# Installing the Jaws Deploy Agent

Source: https://www.jawsdeploy.net/guides/installing-jaws-deploy-agent

One agent per machine. Outbound-only connection to the control plane. Works in air-gapped environments with bundled modules.

The Jaws Deploy Agent is the small background service that runs on every machine target. It connects outbound to the control plane (Cloud or Stack), receives deployment work, runs it locally, and streams logs back.

**MSI installer**

Download the MSI from the workspace's **Add target** flow. Run it. The installer prompts for the registration token and the control plane URL.

**deb/rpm or shell installer**

Same flow, different packaging. `dpkg -i jaws-agent_*.deb` (or `rpm -i`), then run `jaws-agent register` with the token.

## Air-gapped environments

For environments without internet access during installation, the agent supports an offline install path. The control plane provides a bundle of the PowerShell modules the agent needs; you pre-fetch them, copy them to the machine, and pass `--modules-path` to the installer.

This was a frequent pain point in earlier versions and is now a first-class path.

> **// Outbound only - The agent never accepts inbound connections.**
> 
> It opens an outbound HTTPS connection to the control plane and waits for work. That makes the firewall story simple: allow outbound HTTPS to `app.jawsdeploy.net` (or your Stack URL). No inbound ports on the target.

