Guardian setup guide · Manifold Fedimint Guardian

Run a Manifold Fedimint Guardian and earn sats hosting seats

Show steps for
Walkthrough · 3 minutes · UmbrelStart9

Manifold Fedimint Guardian install step by step guide

00 · How it works

Four things happen, in this order

Manifold Fedimint Guardian is the guardian software behind Manifold. It runs one Fedimint guardian process per seat you sell, validates against a Bitcoin Core node on the same box (on StartOS, Bitcoin Knots works as well), and handles the selling for you. It is not a Lightning wallet, and it does not replace the Bitcoin node: it needs one.

Step zero: get your PeerBadge. Ambassadors only see fleets that a PeerBadge holder at Trusted level or higher has authorized, and that holder is you: during setup you sign the authorization with your own badge. Get the badge before you buy hardware or start the node; the FAQ says where to ask.
1

Prepare the box, start the node

umbrelOS on a mini PC with a 500 GB SSD, then Bitcoin Core.Your Umbrel, then its Bitcoin Node app.Your Start9 server on the latest StartOS 0.4 stable, then Bitcoin Core. Its sync takes days, so it goes first and runs in the background.

2

Install and set up the guardian

The guardian app installs from a store and holds a small fleet of guardian seats. Setup is a five screen wizard in your browser.

3

Get advertised, sell seats

Once you have authorized your fleet with your PeerBadge and set a price, your open seats are announced on Nostr. An Ambassador in the Fedi app picks a set, pays once, and your box starts one guardian per seat sold.

4

Earn and withdraw

You receive the seat price up front and a share of that federation's transaction fees for as long as it runs. Both leave to a Lightning address from the Payouts page.

Words used on this page. A seat is one guardian slot you offer. A Federation Ambassador is the person creating a federation in the Fedi app (the code and the API still call them the initiator). The dashboard is the guardian software's own web page, served by your box. The node is the Bitcoin Core you run on the same box; the guardian validates against it.
01 · Requirements

What you need before you start

A guardian is a small, always on server: a Start9 or Umbrel, or a mini PC you set up yourself, with a Bitcoin node on it, and patience for one long sync. It still needs no public address, no domain and no certificate, because the whole protocol was designed to run from a home connection.

A mini PC with a 500 GB SSDAn Umbrel with a 500 GB SSDA Start9 server on the latest StartOS 0.4 stable

Any 64 bit Intel or AMD PC; a refurbished corporate mini is the sweet spot. Aim for a quad core, 16 GB of RAM and a 500 GB SSD as the system disk, because the chain and your seats live on it. New box? Prepare the mini PC walks through the one time install; umbrelOS is x86 only.

An Umbrel Home comes with 16 GB of RAM and a 1, 2 or 4 TB SSD: with a pruned node any of them is enough, the 1 TB model included. Running umbrelOS on your own x86 box? Aim for a quad core, 16 GB of RAM and a 500 GB SSD as the system disk; Prepare the mini PC covers the install.

A Start9 server comes with StartOS installed and at least a 2 TB drive, so there is nothing to build. Before you start, update it to the latest StartOS 0.4 stable release (System › Software Update): the package sideload fails on 0.4 beta builds. Running StartOS on your own x86 or ARM box? Aim for a quad core, 16 GB of RAM and a 500 GB SSD as the system disk, because the chain and your seats live on it.

  • Wired ethernet to your router. Wi‑Fi will not get you through setup or the sync.
  • A laptop or phone on the same network with a browser.

RAM decides how many seats you can sell

Each seat is a separate guardian process, and Bitcoin Core on the same box takes 2 to 3 GB for itself. The dashboard recommends one seat per 1.5 GB of RAM that is free when it starts, capped at 8. You can override the number, but the recommendation is a safe default.

Box RAMSeats, node running
8 GB2 to 3
16 GB8, the cap
32 GB8, the cap, with room to spare

16 GB is the comfortable minimum for a guardian that also runs its own node.

A Bitcoin Core node on the same box, no public IP

The guardian validates against your own Bitcoin Core, pruned or full (Bitcoin Knots works as well). Bitcoin node installs it; its sync takes days, which is why it comes before the guardian in this guide. Everything on the network side is outbound or hole punched: nothing to forward, no certificate to buy.

  • Optional: forwarding UDP 31000 to 31031 on your router improves direct connections between guardians. Without it, traffic falls back to public relays and still works.

A Lightning address for payouts

Everything you earn leaves to one Lightning address or LNURL-pay link that you save once. A bolt11 invoice is not accepted because it is single use.

