# Get the one-line command that installs Tarsana on a server you have {#top}

**Change** · `POST /v1/tenants/{tenant}/servers/{server_name}/install-command` · MCP tool `install-command`

Returns a one-line command for the server you name. Run it once as root in the shell your provider gives you on that machine, such as its rescue system: it checks that what it downloads is signed by Tarsana, installs Tarsana's boot chain and connects the machine to your account as that server. The command holds a token that works once and expires at `expires_at`, and it is shown only once. Asking again for the same `server_name` replaces a command that has not been used yet. A server you create with `create-server` gets its command automatically

Roles that can call it: `deployer`.

## Parameters

| Name | In | Required | Description |
|---|---|---|---|
| `tenant` | path | yes | Your tenant ID |
| `server_name` | path | yes | your name for the server, such as web-1: a letter or digit, then up to 62 letters, digits, dots, dashes or underscores. It is the server's name in your account |

## Returns

A JSON object with these keys: `tenant`, `server_name`, `install_command`, `carrier`, `expires_at`, `superseded`, `guarantee`, `caller_authenticated`.

## Example request

```sh
curl -X POST https://api.tarsana.io/v1/tenants/acme/servers/web-1/install-command \
  -H "X-Tarsana-Access-Token: $ACCESS_TOKEN" \
  -H 'X-Tarsana-Tenant: acme'
```

## Example response

```json
{
  "tenant": "acme",
  "server_name": "web-1",
  "install_command": "A one-line shell command. Run it once, as root, on the server.",
  "carrier": "a root shell on the server -- your provider's rescue system or its stock OS -- once",
  "expires_at": "2026-10-05T03:15:39Z",
  "superseded": false,
  "guarantee": "namespaces are separated, callers are not authenticated",
  "caller_authenticated": false
}
```

## Errors

| Code | HTTP | What it means |
|---|---|---|
| [`invalid_parameter`](/api/errors#invalid_parameter) | 400 | A value in your request does not have the expected format, for example a submission ID that is not a spec hash. Check the value against the field's description and try again. |
| [`no_acting_tenant`](/api/errors#no_acting_tenant) | 400 | Your request does not say which tenant you are acting for. Send your tenant ID in the `X-Tarsana-Tenant` header, or with `--as` on the command line. |
| [`isolation_refused`](/api/errors#isolation_refused) | 403 | This address belongs to a tenant ID you do not have access to. Check the tenant ID in the address and in your request header. |
| [`tenant_refused`](/api/errors#tenant_refused) | 400 | This tenant ID is not allowed, or is not in the expected format. Use a different ID made of lower-case letters, digits, dots, dashes and underscores. |
| [`install_not_configured`](/api/errors#install_not_configured) | 503 | Install commands are not available on this Tarsana deployment yet. Try again later, or contact Tarsana support. |
| [`install_unavailable`](/api/errors#install_unavailable) | 503 | Tarsana could not save the token for this command, so no command was issued. Try again. |
| [`unauthenticated`](/api/errors#unauthenticated) | 401 | Your request has no credential, or one that Tarsana does not recognise. Sign in with `login`, or send a valid access token. |
| [`forbidden`](/api/errors#forbidden) | 403 | Your role does not allow this operation. The response names the roles that do; ask for a credential with one of them. |
| [`rate_limited`](/api/errors#rate_limited) | 429 | You sent too many requests in a short time. Wait for the number of seconds in `retry_after_seconds`, then try again. |
| [`surface_fault`](/api/errors#surface_fault) | 500 | Something went wrong on our side. Try again later, and contact Tarsana support if it keeps happening. |
