Installation
Every way to install the kya-os CLI, plus each Checkpoint SDK by hand if you'd rather not use it.
This page has the full detail behind the install step in the Quickstart, the less common paths, and every SDK installed by hand.
Alpine and other musl distributions need a glibc image, or npm with a glibc Node.
Prerequisites
- A Checkpoint account. Sign up if you don't have one;
kya-os setupsigns you in. - Node.js only for
kya-os mcp create(22.12+) and the agent identity and signing commands (register,dco,agent run, 20+), which also need the npm install: see Which install. Sign-in, project setup, Detect, and Govern don't need it.
Which install
Both install the same kya-os binary. They differ in what comes with it:
- curl: the binary alone, checked against the registry's hash. No Node.js, and no npm packages. That covers sign-in,
setup,detect install, andgovern, so it's the install to standardize on for machines that only set Checkpoint up, and for CI. - npm: the binary plus the Node.js sidecar that the agent identity and signing commands run in. Use it on machines that run
register,dco, oragent run.
Curl
curl -fsSL https://kya.vouched.id/install | shThe installer:
- Detects your OS and CPU.
- Downloads the matching
kya-osbinary from the npm registry. - Checks it against the registry's sha512 integrity hash, and refuses to install anything that doesn't match.
- Runs it once (
kya-os --version) before it replaces anything. A binary this machine can't run, for example on a Linux older than glibc 2.28, stops the installer with the loader's error, and nothing is installed. - Puts it in
~/.kya-os/bin. - Puts it on your
PATH. When a directory you own is already on it ($XDG_BIN_HOME,~/.local/binor~/bin), it linkskya-osthere, and the terminal you ran it from can use it straight away. Otherwise, or when anotherkya-oscomes first on yourPATH(it names that one), it adds~/.kya-os/binwith one line in your shell's profile (~/.zshrc;~/.bash_profileon macOS or~/.bashrcon Linux;~/.config/fish/conf.d/kya-os.fish; otherwise~/.profile), and ends by printing one command that puts it on this terminal'sPATHand runskya-os setup.
Nothing else on the machine changes.
Options go after sh -s --, or in the environment:
curl -fsSL https://kya.vouched.id/install | sh -s -- --dir /usr/local/bin --no-modify-pathnpm
npm install -g @kya-os/cliOr run it once without installing:
npx @kya-os/cli@latest setuppnpm add -g, yarn global add, bun add -g, pnpm dlx, and bunx work the same way. The package installs the same native binary as the curl installer, through a per-platform optional dependency, plus the Node.js sidecar for the identity commands.
Let your agent set it up
Point your coding agent at the Checkpoint skill. It checks what's already set up, installs the CLI, previews the changes, and hands you the steps only you can take: the sign-in, and approving the app's key for server-side detection.
For Claude Code, save it as a skill:
mkdir -p ~/.claude/skills/checkpoint
curl -fsSL https://kya.vouched.id/skills/checkpoint/SKILL.md -o ~/.claude/skills/checkpoint/SKILL.mdOr reference it from any agent's instructions file (CLAUDE.md, AGENTS.md, .cursorrules, .windsurfrules):
Read https://kya.vouched.id/skills/checkpoint/SKILL.md and follow it for Checkpoint setup.See Let your agent set it up for the full skill.
Windows
Install WSL once from PowerShell, then run the curl installer inside it:
wsl --installThe curl installer stops with a pointer to WSL when it runs on Windows directly.
Update
Rerun the installer; it replaces the binary in place. With npm, run npm install -g @kya-os/cli@latest.
Uninstall
kya-os logout # revoke this machine's sign-in on Checkpoint first
rm ~/.kya-os/bin/kya-osThen undo what put it on your PATH: the kya-os link in ~/.local/bin (or ~/bin, or $XDG_BIN_HOME) if the installer made one, or the two lines it added to your shell profile, a # kya-os comment and the PATH line under it (for fish, the kya-os.fish file). The .kya-os/project.json files in your repositories hold no secret and can stay.
Without the CLI
Every SDK installs by hand too. You need a Project ID, plus an API key for the server SDKs; see Credentials for where to find both.
Install the package
npm install @kya-os/checkpoint-nextjsCreate middleware
Create proxy.ts (Next.js 16+) or middleware.ts at your project root, or in src/ if your app uses a src/ directory:
Next.js 16: middleware.ts → proxy.ts
proxy.ts and export a proxy function (a default export also works); middleware.ts exporting middleware still works but is deprecated. The Checkpoint setup below is identical either way — only the file name and export name change. One caveat: proxy.ts runs on the Node.js runtime only, so if you want Checkpoint on the Edge runtime (lowest latency), keep the file as middleware.ts. On Next.js 15 and earlier, use middleware.ts.import { withCheckpointApi } from '@kya-os/checkpoint-nextjs/api-middleware';
export default withCheckpointApi({
apiKey: process.env.CHECKPOINT_API_KEY,
});
export const config = {
matcher: ['/((?!_next/static|_next/image|favicon.ico|.*\\.(?:svg|png|jpg|jpeg|gif|webp)$).*)'],
};Add environment variables
# .env.local
CHECKPOINT_API_KEY=your_api_key_hereKeep your API key secret: server-side environment only, never in client-side code or in a repository. The Project ID is not a secret; the Pixel and Beacon put it in every page. Credentials lists every environment variable the SDKs read.