A PeerBadge, before anything else

Ambassadors only see fleets whose key carries an authorization from a PeerBadge holder at Trusted level or higher, and that holder is you. The dashboard shows your fleet's public key as a QR code; you scan it with the credential app that holds your badge, and the app publishes the authorization. Get your badge before you start, ahead of hardware and the node; the FAQ lists where to ask.

Pen, paper, and patience

The wizard shows a 12 word recovery phrase exactly once. Write it on paper before you continue: it is the entire identity of the fleet and its only backup. Plan about an hour hands on, the node sync running for days in the background, and however long the badge takes to arrive.

02 · Prepare the mini PC

From a box in a drawer to umbrelOS on your network

Twenty minutes with a screen, once. This is the part most guides skip: nobody mentions that a monitor and a keyboard are needed, once. Written for umbrelOS 1.7.4, the current stable release.

The box

Any 64 bit Intel or AMD mini PC. Refurbished office minis are cheap and quiet: Lenovo ThinkCentre Tiny (M720q, M920q), HP EliteDesk 800 Mini, Dell OptiPlex Micro, Intel NUC. 16 GB of RAM runs the node and the full 8 seats; 8 GB leaves room for 2 or 3.

Fit a 500 GB SSD or larger before you install, and install umbrelOS onto it. On umbrelOS 1.x every app, the Bitcoin node included, keeps its data on the disk umbrelOS lives on, so the big disk has to be the system disk. Most office minis take a 2.5 inch SATA or M.2 drive; the Tiny takes both.

Needed once, for the install

  • A monitor or TV with HDMI or DisplayPort, and the cable.
  • A USB keyboard.
  • A USB stick of 4 GB or more. It gets erased.
  • An ethernet cable from the box to your router.
  • A second computer to download and flash from. Mac users: check you have a USB A port or an adapter for the stick.

Not this

  • Wi‑Fi. The install and the app both want a wire.
  • ARM boards, phones, Apple silicon. umbrelOS on x86 only.
  • umbrelOS 2.0 beta. The downloads page leads with it; stay on 1.7.4 stable for a guardian box.
  • Running umbrelOS from the USB stick itself. Install it onto the internal disk.
  1. Download the umbrelOS USB installer and check it

    Two x86 files exist. You want the USB installer, which copies umbrelOS onto the internal disk. The other one, the plain disk image, runs umbrelOS off the stick and wears it out.

    https://download.umbrel.com/release/1.7.4/umbrelos-amd64-usb-installer.iso

    Then check the download against Umbrel's published checksum. The expected value for this file is:

    d30f4e495630b79e946cb6e98cc0f0404a72f69291df5debd7e8908bf106ac40

    macOS: shasum -a 256 umbrelos-amd64-usb-installer.iso · Windows PowerShell: Get-FileHash umbrelos-amd64-usb-installer.iso · Linux: sha256sum umbrelos-amd64-usb-installer.iso. The full list is at download.umbrel.com/release/1.7.4/SHA256SUMS.

  2. Flash it to the USB stick

    balenaEtcherFlash from filethe .isoSelect target: your stickFlash

    Get balenaEtcher from etcher.balena.io. On Windows, Rufus does the same job. Everything on the stick is erased.

  3. Plug in and open the BIOS

    Connect monitor, keyboard, ethernet and the stick. Unplug any external drive so you cannot install onto it by mistake. Power on and tap the setup key at the maker's logo: Lenovo F1, HP Esc then F10, Dell F2, Intel NUC F2.

  4. Three settings, then save

    Secure Boot: Disabled. umbrelOS's bootloader is unsigned; with Secure Boot on, the stick will not boot and you get a "Secure Boot Violation". On a Lenovo it is under Security. Keep UEFI; do not switch to Legacy or CSM. After power loss: Power on (Lenovo: Power › After Power Loss), so the box comes back by itself after an outage. A guardian that stays off until someone presses a button is a guardian that is down. Save and exit, usually F10.

  5. Boot from the stick

    Open the boot menu at the logo: Lenovo F12, HP F9, Dell F12. Pick the entry that starts with UEFI: and names your stick, not a plain "USB HDD" entry.

  6. Install onto the internal disk

    The installer lists the disks it found. Type the number of the internal SSD, recognised by its size (about 238 GB for a 256 GB drive, about 1.8 TB for a 2 TB one), never the stick. If you fitted an SSD for the Bitcoin node, this is the moment it matters: pick that disk. It starts writing immediately, without a confirmation. When it reports that umbrelOS has been installed: power off, remove the stick, power on.

