---
name: oracle-thin-client
description: Use when a laptop or desktop should attach to an Oracle desk the user hosts on their own network.
---

> Oracle native tools: `oracle_cli`, `vault_status`, `signer_status`, `signer_execute`. No fleet SSH. No one else's box.

# Thin client (your desk, your machines)

A thin client is **your** laptop talking to **your** Oracle desk. It is not a shared house server and not someone else's Tailnet.

## Default (no thin client)

```text
oracle setup model
oracle chat
```

Desk, vault, and signer stay on this machine (`127.0.0.1`).

## Optional: desk on machine A, chat on machine B

Both machines must be yours. Keys stay on the signer host.

On the desk host, bind data/public only as far as you intend (loopback, LAN, or your tailnet). Never `0.0.0.0` for exec/signer.

On the client, point at **your** desk URLs — placeholders only:

```json
{
  "deskUrl": "http://YOUR_DESK_HOST:8799",
  "dataUrl": "http://YOUR_DESK_HOST:8799",
  "publicUrl": "http://YOUR_DESK_HOST:8799"
}
```

Write that to `~/.config/oracle/desk.json` (mode 0600). Do not commit it. Do not copy another person's file.

`oracle doctor` must probe `/health` and `/public/health` on those URLs.

## Signer

The loopback signer (`oracle signer`) stays on `127.0.0.1` on the machine that holds the vault. A thin client does not get a remote private key.

## Related

`oracle-tailscale` · `oracle-native-harness` · `setup`
