Skip to main content

Subscribe and activate

By the end of this tutorial, you have an active $5/month subscription and ssg probe onboard reports auth.licensed: true on this machine.

You must already be signed in for this to work — if ssg auth status shows no linked account, do the Sign in tutorial first.

Hand this to your AI agent​

Help me subscribe to SigmaShake and confirm the license activated. You cannot
pay for me — that step needs my card in a browser — so hand me the link and
wait for me to confirm.

1. Check my current state:
ssg auth status
ssg probe onboard
If `auth.licensed` is already true in the probe output, tell me I'm
already subscribed and stop here.

2. If not, tell me to open https://sigmashake.com/pricing (or, if I already
have an account and just need to check out directly:
https://billing.sigmashake.com/start-checkout) and complete payment in my
browser. Wait for me to confirm I've finished.

3. Re-run:
ssg probe onboard
Confirm `auth.licensed` is now true. If it's still false, tell me exactly
what the `nextStep` field says and run it if it's a safe, non-destructive
command.

What your agent will do​

  • Check whether you're already licensed before sending you anywhere, so you don't pay twice.
  • Give you the correct checkout link and wait — it cannot fill in a card number or click "Subscribe" for you.
  • Re-verify the license activated after you confirm payment, and surface the exact recovery command if it didn't.

What only you can do: enter payment details and complete checkout in your own browser. This is a $5/month recurring charge — that decision, and the card behind it, has to be yours.

Step by step​

1. Subscribe​

Go to sigmashake.com/pricing and pick Pro ($5/month, unlimited evaluations) or Enterprise (contact sales). If you're already signed in and just want the direct checkout link, it's billing.sigmashake.com/start-checkout.

There is no free tier or trial of the governed value surfaces — rule evaluation, the audit trail, the dashboard, and Fleet are all gated fail-closed until an active subscription is on file for your account.

2. Activate the license on this machine​

If you're already signed in (see Sign in), the license attaches to your account automatically after payment — there's no key to copy or paste. Re-run login to force a refresh if it doesn't pick up right away:

ssg auth login

or, without a full re-login:

ssg auth refresh

3. Headless, Docker, Kubernetes, or CI environments​

Two headless options. If the target machine can't open a browser but you can, run ssg auth login --no-browser there — it prints a sign-in URL and code you open from any browser, and the license lands on the target machine. If you have an API key for your account (stored locally with ssg auth login --token=KEY), pass it as an environment variable instead and ssg exchanges it for a license at startup — no browser involved at all:

export SSG_API_KEY=<your-token>
ssg status
docker run --rm -e SSG_API_KEY ghcr.io/sigmashakeinc/ssg:latest status

4. What unlocks​

Once activated:

  • Unlimited rule evaluations (no monthly cap on Pro or Enterprise)
  • Every built-in and Hub-installed rule
  • The local audit log and the dashboard's Audit view
  • Fleet features, if your organization has Fleet configured

Until then, an unlicensed install runs the CLI but blocks the governed value surfaces. The exact message you'll see from a direct call is:

Pro license required to use ssg. Start your subscription: https://billing.sigmashake.com/start-checkout

Note the two enforcement paths differ on purpose: a direct ssg eval call fails closed (blocks) when the license can't be verified, because a caller expecting a governance decision shouldn't get a silent pass. The PreToolUse hook that runs inside your AI agent fails open (allows, with a warning to stderr) instead, because blocking every tool call in your editor until a license issue resolves is worse than a visible warning. See Plans & Limits for the full breakdown.

Verify​

ssg probe onboard

Check the auth object in the JSON output:

"auth":{"licensed":true,"tier":"pro","expiresMs":1755043200000}

auth.licensed: true means you're done. If it's false, follow the nextStep field the probe returns.

You can also check with:

ssg status
ssg status --json

The dashboard's Overview card shows the same tier and this month's evaluation count in real time — open it with ssg serve --open.

If something goes wrong​

SymptomCauseNext step
Payment succeeded but auth.licensed still shows falseThe CLI hasn't re-checked since paymentssg auth refresh (forces a re-exchange of your stored token for a fresh license)
Pro license required to use ssg from a direct commandNo active subscription linked to your signed-in account, or you're not signed in at allConfirm sign-in with ssg auth status, then subscribe at sigmashake.com/pricing
License worked yesterday, warning about expiry nowSubscription is nearing renewal or lapsed — ssg surfaces a soft warning 7 days out and an urgent one 1 day outCheck your payment method is current; manage or cancel from your account at accounts.sigmashake.com
CI/Docker run can't open a browser to activateBrowser-based auth login doesn't work headlesslyRun ssg auth login --no-browser and open the printed URL from any browser, or pass an API key for your account as SSG_API_KEY
Subscribed on the web but using the Mac App Store build of DesktopApple's App Review policy doesn't allow an external subscription to carry over into a Mac App Store buildPurchase the in-app Pro upgrade separately inside the Mac App Store app, or use the direct-download .dmg build instead, which does honor a web subscription
Want to change or cancel the planBilling is managed outside the CLIGo to accounts.sigmashake.com and use the billing management link there

Next​

  • Sign in — if ssg auth status shows no linked account yet.
  • Let your agent write rules — once licensed, this is how you safely let an agent author .rules files.
  • Plans & Limits — the full fail-open/fail-closed policy and usage reporting reference.