Installation

Every way to install the kya-os CLI, plus each Checkpoint SDK by hand if you'd rather not use it.

This page has the full detail behind the install step in the Quickstart, the less common paths, and every SDK installed by hand.

PlatformInstallNotes
macOScurl, npmApple silicon and Intel
Linuxcurl, npmx86_64 and aarch64, glibc 2.28 or newer
WindowsWSLNative builds aren't published yet

Alpine and other musl distributions need a glibc image, or npm with a glibc Node.

Prerequisites

  • A Checkpoint account. Sign up if you don't have one; kya-os setup signs you in.
  • Node.js only for kya-os mcp create (22.12+) and the agent identity and signing commands (register, dco, agent run, 20+), which also need the npm install: see Which install. Sign-in, project setup, Detect, and Govern don't need it.

Which install

Both install the same kya-os binary. They differ in what comes with it:

  • curl: the binary alone, checked against the registry's hash. No Node.js, and no npm packages. That covers sign-in, setup, detect install, and govern, so it's the install to standardize on for machines that only set Checkpoint up, and for CI.
  • npm: the binary plus the Node.js sidecar that the agent identity and signing commands run in. Use it on machines that run register, dco, or agent run.

Curl

curl -fsSL https://kya.vouched.id/install | sh

The installer:

  1. Detects your OS and CPU.
  2. Downloads the matching kya-os binary from the npm registry.
  3. Checks it against the registry's sha512 integrity hash, and refuses to install anything that doesn't match.
  4. Runs it once (kya-os --version) before it replaces anything. A binary this machine can't run, for example on a Linux older than glibc 2.28, stops the installer with the loader's error, and nothing is installed.
  5. Puts it in ~/.kya-os/bin.
  6. Puts it on your PATH. When a directory you own is already on it ($XDG_BIN_HOME, ~/.local/bin or ~/bin), it links kya-os there, and the terminal you ran it from can use it straight away. Otherwise, or when another kya-os comes first on your PATH (it names that one), it adds ~/.kya-os/bin with one line in your shell's profile (~/.zshrc; ~/.bash_profile on macOS or ~/.bashrc on Linux; ~/.config/fish/conf.d/kya-os.fish; otherwise ~/.profile), and ends by printing one command that puts it on this terminal's PATH and runs kya-os setup.

Nothing else on the machine changes.

Options go after sh -s --, or in the environment:

FlagEnvironment variableDefaultEffect
--version <v>KYA_OS_VERSIONlatestAn exact version, or an npm dist-tag
--dir <path>KYA_OS_INSTALL_DIR~/.kya-os/binWhere the binary goes
--no-modify-pathKYA_OS_NO_MODIFY_PATH=1offNo link, no profile line
--registry <url>KYA_OS_NPM_REGISTRYhttps://registry.npmjs.orgAn npm mirror or proxy (HTTPS required)
curl -fsSL https://kya.vouched.id/install | sh -s -- --dir /usr/local/bin --no-modify-path

npm

npm install -g @kya-os/cli

Or run it once without installing:

npx @kya-os/cli@latest setup

pnpm add -g, yarn global add, bun add -g, pnpm dlx, and bunx work the same way. The package installs the same native binary as the curl installer, through a per-platform optional dependency, plus the Node.js sidecar for the identity commands.

Let your agent set it up

Point your coding agent at the Checkpoint skill. It checks what's already set up, installs the CLI, previews the changes, and hands you the steps only you can take: the sign-in, and approving the app's key for server-side detection.

For Claude Code, save it as a skill:

mkdir -p ~/.claude/skills/checkpoint
curl -fsSL https://kya.vouched.id/skills/checkpoint/SKILL.md -o ~/.claude/skills/checkpoint/SKILL.md

Or reference it from any agent's instructions file (CLAUDE.md, AGENTS.md, .cursorrules, .windsurfrules):

Read https://kya.vouched.id/skills/checkpoint/SKILL.md and follow it for Checkpoint setup.

See Let your agent set it up for the full skill.

Windows

Install WSL once from PowerShell, then run the curl installer inside it:

wsl --install

The curl installer stops with a pointer to WSL when it runs on Windows directly.

Update

Rerun the installer; it replaces the binary in place. With npm, run npm install -g @kya-os/cli@latest.

Uninstall

kya-os logout            # revoke this machine's sign-in on Checkpoint first
rm ~/.kya-os/bin/kya-os

Then undo what put it on your PATH: the kya-os link in ~/.local/bin (or ~/bin, or $XDG_BIN_HOME) if the installer made one, or the two lines it added to your shell profile, a # kya-os comment and the PATH line under it (for fish, the kya-os.fish file). The .kya-os/project.json files in your repositories hold no secret and can stay.

Without the CLI

Every SDK installs by hand too. You need a Project ID, plus an API key for the server SDKs; see Credentials for where to find both.

Install the package

npm install @kya-os/checkpoint-nextjs

Create middleware

Create proxy.ts (Next.js 16+) or middleware.ts at your project root, or in src/ if your app uses a src/ directory:

Next.js 16: middleware.ts → proxy.ts

In Next.js 16 this file convention was renamed. Name the file proxy.ts and export a proxy function (a default export also works); middleware.ts exporting middleware still works but is deprecated. The Checkpoint setup below is identical either way — only the file name and export name change. One caveat: proxy.ts runs on the Node.js runtime only, so if you want Checkpoint on the Edge runtime (lowest latency), keep the file as middleware.ts. On Next.js 15 and earlier, use middleware.ts.
import { withCheckpointApi } from '@kya-os/checkpoint-nextjs/api-middleware';

export default withCheckpointApi({
  apiKey: process.env.CHECKPOINT_API_KEY,
});

export const config = {
  matcher: ['/((?!_next/static|_next/image|favicon.ico|.*\\.(?:svg|png|jpg|jpeg|gif|webp)$).*)'],
};

Add environment variables

# .env.local
CHECKPOINT_API_KEY=your_api_key_here

Deploy

npm run build && npm run start

Checkpoint is now detecting AI agents on your Next.js application. View results in the dashboard.

Keep your API key secret: server-side environment only, never in client-side code or in a repository. The Project ID is not a secret; the Pixel and Beacon put it in every page. Credentials lists every environment variable the SDKs read.