> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploy client endpoint

> Create a Linux OpenSSL 3 endpoint and download its CryptoHub Client Library credential bundle.

Once you deploy the Ansible service in CryptoHub, set up a client endpoint. An endpoint is a device authorized to access the service. Use the **Endpoints** menu to view and manage these devices. You can also add new endpoints by selecting **\[ Add New ]**.

Unlike the legacy Host-API libraries, the CryptoHub Client Library reaches CryptoHub over the **v2 REST API on port 443**. The CryptoHub Client Library ships inside the endpoint download: deploying an endpoint provisions the identity, connection details, and TLS material that the library uses to authenticate, along with the library module and its supporting tools.

<Steps>
  <Step>
    Go to the **Endpoints** menu for the service you deployed.
  </Step>

  <Step>
    In the **Manage Endpoints** menu, select **\[ Add New ]**.
  </Step>

  <Step>
    In the **Add Endpoint** dialog:

    * Enter a **Name** for the endpoint, or leave empty for auto-generation.
    * Leave the auto-populated CryptoHub **Hostname** as is.
    * Select **Linux OpenSSL 3** for **Platform**.
  </Step>

  <Step>
    Select **\[ Add Endpoint ]**. The browser downloads a ZIP containing
    `libcryptohub-pkcs11.so`, `pkcs11-manager`, a preconfigured
    `cryptohub.json`, and the referenced TLS files.

    Keep the download secure. It is a credential for the Ansible service.
  </Step>
</Steps>

<Note>
  To change the endpoint password, go to **Identity and Access** >
  **Applications & Partitions**. Find the deployed application and select
  **Authentication** under **Manage**.
</Note>
