Skip to content

Getting started with Nanome XR ​

7 steps from boxed headsets to a shared session: hardware, choosing an MDM, setting it up, Wi-Fi, installation, accounts, and sign-in.

Nanome is device-agnostic — best experienced in VR or MR, but no headset is required. Jump in from any browser at app.nanome.ai and start exploring molecules right away.

Hardware ​

Step 1 of 7 · Headsets, and where to buy them

Nanome runs on Meta Quest 3 and 3S, Samsung Galaxy XR, Apple Vision Pro, and Windows PCs over Meta Link.

Meta Quest 3 and 3S
Samsung Galaxy XR
Apple Vision Pro

Where to buy ​

Nanome hardware partner

Preconfigured through VR Expert

Offices in the US and Europe

VR Expert prepares each headset before it ships: enrolled in the organization's MDM, configured, and loaded with Nanome. The US order form lists ready-to-go Nanome kits for Quest 3 and Galaxy XR, and installation and a year of support can be added to every headset.

Order Nanome kits (US) · Europe and global

Buy direct

From a retailer

Meta Quest 3 and 3S are sold by Meta, Best Buy, and Amazon. Meta stopped selling business editions in February 2026, so organizations now buy the standard headsets and enroll them in Meta's free device management (Choose an MDM).

Meta · Best Buy · Amazon

Choose an MDM ​

Step 2 of 7 · Managing a fleet of headsets

A mobile device management (MDM) service enrolls headsets into an organization, pushes Wi-Fi and apps to them, and keeps every headset on the version IT has approved. Managed headsets can also run without personal store accounts.

Which service fits ​

Answer three questions

1 Which headset?

Compare all three side by side ​

Cost, supported headsets, and features

Meta Horizon managed services (HMS) FreeFree. Manages Meta Quest only.More detailLess detail

Free — Free since February 20, 2026. Works with Quest 2, 3, 3S, and Pro. Manages Meta Quest only.

  • Manages Meta Quest headsets only, on Quest 2, 3, 3S, and Pro
  • Quest headsets that are not already enrolled in an MDM enroll through HMS on Horizon OS v74 and later
  • Runs shared headsets without personal Meta accounts, with a fresh session for each user
  • Device presets, Wi-Fi profiles, app and file push, and remote wipe
  • Nanome is listed in the Managed App Store under Discover Apps
  • Meta supports the current version for Quest 3 and 3S through January 4, 2030, with no stated date for Quest 2 and Pro

Meta Horizon managed services · HMS sign-up

ArborXR PaidFrom $7 per headset per month. Multi-brand.More detailLess detail

From $7 — Per headset per month, billed annually. 30-day free trial. Manages Meta Quest, Galaxy XR, PICO, HTC VIVE, Magic Leap 2.

  • Adds a management layer on top of HMS for Quest headsets
  • Also manages PICO, HTC VIVE, Samsung Galaxy XR, and Magic Leap 2 headsets, with features that vary by model
  • ArborXR Home launcher or single-app kiosk, locked with an admin PIN
  • Secure Wi-Fi provisioning and app, video, and file push on every plan
  • Release channels hold each device group on the Nanome version IT has approved
  • Remote casting and usage analytics on the Essential plan

ArborXR · ArborXR pricing

ManageXR PaidFrom $7 per headset per month. Multi-brand.More detailLess detail

From $7 — Per headset per month, billed annually. 30-day free trial. Manages Meta Quest, Galaxy XR, PICO, HTC VIVE.

  • Enrolls Quest headsets through HMS with an organization enrollment token
  • Also manages Samsung Galaxy XR, PICO, and HTC VIVE headsets, with features that vary by model
  • Imports Nanome from the Meta managed store as a CSV, or deploys an uploaded APK
  • Single-app kiosk and Wi-Fi with certificates on the Essential plan, though Galaxy XR cannot be kiosk-locked yet
  • Multi-app home screen, release channels, remote screen streaming, and usage analytics on the Premium plan

ManageXR · ManageXR pricing

MDM setup guides ​

Step 3 of 7 · Setting up an MDM

Enrollment happens during a headset's first-time setup, so it comes before apps and accounts. Each guide covers signing up, enrolling headsets, and pushing Nanome.

