Get Started
lnk is a small core, and each part of Link is a plugin, the way
git runs git-<name>. The core only installs, runs, updates and
removes plugins, so you have only what you use, and one plugin can't
break another. To install lnk and pick your first plugins:
Install.
Needs: lnk (Install). Free.
Quickstart
lnk plugin list # what's installed
lnk plugin add telegram # add one, with what it needs
lnk upgrade # lnk and its plugins, to the latest releaseWhat each choice installs
lnk up asks which parts you want and installs their plugins:
| You pick | Plugins | Commands |
|---|---|---|
| agents | sandbox, harness, link-harness | lnk agent, lnk sandbox |
| models | models | lnk model |
| tunnels | tunnel, accounts | lnk tunnel, lnk auth |
| buckets | bucket | lnk bucket |
| boxes | cloud, accounts, box, vpn, sandbox | lnk cloud, lnk auth, lnk box, lnk vpn, lnk sandbox |
| memory | link-memory, models (and sandbox, harness) | lnk agent memory |
More come when you need them: a harness (openclaw, hermes,
deepseek) when you lnk agent use it, a channel
plugin (telegram, slack, discord, whatsapp, signal) when you
connect one, link-memory when you turn on your agent's memory (lnk agent memory use) without picking memory, and aws or gcp when you connect that cloud.
Add or remove a plugin
lnk plugin list # every plugin, and which are installed
lnk plugin add telegram # also installs harness and sandbox, which it needs
lnk plugin remove bucket # stops what it runs, deletes the program; its settings and files stayaddinstalls from the release oflnk's own version, with the plugins it needs: a harness, a channel orlink-memoryneedsharness, which needssandbox;awsandgcpneedcloud;tunnelneedsaccounts, whoselnk auth loginit connects with;boxneedscloudandaccounts, whose login tags your boxes as yours;vpnneedssandbox, whose proxy is its exit's home side.removealso removes what needs the plugin:remove harnesstakes every harness (link-harness,openclaw,hermes,deepseek),link-memoryand the channels,remove cloudtakesaws,gcpandbox. Each stops what it runs first (remove harnessstops your agents).- Run a command whose plugin you don't have, and
lnkoffers to install it. Outside a terminal it fails and nameslnk plugin add <plugin>. The same goes for a plugin it needs that isn't installed, such asaccountsforboxortunnel.
Add a plugin from outside Link
A harness Link doesn't ship comes from its own GitHub repository, signed by its maker's key, not Link's. The ones Link ships are under Use another harness.
lnk plugin add https://github.com/<owner>/<repo> # shows its key and asks
lnk plugin add https://github.com/<owner>/<repo> --yes # in a script: trusts the key without asking
lnk plugin list # Link's plugins, then those from outside, with where from
lnk plugin remove <name> # the program, and lnk's trust in its keyaddinstalls the plugin from the repository's latest release. The first time, it shows the release's key and asks;lnkthen keeps the repository and the key in~/.config/lnk/plugins.toml.lnk upgradeupdates it from the same repository, only with a release signed by that key.- It may only be a harness adapter: one that doesn't answer the harness contract isn't installed.
- It runs as you, like any program you install. Link's sandbox confines the harness it installs, not the plugin itself (Security).
lnk agent moveto a box adds it there from the same repository, trusting only the key this computer trusted.
Upgrade
lnk upgrade # lnk and every installed plugin, to the latest release
lnk upgrade 0.11.0 # or to this versionEach release is checked against its signature first; if anything fails,
what you have stays as it was. The relay tells a connected lnk when a
newer release exists.
Uninstall
lnk uninstall # asks what else should go
lnk uninstall --yes # only lnk and its plugins
lnk uninstall --yes --delete agents,relay # and these partslnk uninstall has each plugin stop what it runs (your agents, your
exits), and removes lnk and its plugins.
Everything Link kept stays unless you pick it, so installing again
picks it up. Each plugin names what it keeps; Link's own parts:
| Part | What goes |
|---|---|
agents | Your agents, their memory, settings and keys |
personal | Your files in ~/Link/Personal |
buckets | Bucket settings and encrypted buckets' passwords |
clouds | Cloud keys and Link's SSH key to your boxes |
relay | Your relay login |
rest | Everything else in ~/.config/lnk and ~/Link |
all | All of them |
- Back up an agent first with
lnk agent backup:agentsdeletes its memory and conversations. personaldeletes files you never pushed to a cloud, andbucketsdeletes the only copy of encrypted buckets' passwords.cloudsleaves your boxes running, and billing.resttakes folders you made in~/Linktoo.- On a Mac, each part's Keychain items go with it.
- Another program named
lnk-*besidelnkgoes too (what it may run). - It leaves your relay login on the relay's list, anything in your
clouds, and the bots and apps you made for channels: delete a Telegram
bot with BotFather's
/deletebot, a Slack app at api.slack.com/apps, and a Discord application; unlink WhatsApp or Signal on the phone. - Installed with Homebrew, it prints the command that removes the
programs. Installed with cargo, it prints
cargo uninstallwith the crates cargo installed them from, and deletes any it doesn't track.
Get help
lnk help # every group and command
lnk help bucket push # one command, with every flag
lnk agent --helpWhere things live
~/.local/bin/lnkandlnk-<plugin>: the core and its plugins, side by side.LNK_INSTALL_DIRmoves them.~/.config/lnk: Link's settings, each plugin's.plugins.tomlis where each plugin from outside Link comes from, and its key.~/Link: your files (Personal) and your agents' (Agents).
Troubleshooting
| Symptom | Fix |
|---|---|
| A command says its plugin isn't installed | lnk plugin add <plugin> |
| "isn't a harness adapter" | Only harnesses are added from outside Link |
| A plugin from outside Link "not upgraded: ... doesn't trust" | Its release is signed by another key: if its maker says they changed keys, lnk plugin remove <name>, then add it again |
| "The plugin at ... isn't in lnk's folder" | Remove it the way you installed it |
What's checked before anything installs: Security. Why it works this way: Decisions. How plugins are built: plugins.md.
