OpenFrame Gen1 is Here

Install the OpenFrame Agent on macOS

ENDPOINT MANAGEMENTGUIDEIMPLEMENTATIONOPENFRAMETUTORIAL

Phase 2 — Device Deployment · Step 1

Section

June 18, 2026

Published

Vladislav Marchenko

Vladislav Marchenko

Head Of Marketing

Time to get a real machine reporting in. The OpenFrame agent is a single command — it pulls the client, installs it, and registers the Mac to the customer you choose. This walks you through doing one Mac by hand so you understand the flow before you deploy at scale.


Before you start

  • You need an Admin role in OpenFrame.
  • Have admin (sudo) rights on the Mac you're enrolling — the installer needs them.
  • Know which customer this device belongs to. The wrong customer means the device shows up under the wrong client, so get this right at install time.
  • macOS will likely flag the install at first (it's new software without an established reputation). That's expected — see Troubleshooting below.

Get the install command

  1. Left nav → DevicesAdd Device.
  2. Under Select Customer, pick the client this Mac belongs to.
  3. Under Select Platform, choose macOS.
  4. (Optional but recommended) Click Add Device Tag to attach tags now — e.g. Type: laptop or Purpose: workstation. Tagging at install saves you sorting devices later (see Organize Devices with Device Tags).
  5. Your install command appears under Device Add Command. Click Copy Command.

The command looks like this (your key and org ID are baked in — don't share them around):

bash
cd ~ && rm -f openframe-client_macos.tar.gz openframe-client 2>/dev/null; \
curl -L -o openframe-client_macos.tar.gz '<openframe release URL>/openframe-client_macos.tar.gz' && \
tar -xzf openframe-client_macos.tar.gz && \
sudo chmod +x ./openframe-client && \
sudo ./openframe-client install --serverUrl <your-tenant>.openframe.ai --initialKey <YOUR_KEY> --orgId <YOUR_ORG_ID>

In plain terms: it downloads the macOS client, unpacks it, makes it executable, and runs install pointed at your tenant with an enrollment key and the customer's org ID.

The --initialKey is a live enrollment token. Treat the copied command like a credential — don't paste it into a public channel or a ticket a client can read.


Run it on the Mac

  1. On the target Mac, open Terminal.
  2. Paste the command and hit Return.
  3. Enter the local admin password when sudo prompts.
  4. Let it finish — it downloads, installs, and registers in one go.

That's it. No reboot needed.

Shortcut for the machine you're on: if you're enrolling the Mac you're currently using, the Add Device screen has a Run on Current Machine button instead of copy-paste. Handy for your own workstation; for everything else you'll use the copied command.


Confirm it worked

Head to Devices — the Mac should appear with an Online status within a minute or two. For the full verification and what to do if it doesn't show up, see Confirm Your First Device Is Connected.


Troubleshooting

macOS or your AV blocked the install. This is the common one, and it's a false positive — new software just hasn't built reputation with security vendors yet. If the client gets quarantined, add these to your antivirus / security tool's exclusions:

  • /Library/LaunchDaemons/com.openframe.client.plist
  • /Library/Application Support/OpenFrame/meshcentral-agent/

Or temporarily disable protection for the duration of the install, then re-enable it. OpenFrame is open-source software you can inspect on GitHub.

sudo rejected the password / permission denied. The account isn't a local admin. Use an admin account or have one handy.

Command fails to download. Check the Mac has outbound internet and isn't behind a proxy or content filter that blocks GitHub release downloads.

It installed but shows Offline. Give it a couple of minutes. If it persists, see the troubleshooting steps in Confirm Your First Device Is Connected and Troubleshooting a Disconnected Device (Phase 10).


Quick checklist

  • Selected the correct customer
  • Chose macOS and (optionally) added tags
  • Copied the command and ran it in Terminal with sudo
  • Added AV exclusions if the install was blocked
  • Confirmed the Mac shows Online under Devices

What's next

Got a Mac in? Do the same for a PC — Install the OpenFrame Agent on Windows — then verify both with Confirm Your First Device Is Connected.


Based on OpenFrame v0.9.19. The install command and client version come straight from your console's Add Device screen — always copy the current one rather than reusing an old command.

Vladislav Marchenko

Head Of Marketing

Hi all! My name is Vlad and I’ve been brought on to head the marketing team at Flamingo. Thankfully, this isn’t the first time I will be building a marketing department from scratch, so the experience should come in handy. Now it’s time to dive into the world of MSPs and find myself in this new world.

More in Phase 2 — Device Deployment

Related Content

Product Releases

Webinars

Case Studies

Blog Posts

Frequently Asked Questions

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.

EDR Security

SentinelOne is a strong fit for MSPs that want autonomous detection, one-click ransomware rollback, and real multi-tenancy across Windows, macOS, and Linux. The trade-offs are a dense console, premium pricing, and a tuning period that produces false positives early on.

Endpoint Security

Yes, for security-led MSPs and MSSPs serving mid-market or compliance-driven clients. The detection and threat hunting rank at the top of the market, and Flight Control handles multi-tenant management. It fits poorly for books made up of many small clients on tight budgets.
Bitdefender GravityZone is a cloud-native endpoint protection platform that combines prevention, EDR, and XDR in one agent and console. For MSPs, it adds multi-tenant management, so one team can protect and monitor every client's endpoints from a single dashboard.
Yes, for MSPs that want one vendor across endpoint, firewall, and managed detection. Sophos Central Partner gives true multi-tenant control, and MSP Connect Flex bills monthly by usage. Plan around occasional CPU spikes on busy servers and a console learning curve.

Sophos XDR

Sophos XDR is extended detection and response built on Intercept X. It correlates telemetry from endpoints, the Sophos firewall, email, cloud, and identity inside Sophos Central, then lets technicians hunt across that data with Live Discover queries.

Microsoft Defender XDR

Microsoft Defender XDR is Microsoft's extended detection and response suite. It unifies endpoint, email, identity, and cloud-app threat signals into one Defender portal, correlating related alerts into single incidents so teams investigate one timeline instead of chasing scattered, disconnected alerts.

EDR Comparison

It depends on the job. SentinelOne has the higher endpoint score, a 4.7 on G2, and stronger autonomous response. Sophos wins on breadth and price, pairing endpoint with firewall and a 4.7-rated MDR service from one console.