Let your AI agent install and set up SigmaShake
By the end of this tutorial, ssg is installed and authenticated on your machine, wired into your AI coding agent's host, and ssg probe onboard reports "ok": true.
This page hands the work to your agent as one prompt. Humans reading over the agent's shoulder: use the Agent Install Guide (same sequence) or Getting Started.
SigmaShake is free to download and install. A $5/month subscription unlocks the governed value surfaces — there is no free tier or trial of that value. SigmaShake is a sole-operator individual entity (USA). See Plans & Limits.
Hand this to your AI agent
Set up SigmaShake governance for my project.
You are the agent executing this. Do not invent extra steps.
1. If `ssg` is missing, install it with non-interactive ToS consent (`-y` / `-Yes`).
Without that flag a non-TTY install fails closed.
- Linux/macOS:
curl -fsSL https://install.sigmashake.com | sh -s -- -y
# alias (same script):
curl -fsSL https://install.sigmashake.com/install.sh | sh -s -- -y
- Windows (PowerShell pipe form — prefer this):
iwr -useb https://install.sigmashake.com/install.ps1 | iex
# pass -Yes / -y for non-interactive ToS consent
2. Onboard this project:
- Prefer the MCP tool `ssg_onboard` when available (headline path).
- Otherwise run: `ssg init --smart --client=<your-host>`
Host names: claude-code | cursor | codex | antigravity | gemini | copilot | pi | opencode
(`ssg init --list` if unsure). Preview with `--dry-run` if needed.
- Headless auth: `ssg auth login --no-browser` (or `--device` / `--token <api-key>`).
Show the human any URL they must open; $5/mo subscribe/activate is on them.
3. SigmaShake Desktop — install OR print the live download URL (OS-correct):
- Linux: curl -fsSL https://sigmashake.com/desktop/install.sh | sh
(CDN desktop/wails/latest.json — currently 1.0.12)
- macOS: print/open https://download.sigmashake.com/desktop/swift/latest.json
(currently 1.0.13 .dmg). desktop/macos/latest.json is a legacy alias of desktop/swift/latest.json.
- Windows: print/open https://download.sigmashake.com/desktop/windows/latest.json
(currently 1.0.20 Setup.exe).
Desktop first-run license/ToS is fail-closed. On macOS/Windows it is a GUI
gate — never tell the user to skip it.
4. Restart this AI client so MCP / hooks load.
5. On any failure: run `ssg probe onboard`, execute the returned `nextStep`
verbatim, re-probe until `"ok": true`. Do not scrape `findings` as a key set.
What your agent will do
- Install the CLI with non-interactive ToS consent (
-y/-Yes) whenssgis missing — fail-closed without that flag on a non-TTY shell. - Prefer MCP
ssg_onboard, otherwise runssg init --smart --client=<host>and headless auth (ssg auth login --no-browser). - Install or surface the OS-correct SigmaShake Desktop download URL (Linux install script; macOS/Windows live
latest.jsonURLs — or the legacydesktop/macos/alias of the swift channel). - Ask you to restart the AI client so MCP / hooks load.
- Loop
ssg probe onboard→ executenextStep→ re-probe until"ok": true.
What only you can do:
- Open the URL and sign in — the agent has no browser session of its own.
- Pay — SigmaShake is free to download and install; the $5/month subscription is a human decision. See Subscribe and activate.
- Click through OS install / Desktop first-run ToS dialogs — Gatekeeper, SmartScreen, Mac App Store, and the Desktop license gate need a human GUI click; nothing scriptable skips those fail-closed gates.
Step by step
There is no second install sequence on this page. The numbered items inside the prompt above are the whole path — CLI install with ToS consent, ssg_onboard / ssg init --smart, OS-correct Desktop, client restart, and ssg probe onboard self-heal. Paste that block into your agent and follow only the human gates it hands back (sign-in URL, subscribe/activate at $5/month, Desktop first-run ToS).
For the same sequence written for a human reading over the agent's shoulder — Windows pipe-form notes, probe JSON schema, and failure playbook — see the Agent Install Guide. Full file-by-file write list: What SSG Changes on Your Machine.
Verify
ssg probe onboard
Emits exactly one JSON object on stdout. The schema is stable — every key is always present, findings/hints are arrays (never null), and nextStep is a copy-pasteable command set iff ok is false.
{"probe":"onboard","ok":false,"findings":["no verified Pro/Enterprise license — governance value surfaces are gated (free download/install, $5/month unlocks evaluation)","eval daemon not running","dashboard not reachable on ports 5599-5603"],"hints":[],"ms":3,"version":"0.0.0-dev","auth":{"licensed":false,"tier":null,"expiresMs":null},"daemon":{"pid":null,"alive":false,"socketExists":false},"dashboard":{"port":5599,"reachable":false},"hostArtifacts":{"cwd":"/home/user/project","detected":[]},"nextStep":"ssg auth activate --license <your-license-key> # https://sigmashake.com/pricing"}
The contract: parse ok. If false, execute nextStep verbatim, then re-run the probe. Repeat until ok is true. Don't pattern-match on findings wording — it's prose for a human.
You can also check ssg status, which prints a human-readable posture card (binary path, hook status, rule count, daemon/dashboard state, linked account).
If something goes wrong
| Symptom | Cause | Next command |
|---|---|---|
ssg auth login fails non-interactively with a Terms-of-Service prompt | No tty attached and -y/-Yes wasn't passed to the installer, or auth login needs a browser it can't open | Re-run the installer with -y (sh -s -- -y / -Yes on Windows); for auth login add --no-browser and follow the printed URL |
ssg probe onboard finds a stale daemon socket / ownership record | A prior daemon exited without releasing its socket | ssg daemon --stop && ssg daemon |
ssg probe onboard or ssg probe desktop reports the daemon as crashed, but SigmaShake Desktop shows it running | Namespace split-brain — a project-relative probe resolves a different daemon namespace than the desktop app's $HOME-derived one | Run ssg probe desktop instead when checking the desktop app's own daemon |
Windows: saved install.ps1 throws an execution-policy error | PowerShell blocks script files downloaded from the internet — not a permissions problem | Use the pipe form (iwr … | iex), or Unblock-File .\install.ps1 |
A hook call fails closed: governance daemon is DEGRADED (rules not fully loaded); blocking | The daemon's loaded rules are stale relative to .sigmashake/rules/ on disk | ssg lint && ssg rule sync |
ssg probe onboard returns "eval daemon not running" | No daemon started for this project yet | ssg daemon (or ssg serve, which also starts it) |
ssg probe onboard returns "dashboard not reachable on ports 5599-5603" | Dashboard server isn't running | ssg serve |
ssg probe onboard returns "no verified Pro/Enterprise license" | No license activated on this machine — the fail-closed default, not a bug | Subscribe at sigmashake.com/pricing, then run the nextStep command it printed |
Next
- Sign in — the full provider list and what each login shares with SigmaShake.
- Subscribe and activate — turn the license on once you've signed in.
- Let your agent write rules — the safe way to let an agent edit
.rulesfiles after setup.