Choose a service ​

Manages Meta Quest headsets only.

Official Meta Horizon managed services documentation — work.meta.com/help

  1. Sign up for a free HMS organization with Meta. Adding at least 2 System admins, on shared role-based email addresses, keeps access from depending on one admin.
  2. Factory reset any headset that has already been set up. Enrollment only happens during first-time setup.
  3. During setup, choose Connect to your organization and note the 8-digit code. Enter it at work.meta.com/device while signed in to a managed account. The Meta Horizon Device Setup app enrolls headsets over USB instead, straight into Shared Mode, with no account needed.
  4. In Device Manager, put shared headsets in a Shared Mode device preset and assign the Wi-Fi network to it.
  5. Add Nanome from Apps & Content > Discover Apps in Device Manager.

Meta's enrollment guide → · HMS sign-up walkthrough →

Manages Meta Quest, Samsung Galaxy XR, PICO, HTC VIVE, and Magic Leap 2, with features that vary by model.

Official ArborXR help center — help.arborxr.com

  1. Set up the free HMS organization first (steps 1 and 2 of the HMS guide). Quest headsets that are not already enrolled in an MDM enroll through HMS on Horizon OS v74 and later.
  2. Start an ArborXR free trial and create a device group.
  3. In the group's Enrollment tab, create a JSON enrollment file in the Horizon managed services format, then upload it in Meta's Device Manager under Third Party MDMs.
  4. Enroll each headset with its device code, then confirm it appears in ArborXR.
  5. Upload the Nanome APK to Content Library and add it to the group.
  6. Set the group's Kiosk Experience to ArborXR Home, ArborXR Kiosk Mode, or an in-house launcher, then check that Offline Mode is on in its Shared Mode settings.
  7. Wi-Fi comes from the network details in the enrollment file. Once headsets are enrolled in ArborXR, app and settings changes happen there.

Enroll through HMS → · Group devices → · Upload apps → · Share apps with an organization → · Kiosk mode → · Shared Mode settings →

Manages Meta Quest, Samsung Galaxy XR, PICO, and HTC VIVE, with features that vary by model.

Official ManageXR help center — help.managexr.com

  1. Set up the free HMS organization first (steps 1 and 2 of the HMS guide), then start a ManageXR free trial.
  2. In ManageXR, open Devices > Add Device, check that the default configuration uses the intended Meta device mode (Shared or Individual), and download the Organization Enrollment Token.
  3. In Meta Admin Center, open Devices > Third-party enrollments > Create third-party enrollment, choose ManageXR as the provider, and upload the token.
  4. During each headset's setup, choose Connect to your organization and enter the code at work.meta.com/device.
  5. Save Nanome in HMS Discover Apps, export the app list as a CSV, and import it in ManageXR under VR Content > Add Content > Meta Horizon Store Apps. Repeat that export when the app list changes. Organizations on a private Nanome server upload the matching APK instead.
  6. Deploy Nanome and the Wi-Fi network in the configuration, then save it.

Quest enrollment → · Galaxy XR enrollment → · Meta store apps → · Upload an APK → · Wi-Fi profiles →

Wi-Fi & network ​

Step 4 of 7 · A network Nanome can reach

Headsets need Wi-Fi with direct internet access and a short list of hostnames allowed through the firewall. The checklist below is written to hand straight to IT.

Six checks for IT ​

6 checks for IT

Direct internet, no sign-in page Guest networks with a browser sign-in block headset setup.More detailLess detail

Guest networks that ask for a browser sign-in (captive portals) block first-time headset setup. Quest also shows a no-internet message whenever it can't reach Meta, before Nanome ever opens.