  7. First boot and account

    Give it about five minutes. On your other computer open http://umbrel.local. On Windows try http://umbrel, or find the box's address in your router's device list and open that. Create the account and put the password in a password manager: on Umbrel it is also what protects the guardian dashboard. In Settings, install any 1.x update it offers.

  8. Unplug the screen, fix the address, walk away

    Monitor and keyboard can go. In your router, give the box a fixed address (a DHCP reservation) so umbrel.local keeps resolving after reboots. A small UPS is worth it if your power is unreliable. Then continue with Install.

Next: the Bitcoin node, before the guardian. Its sync is the longest step of the whole setup and everything else can proceed while it runs. The one choice that cannot be fixed later without a reinstall is the disk umbrelOS went onto.
03 · Bitcoin node

Install the Bitcoin node first and let it sync while you do the rest

A mainnet guardian validates against a Bitcoin Core node you run on the same box, pruned or full. The initial sync is the slowest step of the whole setup, one to three days on an SSD and one to two weeks on a spinning USB disk, so it comes first: start it now, then carry on with the guardian install and setup while it runs. Nothing later waits for it, except selling your first seat.

Disk: 500 GB, and it must be the system disk

A pruned node keeps only recent blocks: with a 10 GB prune target it settles between 35 and 115 GB, which is what this guide assumes. The full chain is about 760 GB today and grows 60 to 80 GB a year, so run pruned unless you have the disk to spare. Any Umbrel Home passes this, the 1 TB model included. On umbrelOS 1.x apps keep their data on the disk umbrelOS was installed to, so the big disk has to be the one you installed onto. If umbrelOS is on a very small drive, fit a larger SSD and reinstall; a guardian comes back from its 12 words.A Start9 server ships with far more room than a pruned node needs, so there is nothing to change. StartOS on your own box: services live on the data drive, so install StartOS onto the 500 GB SSD.

Time: leave it on and wired

Expect one to three days on an internal SSD with a decent connection, one to two weeks on a spinning USB disk, longer on Wi‑Fi or a metered line. The box must stay on the whole time. The After Power Loss BIOS setting from the mini PC section is what makes that survivable.

What to keep at the end

Three values the guardian may ask for: the node's RPC address, RPC username and RPC password. On both platforms the guardian normally reads them from the node it depends on, so you may never type them, but put them in your password manager the day you set the node up.

  1. Check the disk before anything else

    umbrelOSSettingsStorage

    You need about 100 GB free today; 500 GB is comfortable for years. Less than that means the node fills the disk mid sync and stops. If the number is too small, go back to Prepare the mini PC, fit the SSD, and reinstall onto it.

  2. Install the Bitcoin Node app

    App StoreBitcoinBitcoin NodeInstall

    This is Umbrel's official app, powered by Bitcoin Core, in the main App Store rather than the Fedi Dev one. Version 1.4.0 (Sep 2026) ships Bitcoin Core v31.1. It starts syncing the moment it is installed. Prefer Knots? Umbrel's Bitcoin Knots app implements the same dependency, so the guardian app accepts it in place of Bitcoin Node and should work as well; the settings below are Bitcoin Node's.

    Bitcoin Node on apps.umbrel.com →   Source on GitHub →

  3. Five settings to check, once

    Bitcoin NodeSettings

    The app has over twenty advanced settings. Only these matter for a guardian:

    SettingValueWhy
    Prune Old Blocks10 GBKeeps the node between 35 and 115 GB. Tested across seven production guardians in September 2026; umbrelOS reclaims the space on its own once the node catches up.
    Bitcoin NetworkMainnetThe default; the guardian needs the main network.
    Bitcoin Core VersionAlways use the latest versionKeeps the node current; v31.1 as of September 2026.
    Enable Transaction IndexingOffumbrelOS turns it off for you when pruning is on. An index written before you enabled pruning stays on disk: it is dead weight rather than a problem, and clearing it is optional.
    Cache Size2000 MB on a 16 GB box, 1000 MB on 8 GBSpeeds up the initial sync noticeably. You can lower it again afterwards.

    Leave Max Upload Target alone unless your line is metered, and leave the peer connection settings on their defaults. Changing settings restarts the node, which pauses the sync for a minute.

  4. Watch the sync, and know how to read it

    The app's home screen shows the current block height, a Synchronizing percentage and the peers it is connected to. The percentage misleads: it is weighted by transactions, and early blocks hold almost none, so it sits under 1 percent for the first day while the block count climbs past hundreds of thousands, then races through the last years. Watch the block height instead and compare it with a public explorer such as mempool.space; when the two numbers match, the sync is done.

