---
title: "Panel Pairing"
url: "https://control.actana.ai/docs/pairing/panel-pairing"
description: "Add a Core in the Panel: address, fingerprint compared before the code is sent, then session and code."
updated: 2026-09-01T09:03:06+00:00
---

You are enrolling the Panel as a client of a Core. Mint the ticket on the Core first — [`actana pair new`](/docs/pairing/create-a-pairing-code) — then spend it here.

Two doors to the same form:

- **A Panel with no Cores yet** opens straight into the [first-run wizard](/docs/panel/first-run) — there is nothing else to show. The wizard carries the install commands for a machine that has no Core yet, and this same pairing form.
- **A Panel with a fleet**: Settings (gear icon) → **Cores** → **Add a Core**.

## Address, then fingerprint, then code

Enter the Core address the Panel can actually dial:

- Compose, Panel and Core on one network: `core:8443` — the service name; the Core publishes no host port, the Panel reaches it over the compose network.
- Metal, or a Core the Panel reaches by name: `host:8443` — an entry of that Core's `ACTANA_PUBLIC_HOST`, a SAN on its server certificate.

**Check fingerprint** before anything secret is typed. The Panel dials with nothing trusted and **sends nothing**. It shows the CA fingerprint that machine presented; compare it against the `CA fingerprint` line of the handout. A mismatch stops — the code fields are not shown, and the code is not sent. [Why the fingerprint exists](/docs/pairing/how-pairing-works#the-ca-fingerprint).

Only after they match do **Session** and **Pairing code** appear. The session id is part of the ticket, not optional. Then the eight-character code — hyphen and case are yours to get wrong. The name in this Panel is optional; empty falls back to the endpoint host.

After a 200, the Core appears in [Fleet](/docs/panel/fleet). The credential is sealed on the Panel server; the browser never sees the private key.

## Address already registered

If this Panel already has a Core at that endpoint, pairing refuses **before** spending the code — you get the registry's sentence, not a spent ticket.

That matters after [`actana token regenerate`](/docs/pairing/create-a-pairing-code#rotate-the-ca). Rotation does not move the endpoint, so a second **Add a Core** at the same address is refused until you remove the Core (Settings → Cores → Remove Core), then mint a fresh code and add it again. [`actana core pair`](/docs/pairing/cli-pairing) is different: it replaces the stored credential in place.

## What the Panel must reach

The Panel dials the Core, never the reverse. If 8443 is unreachable from the Panel host, the fingerprint check fails and nothing is paired. In compose, that path is the service name on the compose network, not `localhost` on your laptop.

## See also

- [Create a Pairing Code](/docs/pairing/create-a-pairing-code)
- [How Pairing Works](/docs/pairing/how-pairing-works)
- [First-Run Wizard](/docs/panel/first-run)
- [Pairing Troubleshooting](/docs/pairing/troubleshooting)
