Joining a CanMe network?
Paste the network address your admin sent you and we'll walk you through the rest.
Three steps
Get on the network.
Download the client
Pick your platform and download Cannector — the small, signed client that connects you to the network. Links come straight from our downloads server, so you always get the current release.
Install it
No installer — two commands in a terminal, from the directory you downloaded the binary into.
1. Make the binary executable
chmod +x cannector2. Install it — this needs root
sudo ./cannector --installSign in
On Linux the client is given a device identity instead of a user sign-in — no SSO and no local CanMe account yet. One command and the machine is on:
Give the device its identity
cannector --join -n your-network.canme.network -s YOUR_SECRETThe secret comes from Cansole → Configuration → Secret-Mgmt. Ask your admin if you don't have access.
What your computer needs
A few things have to be true on your machine. If any of these sound unfamiliar, don't worry — send the list to your IT admin and they'll confirm in a minute.
Local administrator rights
On Windows and Linux the client installs a small network service, so you need admin rights on the machine (root on Linux). On macOS and iOS you don't — you install from the App Store and approve a VPN extension the first time you open it.
Outbound port 443 open
The client only makes outgoing connections on port 443 — the same standard HTTPS port your browser uses. Nothing needs to be opened for incoming traffic.
No SSL/TLS inspection on this traffic
If your firewall inspects or decrypts HTTPS, it can break the connection. Either exempt the network address, or make sure the network's certificate is trusted on your machine.
No other VPN running
Cannector manages its own secure tunnel. Disconnect any other VPN (corporate VPN, WireGuard, OpenVPN, …) while you use it — you don't have to uninstall them.
Not sure? Forward this list to your admin.
While you're here
What CanMe is, in three lines.
Identity-first
Your access is your identity — not an IP, not a VPN tunnel.
Hosted at your side
Your customer's network is theirs alone. We don't see your traffic or your data.
Live in days
No firewall tickets, no MPLS, no waiting on a change window.
Quick questions
Is this safe?
Yes. The client is signed, the connection is end-to-end encrypted, and CanMe never sees your traffic. Your admin can revoke your access at any time.
What does the client actually do?
It opens an outbound connection to your network's Mesh — no inbound ports, no public IP. Once you sign in, the apps your admin allowed you to reach become available exactly as if you were on the LAN.
It installed but won't connect. What should I check?
Almost always one of three things: another VPN is still connected, outbound port 443 is blocked, or your company firewall is inspecting HTTPS traffic to the network. Share the requirements list above with your IT admin — they can confirm all three quickly.
I don't have a network address — what now?
Ask the person who invited you to resend the invite link, or paste the address they sent you into the field at the top of this page. The address looks like company.canme.network.