    Umbrel's Bitcoin Node app, fully synchronized: block height, peers and latest blocks

    What a synced node looks like. Umbrel's Bitcoin Node app once it has caught up: Synchronized 100%, peer connections, latest blocks. Image from the app's store listing.

  5. Know where the RPC details live

    Bitcoin NodeConnectBitcoin Core RPC

    The guardian app declares Bitcoin Node as a dependency and reads the RPC connection from it, so you should not need to type anything. If the wizard ever asks, the Connect panel shows Host, Port (8332), Username and Password. The password is generated by the app and always visible here, so it cannot be lost, but a reinstall of the app generates a new one.

    The Connect panel of Umbrel's Bitcoin Node app showing RPC username, password, host and port

    The Connect panel. RPC Details is the tab with the username, password, host and port. Image from the app's store listing.

  6. Done when

    • Block height matches the explorer and the app no longer says Synchronizing.
    • Prune Old Blocks is set to 10 GB and the disk still shows at least 10 percent free.
    • You know where the RPC details are (Bitcoin Node › Connect), in case the app ever asks.
    • The box has been left on since; a node that is switched off falls behind and has to catch up before a guardian can use it.
  1. Install Bitcoin Core from the Start9 registry

    StartOSMarketplaceBitcoin CoreInstall

    Start9's own package, Bitcoin Core v31.1 (release v31.1_16, Sep 6, 2026). Bitcoin Knots from the same registry works as well; this guide follows Bitcoin Core. It installs onto the StartOS data drive, which on a Start9 server is already 2 TB or more.

    Package on GitHub →   Start9 Bitcoin guide →

  2. Set pruning before the sync gets far

    Bitcoin CoreActions

    Start9's package sizes itself to the disk: on a drive under about 900 GB it installs pruned, on anything larger it defaults to a full archival node. A guardian is happy either way. To run pruned on a larger drive, open Actions › Other, enable pruning, set the target to 10000 MB, turn the transaction index (txindex) off, and save. StartOS reclaims the space on its own once the node catches up.

  3. Watch the sync

    The service page shows the block height and sync state. Start9 quotes "under a day to several days" depending on hardware and bandwidth; a spinning USB disk stretches that to weeks. Compare the block height with mempool.space; matching numbers mean done.

  4. Know where the RPC credentials live

    Bitcoin CoreProperties

    On StartOS the guardian package reads the node's RPC address and credentials from the Bitcoin Core service it depends on, so you should not need to copy anything. If the wizard ever asks, Properties shows the RPC username and password (and a QuickConnect code for wallets). If a password is ever lost, the Delete RPC Users action removes the old user so a new one can be created.

How the guardian finds the node. The guardian app takes the node's RPC address and credentials from the platform: on Umbrel, apps normally read them from the Bitcoin Node app they depend on; on StartOS, from the Bitcoin Core service. Keep the details in your password manager in case the app asks for them.
04 · Install

Install on Umbrel

Install on Start9 (StartOS)

The guardian software is published in a community app store, so Umbrel installs and updates it like any other app. Umbrel's own login protects the dashboard, so there is no extra password.

StartOS installs the package from a single file you download from GitHub and sideload. The dashboard has its own generated password, shown by an action inside StartOS.

  1. Have umbrelOS running, up to date, and open its dashboard

    Install umbrelOS on the box if you have not (umbrel.com/umbrelos: flash a USB stick, boot the box from it, follow the on screen setup). Then open the Umbrel dashboard from a browser on the same network, sign in, and take any pending umbrelOS update from Settings before you add the store, so the app meets a current OS.

  2. Add the Fedi Dev community app store

    App Store⋯ menu, top rightCommunity App Stores

    Paste this address and click Add:

    https://github.com/fedibtc/manifold-umbrel-store.git

    The store is public. Nothing to log into and no token to paste.

  3. Install Manifold Fedimint Guardian, the mainnet one

    Open the new Fedi Dev store. It lists two guardian apps side by side: install the one called just Fleet Manager (tagline "Run Fedimint guardians on Bitcoin mainnet"); that is Manifold Fedimint Guardian under its technical name. Fleet Manager (staging) next to it is a test network build: skip it. Umbrel lists Bitcoin Node as the app's dependency and offers to install it if it is missing, or lets you pick Bitcoin Knots in its place if that is the node you run. The image pulls from GitHub's registry; the first pull takes a minute or two.

