave forgets the hub: your projects stay with you as your own, the team keeps what you shared, and you need a new invitation to come back.
Approve a device that asks to join
A device can ask to join without a code, for example a node run with mojoup-node join --hub https://…. It appears on the hub's Settings → Team as "name wants to join", showing the code the device displays and where it is connecting from. Approve it only if that is the device in front of you: Approve as someone new or as an existing person's device, or Deny. A device approved this way joins as a contributor.
People and devices
The People group lists everyone on the team, their role, and the devices they joined with, and when each was last seen. Revoke a device that is lost; Remove someone who left.
The team's rules
Under Team's rules, the hub can share a policy with the whole team: what agents may do and the settings every workbench and node takes. Choose Import from a repository… to take a repository's .mojoup/policy.json, then Publish. Members pull a published policy; until then only you have it. See Policies.
Phones
The hub can invite a phone, but phones can join only through the hub machine's Tailscale name: turn on HTTPS certificates for your tailnet and bind the hub to the tailnet. Joining a team hub from the mobile app is coming.