Skip to main content

Let your AI agent install and set up SigmaShake

By the end of this tutorial, ssg is installed and authenticated on your machine, wired into your AI coding agent's host, and ssg probe onboard reports "ok": true.

This page hands the work to your agent as one prompt. Humans reading over the agent's shoulder: use the Agent Install Guide (same sequence) or Getting Started.

SigmaShake is free to download and install. A $5/month subscription unlocks the governed value surfaces — there is no free tier or trial of that value. SigmaShake is a sole-operator individual entity (USA). See Plans & Limits.

Hand this to your AI agent​

Set up SigmaShake governance for my project.

You are the agent executing this. Do not invent extra steps.

1. If `ssg` is missing, install it with non-interactive ToS consent (`-y` / `-Yes`).
Without that flag a non-TTY install fails closed.
- Linux/macOS:
curl -fsSL https://install.sigmashake.com | sh -s -- -y
# alias (same script):
curl -fsSL https://install.sigmashake.com/install.sh | sh -s -- -y
- Windows (PowerShell pipe form — prefer this):
iwr -useb https://install.sigmashake.com/install.ps1 | iex
# pass -Yes / -y for non-interactive ToS consent

2. Onboard this project:
- Prefer the MCP tool `ssg_onboard` when available (headline path).
- Otherwise run: `ssg init --smart --client=<your-host>`
Host names: claude-code | cursor | codex | antigravity | gemini | copilot | pi | opencode
(`ssg init --list` if unsure). Preview with `--dry-run` if needed.
- Headless auth: `ssg auth login --no-browser` (or `--device` / `--token <api-key>`).
Show the human any URL they must open; $5/mo subscribe/activate is on them.

3. SigmaShake Desktop — install OR print the live download URL (OS-correct):
- Linux: curl -fsSL https://sigmashake.com/desktop/install.sh | sh
(CDN desktop/wails/latest.json — currently 1.0.12)
- macOS: print/open https://download.sigmashake.com/desktop/swift/latest.json
(currently 1.0.13 .dmg). desktop/macos/latest.json is a legacy alias of desktop/swift/latest.json.
- Windows: print/open https://download.sigmashake.com/desktop/windows/latest.json
(currently 1.0.20 Setup.exe).
Desktop first-run license/ToS is fail-closed. On macOS/Windows it is a GUI
gate — never tell the user to skip it.

4. Restart this AI client so MCP / hooks load.

5. On any failure: run `ssg probe onboard`, execute the returned `nextStep`
verbatim, re-probe until `"ok": true`. Do not scrape `findings` as a key set.

What your agent will do​

  • Install the CLI with non-interactive ToS consent (-y / -Yes) when ssg is missing — fail-closed without that flag on a non-TTY shell.
  • Prefer MCP ssg_onboard, otherwise run ssg init --smart --client=<host> and headless auth (ssg auth login --no-browser).
  • Install or surface the OS-correct SigmaShake Desktop download URL (Linux install script; macOS/Windows live latest.json URLs — or the legacy desktop/macos/ alias of the swift channel).
  • Ask you to restart the AI client so MCP / hooks load.
  • Loop ssg probe onboard → execute nextStep → re-probe until "ok": true.

What only you can do:

  • Open the URL and sign in — the agent has no browser session of its own.
  • Pay — SigmaShake is free to download and install; the $5/month subscription is a human decision. See Subscribe and activate.
  • Click through OS install / Desktop first-run ToS dialogs — Gatekeeper, SmartScreen, Mac App Store, and the Desktop license gate need a human GUI click; nothing scriptable skips those fail-closed gates.

Step by step​

There is no second install sequence on this page. The numbered items inside the prompt above are the whole path — CLI install with ToS consent, ssg_onboard / ssg init --smart, OS-correct Desktop, client restart, and ssg probe onboard self-heal. Paste that block into your agent and follow only the human gates it hands back (sign-in URL, subscribe/activate at $5/month, Desktop first-run ToS).

For the same sequence written for a human reading over the agent's shoulder — Windows pipe-form notes, probe JSON schema, and failure playbook — see the Agent Install Guide. Full file-by-file write list: What SSG Changes on Your Machine.

Verify​

ssg probe onboard

Emits exactly one JSON object on stdout. The schema is stable — every key is always present, findings/hints are arrays (never null), and nextStep is a copy-pasteable command set iff ok is false.

{"probe":"onboard","ok":false,"findings":["no verified Pro/Enterprise license — governance value surfaces are gated (free download/install, $5/month unlocks evaluation)","eval daemon not running","dashboard not reachable on ports 5599-5603"],"hints":[],"ms":3,"version":"0.0.0-dev","auth":{"licensed":false,"tier":null,"expiresMs":null},"daemon":{"pid":null,"alive":false,"socketExists":false},"dashboard":{"port":5599,"reachable":false},"hostArtifacts":{"cwd":"/home/user/project","detected":[]},"nextStep":"ssg auth activate --license <your-license-key> # https://sigmashake.com/pricing"}

The contract: parse ok. If false, execute nextStep verbatim, then re-run the probe. Repeat until ok is true. Don't pattern-match on findings wording — it's prose for a human.

You can also check ssg status, which prints a human-readable posture card (binary path, hook status, rule count, daemon/dashboard state, linked account).

If something goes wrong​

SymptomCauseNext command
ssg auth login fails non-interactively with a Terms-of-Service promptNo tty attached and -y/-Yes wasn't passed to the installer, or auth login needs a browser it can't openRe-run the installer with -y (sh -s -- -y / -Yes on Windows); for auth login add --no-browser and follow the printed URL
ssg probe onboard finds a stale daemon socket / ownership recordA prior daemon exited without releasing its socketssg daemon --stop && ssg daemon
ssg probe onboard or ssg probe desktop reports the daemon as crashed, but SigmaShake Desktop shows it runningNamespace split-brain — a project-relative probe resolves a different daemon namespace than the desktop app's $HOME-derived oneRun ssg probe desktop instead when checking the desktop app's own daemon
Windows: saved install.ps1 throws an execution-policy errorPowerShell blocks script files downloaded from the internet — not a permissions problemUse the pipe form (iwr … | iex), or Unblock-File .\install.ps1
A hook call fails closed: governance daemon is DEGRADED (rules not fully loaded); blockingThe daemon's loaded rules are stale relative to .sigmashake/rules/ on diskssg lint && ssg rule sync
ssg probe onboard returns "eval daemon not running"No daemon started for this project yetssg daemon (or ssg serve, which also starts it)
ssg probe onboard returns "dashboard not reachable on ports 5599-5603"Dashboard server isn't runningssg serve
ssg probe onboard returns "no verified Pro/Enterprise license"No license activated on this machine — the fail-closed default, not a bugSubscribe at sigmashake.com/pricing, then run the nextStep command it printed

Next​