  4. Open the app

    Click the app tile. The dashboard opens behind Umbrel's own login, so you are already signed in. It lands on the setup wizard described in the next section.

    Known quirk. The screen before the wizard may briefly flash an [object Object] error. It is a display bug; the wizard works. Reload if it does not appear within a few seconds.
  1. Make sure StartOS is on 0.4.0 stable or later

    SystemSoftware Update

    On a 0.4.0 beta build the sideload page fails with an alerts is undefined error. Update the OS first.

    Bare mini PC? StartOS installs like umbrelOS does: download x86_64.iso from Start9's releases, flash it with balenaEtcher to an 8 GB stick, boot from it with Secure Boot off, and run the setup wizard at http://start.local. Start9's guide: docs.start9.com › flashing guides › x86. The mini PC shopping list and BIOS settings in this guide's Mini PC path apply to StartOS too.

  2. Download the package file

    From the latest production release of the packaging repo, download fleet-manager_x86_64.s9pk (about 53 MB). ARM servers take fleet-manager_aarch64.s9pk instead. Skip any file with a fedi-dev- prefix: that is the staging build.

    Latest release on GitHub →

  3. Sideload it

    Top navigation barSideload

    Drop the file in and wait for the install to finish. The image is embedded in the file, so the box never pulls from a registry.

  4. Start the service and wait for the health check

    Start the Manifold Fedimint Guardian service (listed under its technical name, Fleet Manager) and wait until the Operator Dashboard health check turns green.

  5. Get the dashboard password

    Actions tabShow Dashboard Password

    Copy it. StartOS has no authenticating proxy in front of apps, so the dashboard protects itself with this generated password.

  6. Open the dashboard and sign in

    Use the interface's address entries, the Local https://… one, and accept the self signed certificate warning (unless you have installed your server's root certificate). Enter the password on the Sign in screen.

    Known StartOS quirk. If you browse StartOS from the server itself (a kiosk, or a browser inside a VM), the Open button builds a dead 127.0.0.1 link. Use the address entries instead.
05 · Set up the fleet

The five screen setup wizard

Setup happens once, in the dashboard. Every step is saved as you go, so a closed tab or a restarted box resumes where you left off. The same five screens on Umbrel and Start9. The dashboard still uses the technical name in a few of its own labels; read them as Manifold Fedimint Guardian.

  1. SCREEN 1

    Choose: a new fleet, or recover one

    Two doors. Start a new fleet generates a fresh recovery phrase and starts with no seats. This is the usual choice. Recover from your phrase rebuilds a fleet whose original host is gone, from its 12 words, and brings its seats back with it.

    Recovery is only offered here. Once a host is set up, the choice is made and cannot be revisited on that host.

    Setup screen 1: Start a new fleet, or Recover from your phrase
  2. SCREEN 2

    "Record your recovery phrase"

    Click Reveal phrase and write the 12 words down on paper, in order. They are never stored in the browser, and there is no other backup: losing them loses every seat's guardian identity. Then click I've written it down, continue.

    Do not photograph or type the phrase anywhere. Anyone holding these words owns your fleet and everything it earns. You can reveal them again later from the Backup page if you need to check your copy.
    Setup screen 2: the twelve word recovery phrase
  3. SCREEN 3

    "Get this fleet authorized"

    The screen shows a QR code and your fleet's service Nostr public key (a 64 character string). Ambassadors only see fleets whose key carries a PeerBadge authorization, so this step cannot be skipped.

    Authorize it with your own PeerBadge: open the credential app that holds your badge, scan the QR code (or click Copy the authorization request and paste it into the app) and sign. Back in the wizard, click Check now. It does not poll in the background, so nothing happens until you click.

    When the relay carries your authorization the status changes to "Authorization observed" and the wizard moves on to the terms by itself after two seconds.

    Setup screen 3: QR code and service Nostr public key, waiting for a holder authorization
  4. SCREEN 4

    The terms

    The wizard shows the terms for running a Manifold guardian. Read them and accept to continue; the price step does not open until you have.

  5. SCREEN 5

    "Set your price"

    Maximum active seats is prefilled with the RAM based recommendation; lower it if the box does other work. Price per seat (sats) is the whole offer: the gross amount an Ambassador pays for one seat, before mint and Lightning fees. The dashboard suggests the equivalent of $2 to $3; a lower price fills seats sooner.

    Click Finish setup. Leaving the price blank finishes setup without selling anything; you can set a price any time from the Overview.