Nanome allowed by hostname Outbound TCP 443 to *.nanome.ai and *.nanome.com.More detailLess detail

Allow outbound TCP 443 to *.nanome.ai and *.nanome.com. Nanome's servers run on Cloudflare and AWS, where IP addresses change, so IP-based rules eventually break.

  • app.nanome.aiWeb app and workspaces
  • home.nanome.aiAccounts, licenses, and organizations
  • api.nanome.comSign-in and licensing, Nanome 2.6 and later
  • api.nanome.aiSign-in for earlier releases and Nanome Classic
  • downloads.nanome.aiAPK and Windows downloads
Enterprise Wi-Fi from the MDM 802.1X networks and certificates pushed to every headset.More detailLess detail

HMS pushes WPA2 and WPA2-Enterprise networks (EAP-TLS and EAP-PEAP). ArborXR and ManageXR add WPA3, proxy settings, EAP-TTLS, and SCEP certificate enrollment, and ArborXR also supports EST. Headsets enrolled in ArborXR or ManageXR take their apps and settings, Wi-Fi included, from that MDM.

802.1X profiles need the RADIUS server's domain and a root certificate served with its full chain, intermediates included.

HMS Wi-Fi profiles → · ArborXR Wi-Fi options → · ManageXR Wi-Fi profiles →

Networks that register devices by MAC Headsets randomize their MAC address by default.More detailLess detail

Quest 3 uses a randomized MAC address for each network by default, and other Android-based headsets and Vision Pro do the same. For MAC registration, switch that saved network to the device MAC, or turn off randomization in the HMS, ArborXR, or ManageXR Wi-Fi profile.

Finding a Quest's MAC address →

Firewall allowlist Nanome, Meta, and MDM hosts and ports in one list to copy.More detailLess detail

Firewall allowlist

Nanome (headsets and web app)
  Outbound TCP 443 (HTTPS and secure WebSockets), allowed by hostname:
  *.nanome.ai, *.nanome.com
  Includes app.nanome.ai, home.nanome.ai, api.nanome.com, api.nanome.ai, downloads.nanome.ai
  Exempt these hosts from TLS/SSL inspection.

Meta Quest (Meta Horizon managed services requirements)
  TCP 80, 443, 3478, 3479, 8080
  UDP 40003, 40005, 40007, 40008, 50000-59999
  www.facebook.com, graph.facebook.com, graph.facebook-hardware.com, edge-mqtt.facebook.com, portal.fb.com
  static.xx.fbcdn.net, www.oculus.com, graph.oculus.com, scontent.oculuscdn.com, work.meta.com
  forwork.meta.com, www.google.com, devicemanager.meta.com
  Plus regional CDN hosts under xx.fbcdn.net, such as scontent-iad3-2.xx.fbcdn.net
  Full per-task list: https://work.meta.com/help/278069664862989

ArborXR (when used as the MDM)
  TCP 443:
  arborxr.com, *.arborxr.com, xrdm.app, *.xrdm.app, abxr.us, storage.googleapis.com
  arborxrstatic.com on ports 53, 80, and 443 (captive portal detection)
  Remote Assistance: stun.cloudflare.com (53, 1473, 3478), turn.cloudflare.com (53, 443, 3478, 5349)
  Full list: https://help.arborxr.com/en/articles/6399721-what-urls-and-ports-are-required-to-allow-whitelist-arborxr-traffic-in-my-local-network

ManageXR (when used as the MDM)
  TCP 443:
  *.managexr.com, managexrapi.com, managexrcdn.com
  mighty-platform-prod.appspot.com, mighty-platform-prod.firebaseio.com, us-central1-mighty-platform-prod.cloudfunctions.net
  *.googleapis.com
  *.crashlytics.com on ports 80 and 443 (error reporting)
  clients3.google.com and connectivitycheck.gstatic.com on port 80 (connectivity checks)
  Remote screen streaming: openrelay.metered.ca, stun.relay.metered.ca, and global.relay.metered.ca on ports 80 and 443 (TCP and UDP)
  Full list: https://help.managexr.com/en/articles/6994017-network-requirements
Testing the connection A curl check and a phone hotspot narrow down network problems.More detailLess detail

From the same network, curl -v https://api.nanome.com confirms port 443 is open (ping uses ICMP and doesn't test it). When a phone hotspot works and the office network doesn't, the network is blocking something. ArborXR and ManageXR both publish network tests that also run in the headset's browser.

