Start a machine
Install
curl https://ix.dev | sh Linux on x86_64 and arm64, and macOS on Apple silicon. The Nix package has no Linux arm64 build. The installer puts ix in ~/.local/bin.
Sign in
ix login ix me ix login opens your browser once and saves the login to ~/.config/ix/config.toml. The CLI and every SDK use it. There is no token to copy.
Run a machine
ix new --name hello --no-shell
ix shell hello --noninteractive -- uname -a
ix ls
ix snapshot create hello
ix new <snapshot-id> --name hello-copy --no-shell
ix logs hello -n 50
ix rm hello hello-copy --forceix new -- uname -a boots a machine and runs one command in it. A bare ix new boots ix/debian:12; pass another image reference such as debian:12 or a snapshot id for something else.
Add --arch arm64 to pick an architecture (x86_64 or arm64), and --registry-secret <name> to pull from a private registry with a stored secret.
SDK
bun add @indexable/sdk import { Client, Machine } from "@indexable/sdk"
const machine = await Machine.create({ image: "ix/debian:12", name: "hello" })
console.log((await machine.exec(["uname", "-a"], { check: true })).stdout)
const snap = await machine.snapshot()
const copy = await new Client().snapshots.restore(snap.snapshotId, "hello-copy")
await copy.delete()
await machine.delete()CI and servers
No browser there, so use an API key. Mint one from a signed-in terminal, with a spending cap and only the access the job needs:
ix keys create ci --limit 25 --scope 'vm:*@created' The key prints once. Store it in your CI or host secret store and expose it as IX_TOKEN. The CLI and SDKs read it before the stored login. Revoke it with ix keys revoke <id>.
export IX_TOKEN="<key>" The web app also mints keys, always full access.