    Expect "Loading…" for about two minutes after this step. The fleet joins the network's shared setup payment federation, the one Ambassadors pay you through, and scans its history once. It only happens the first time.
    Setup screen 4: maximum active seats and price per seat
You are set up. The dashboard now opens on the Overview with six pages in the left menu: Overview, Authorization, Seats, Wallet, Payouts and Backup. Your fleet has a two word name (for example cranked-bonobo) that Ambassadors and support can recognise it by; it is shown top left and on the Backup page.
Overview right after setup: nothing sold yet

Overview right after setup. Zero everywhere is normal. The next section is about getting from here to the first sale.

06 · Get discovered

Three conditions

A fleet is invisible to Ambassadors until it has an authorization, a price, and a wallet that can receive payment. The dashboard shows all three. Then the software publishes your advertisement and keeps it fresh on its own.

  • Authorization observed. Open Authorization in the left menu. It should list at least one holder under "Observed holders". This is the badge from screen 3.
  • A price is set. The Overview's "Your offer" card shows a price per seat rather than "Not selling seats". Change it any time with Change price.
  • The wallet can receive. Open Wallet. At least one payment federation should be listed. You did not add it and cannot remove it: membership follows the network's published setup payment policy, and the fleet joins automatically.
  • Confirm. The Overview banner reads Advertised and healthy. That is the whole check. Anyone can additionally see your advertisement (a kind 37701 Nostr event) published from your service Nostr key on the Manifold relay.
Still not advertised after a few minutes? The loop runs every 30 minutes, and a cycle that fires while the wallet is still opening (about three minutes after a start) is skipped silently. Wait until the Wallet page shows the federation, then restart the app once (Umbrel: the app tile's menu › RestartStartOS: Stop the service, then Start it again); a restart publishes immediately.
07 · Earn

What happens when someone buys your seat

You do nothing. Ambassadors pick, pay and form the federation from the Fedi app; the fleet accepts, starts a guardian and reports. Here is what you will see, and where the money comes from.

  1. An Ambassador assembles a guardian set

    In the Fedi app the Ambassador opens Wallets, taps Create, and the app assembles a set of guardians from advertised fleets: cheapest first, then most free slots. One Ambassador buys at most one seat from your fleet per federation.

  2. They pay once, for the whole set

    The Ambassador pays the total in ecash through the shared setup payment federation. Your fleet receives your seat price, gross, before mint and Lightning fees. Every offered seat accepts automatically once a valid payment lands; there is no approval step and no "create seat" button on your side.

    The Overview counts this as an accepted payment claim, which is not yet the same as a settled payment. The fleet reconciles the claim in the background and the Wallet balance follows.

  3. A seat appears and forms the federation

    Open Seats. The new seat moves from Created to DKG (the guardians generating their shared keys) to Running. From then on your box is one of that federation's guardians. Click a seat for its detail page: federation, health, fee policy and payment evidence.

    Seats page with seats in different states
  4. Fees accrue for as long as the federation runs

    Every transaction members make inside the federation pays a small fee, split by a fixed rule: the Ambassador holds 4 shares, each guardian 1 share, and 1 share is the guardian verification fee, so a federation with 10 guardians has 15 shares and you hold one of them. The rate starts at 0.5% (5,000 ppm) and the Ambassador can change it within the network's bounds. Your share is remitted into a per seat fee account that you collect from Payouts.

Overview with seat sales and guardian fees over several days

Overview with revenue. The four tiles are Wallet balance, Earned all time, Seat sales and Guardian fees. Everything is gross. The Earnings list groups seat sales and fee remittances by day. A dash means the fleet could not read that figure yet, not that it is zero.

08 · Withdraw

Payouts: one destination, two kinds of revenue

Payouts is the only page where money leaves the fleet. It is ordered the way the software is: destination first, then seat sales, then guardian fees. A sweep always sends the largest amount the wallet can economically fund, through a gateway the software selects. There is no amount to type and no gateway to pick.

  1. Save a payout destination

    In the Payout destination card, paste a Lightning address or LNURL-pay link (for example you@wallet.example) and click Save destination. Every sweep reuses it. A bolt11 invoice is refused because it can only be paid once.

  2. Sweep seat sales

    The Seat sales table lists each payment federation your fleet has been paid through, with its balance. Click Sweep on a row. A small residue can stay behind when notes cannot cover the fees; that is expected and it is swept with the next sale.

  3. Collect, then send guardian fees

    Guardian fees take two clicks per seat, because the money first has to be released from the federation's fee pool into ordinary ecash: 1. Collect out of the pool, then 2. Send to destination. Part of a collection can stay locked until the federation's next cycle; the dashboard shows it as awaiting the cycle and you collect it next time.