ArborXR network test → · ManageXR network test →

Download & install ​

Step 5 of 7 · Downloading and installing Nanome

Nanome comes from a store, through an MDM, or as a manual download to sideload. Picking a method and a device shows the matching download and steps, always for the latest release.

Pick a method and a device ​

1 How will Nanome be installed?

Accounts & licenses ​

Step 6 of 7 · Accounts and licenses

Each user signs in with their own Nanome account, even on a shared headset. Users work in the web app at app.nanome.ai, and admins manage licenses and organization membership at home.nanome.ai.

Two sites, two jobs ​

app.nanome.ai

The Nanome web app

Where users create their Nanome account, with an email or a Google, Microsoft, Apple, or SSO sign-in. It's also where the work lives: projects and workspaces, structures loaded by PDB ID or dragged in from a computer, and sharing by link, 8-digit code, or email invite.

New accounts include a 14-day Full license trial.

Create an account

home.nanome.ai

License management

Where admins assign and reassign licenses, invite members to the organization, set up single sign-on, download invoices under Billing, and turn on two-factor authentication.

Open home.nanome.ai

Account Settings > Security. See Two Factor Auth.

Getting a team ready ​

4 steps

1. An account for each user Created at app.nanome.ai, with a 14-day Full trial.More detailLess detail

Each user creates a Nanome account at app.nanome.ai, including users who share a headset. Every new account starts with a 14-day Full license trial.

2. A seat that includes XR Headset use takes a Collab or Full seat.More detailLess detail

Working in a headset takes a Collab or Full seat. The Free Web Seat covers 3 workspaces in the browser and view-only collaboration.

3. Licenses once the trial ends Seats and pricing, or a quote from the Nanome team.More detailLess detail

After the trial, headset access continues on a paid seat. The pricing page lists what each seat includes, and the Nanome team quotes volume and academic pricing by email.

Plans and seats · Ask for a quote

4. Licenses assigned by an admin Assigned at home.nanome.ai by account email.More detailLess detail

An admin assigns licenses in home.nanome.ai under Licenses > Assign Users, using each user's account email. The license activates once that user confirms the email Nanome sends.

Licenses > Assign Users. See Licenses.

Related pages: Web App Basics · Licenses · home.nanome.ai overview · Plans and seats

Log in ​

Step 7 of 7 · Signing in on a headset

The headset login screen has 2 tabs: Code, for a short code confirmed from a phone or laptop, and Password, for a username and password typed in the headset.

Two ways in ​

2 ways to log in on a headset

Log in with a code Quickest in a headset, and the sign-in for SSO accounts.More detailLess detail
  1. On the headset's login screen, open the Code tab. Nanome shows a short code.
  2. On a phone or computer, sign in at app.nanome.ai and choose Login via Device Code.
  3. Enter the code. The headset signs in to that account.

Each code signs in one user's account. Accounts that use single sign-on (SSO) sign in to headsets this way.

Log in with username and password The Password tab on the headset's login screen.More detailLess detail
  1. On the Password tab, enter the Nanome username and password, then choose Log in.
  2. Create Account on the same screen starts a new account with a 14-day free trial.

Forgotten passwords are reset at home.nanome.ai.

Login screen guide →

Next ​

Headsets are set up and everyone can sign in. The Session Guide picks up from there: planning a session, building a workspace, and running it with a group.