    Collecting works without a destination, since it moves money inside the fleet. Sending does not.

  4. Keep the operation id

    Each sweep shows an operation id with a copy button. It is the reference support will ask for if a payment needs tracing. The Wallet page stays read only: balances per payment federation, nothing to configure.

Payouts page: payout destination, seat sales sweep, guardian fee collect and send

Payouts with revenue on both sides. Destination at the top, then per federation seat sales, then per seat guardian fees with their two step buttons.

09 · Keep it running

A guardian's only job is to stay up

Every running seat is one of the guardians a real federation depends on. Nothing needs daily attention, but these five things are yours to own.

01

Updates are manual, and due the day the network asks

Umbrel shows an Update button on the app once the store has a new version.Download the new .s9pk from the releases page and sideload it again. When the network names a newer release than yours, the dashboard takes the screen over with a notice; out of date fleets show up in the app as "not enough guardians" or "unauthorized request". Data survives updates, not uninstall.

02

Keep the node synced

The guardian is only as current as its Bitcoin node. The Bitcoin Node app updates like any other app, and after an outage it catches up by itself. If a federation reports trouble, check the block height against mempool.space before anything else.

03

The 12 words are the whole backup

Every key is derived from them and your seat records are published, encrypted, to the relay. The Backup page shows your fleet name, keys, and a Reveal recovery phrase link. Nothing else to export.

04

One phrase, one host

Recovery is only possible while setting up a fresh host ("Recover from your phrase"). Never run two boxes from the same words: two guardians with one identity would contradict each other and break the federation.

05

Change price and capacity any time

Overview › Change price. A blank price stops selling; 0 gives seats away and keeps you advertised. Seat capacity is on the same page and can never go below the seats already active.

Backup page: fleet name, keys, reveal recovery phrase

Backup. Name, service key, service Nostr key, and the phrase behind a deliberate extra click.

Your offer page: seat capacity and price per seat

Your offer. Seat capacity and price are saved separately; each change re-issues the offer to Ambassadors.

10 · Troubleshooting

When something looks wrong

Most of these are waits, not failures.

What you seeWhyWhat to do
"Loading…" for minutes right after setupFirst join of the setup payment federation scans its whole history.Wait. About two minutes, once only.
Price set, but no "Advertised and healthy"The advertisement loop skipped a cycle while the wallet was still opening, and nothing wakes it.Check Wallet lists a federation, then restart the app once. Umbrel: app ⋯ › Restart.StartOS: Stop, then Start.
Authorization never observedThe authorization was signed over a different key, or the relay read has not been repeated.Compare the full key on the Authorization page with the one your credential app scanned. Click Check now; setup never polls by itself.
A dash instead of a number on the OverviewThe fleet could not read that account yet (a seat still forming has no fee account).Nothing. A dash is "unknown", not zero. It fills in once the seat is running.
Sweep button greyed outNo payout destination saved, or that wallet holds nothing.Save a Lightning address in the card at the top of Payouts, then retry.
"Send to destination" greyed out on a seatFees are still in the pool; only collected ecash can be sent.Click 1. Collect out of the pool first. Locked deposits release at the next cycle.
App crash loops after an update with a migration errorThe new build's database schema is incompatible with the data on disk (release notes flag these).Uninstall, reinstall, and choose Recover from your phrase on the first setup screen; the fleet and its seats come back from the 12 words.
Ambassadors see "not enough guardians" or "unauthorized request"Version skew between fleets, the app and the network.Update the fleet to the current release (see Keep it running).
[object Object] error before the wizardFrontend rendering bug on the pre setup screen.Ignore or reload. The wizard still works.
Sideload page: "alerts is undefined"StartOS 0.4.0 beta.System › Software Update to 0.4.0 stable or later.
Open button leads to a dead 127.0.0.1 linkYou are browsing StartOS from the server itself.Use the interface's Local address entry instead.
"Secure Boot Violation", or the stick will not bootSecure Boot is still on.Back into the BIOS: Security › Secure Boot › Disabled. Keep UEFI mode.
The installer lists the wrong disk, or noneAn external drive is plugged in, or the internal disk is in a RAID/Optane mode.Unplug external drives and pick the internal SSD by size. If it is missing, set the SATA mode to AHCI in the BIOS.
umbrel.local does not openFirst boot takes a few minutes, Windows does not always resolve .local names, or the ethernet is not plugged in.Wait five minutes. Try http://umbrel, or the box's IP from your router's device list. Check the cable.
The box stayed off after a power cutThe BIOS default is to stay off when power returns.BIOS › Power › After Power Loss › Power on. Then it comes back on its own.
Bitcoin node at under 1 percent for a dayThe percentage is weighted by transactions; early blocks have almost none.Normal. Watch the block height climb instead, and compare it with mempool.space.
Bitcoin node stopped, disk fullA full node on a disk too small to hold the chain.Turn pruning on with a 10 GB target: both platforms reclaim the blocks themselves once the node catches up. If the disk is already full and the node will not start, fit a larger SSD as the system disk and reinstall; a guardian comes back from its 12 words.
Bitcoin sync still running after two weeksA spinning USB disk, Wi‑Fi, or a box that was powered off overnight.Move the chain to an internal SSD, use ethernet, and set After Power Loss to Power on in the BIOS.
RPC password lostUmbrel's Bitcoin Node app always shows it under Connect; only a reinstall changes it.StartOS shows it under Properties; a lost user can be removed with Delete RPC Users and recreated.Copy it again from the app and update your password manager.
Seats beyond the eighth connect slowlyOnly UDP 31000 to 31031 are published; later seats fall back to relays.Still works. A later package update extends the range.
11 · FAQ

Questions people ask before they start

Do I need a public IP address, a domain, or a certificate?
No, and by design you never will. Ambassadors reach your fleet over hole punched connections with public relays as fallback, your advertisement goes out over Nostr, and the dashboard is either behind Umbrel's login or protected by StartOS's generated password. Forwarding UDP 31000 to 31031 is optional and only improves direct connections.
Do I need to run Bitcoin Core or Lightning?
Bitcoin Core yes (Bitcoin Knots works as well), Lightning no. A mainnet guardian validates against your own Bitcoin node on the same box, pruned or full; Bitcoin node covers it, and its sync is the longest step of the setup. A Lightning node is never required; payouts go to any Lightning address you already have.
Can I choose which federations I host?
No. You set a price and a seat count; Ambassadors choose you. Every offered seat accepts automatically once a valid payment lands. If you want to stop being chosen, clear the price on the Overview.
How much will I earn?
Two things: the seat price you set, paid once per seat sold, and one share of the federation's transaction fees for as long as it runs. The dashboard suggests a seat price around the equivalent of $2 to $3. Fee income depends entirely on how much the federation's members transact, so no number is promised here.
What if I lose the 12 words?
While the box runs, nothing changes and you can reveal the phrase again from Backup. If the box dies and you do not have the words, the fleet and its seats cannot be recovered. Write them down before continuing past screen 2.
Can I move my fleet to a new box?
Yes: set the new box up, choose "Recover from your phrase" on screen 1, and the seats rebuild from the encrypted records the fleet published to the relay. Turn the old box off first. Two hosts with one identity would contradict each other.
Can I run more than one fleet, or raise the seat count later?
One fleet per box and per phrase. The seat limit is adjustable at any time on the Your offer page (or with fman-cli capacity set N); it just cannot drop below the seats already active.
Where do I get help?
For the Umbrel app, the package's issue tracker at github.com/fedibtc/manifold-umbrel-store/issues. For the StartOS package, github.com/fedibtc/manifold-fman-startos/issues. For everything else, including getting a PeerBadge, fedi.xyz.
12 · Sources

Where every statement on this page comes from

Checked against these on Sep 11, 2026; the StartOS release, the Umbrel manifests and Umbrel Home on Sep 18.

Umbrel app manifests: mainnet vs staging tile, Bitcoin dependency, Knotsfedi-dev-fleet-manager-production/umbrel-app.yml (v0.1.1, dependencies: bitcoin), umbrel-apps › bitcoin-knots (implements: bitcoin), umbrel.com/umbrel-home (16 GB RAM, 1, 2 or 4 TB SSD)
The guardian software architecturecrates/fman/specs/ARCH-fleet-manager.md
Fee split and guardian feesSPEC-guardian-fee-policy.md
Backup and recoverySPEC-nostr-backup-restore.md
Umbrel Bitcoin Node appapps.umbrel.com/app/bitcoin (v1.4.0-patch.1, Bitcoin Core v31.1), github.com/getumbrel/umbrel-bitcoin (setting names read from the source)
Start9 Bitcoin Coregithub.com/Start9Labs/bitcoin-core-startos (v31.1_16, Sep 6, 2026; in-app instructions on pruning, Properties and sync time), docs.start9.com › service guides › Bitcoin
Fedimint reference bitcoind configfedimint/devimint/src/cfg/bitcoin.conf