Subscribe and activate
By the end of this tutorial, you have an active $5/month subscription and ssg probe onboard reports auth.licensed: true on this machine.
You must already be signed in for this to work — if ssg auth status shows no linked account, do the Sign in tutorial first.
Hand this to your AI agent
Help me subscribe to SigmaShake and confirm the license activated. You cannot
pay for me — that step needs my card in a browser — so hand me the link and
wait for me to confirm.
1. Check my current state:
ssg auth status
ssg probe onboard
If `auth.licensed` is already true in the probe output, tell me I'm
already subscribed and stop here.
2. If not, tell me to open https://sigmashake.com/pricing (or, if I already
have an account and just need to check out directly:
https://billing.sigmashake.com/start-checkout) and complete payment in my
browser. Wait for me to confirm I've finished.
3. Re-run:
ssg probe onboard
Confirm `auth.licensed` is now true. If it's still false, tell me exactly
what the `nextStep` field says and run it if it's a safe, non-destructive
command.
What your agent will do
- Check whether you're already licensed before sending you anywhere, so you don't pay twice.
- Give you the correct checkout link and wait — it cannot fill in a card number or click "Subscribe" for you.
- Re-verify the license activated after you confirm payment, and surface the exact recovery command if it didn't.
What only you can do: enter payment details and complete checkout in your own browser. This is a $5/month recurring charge — that decision, and the card behind it, has to be yours.
Step by step
1. Subscribe
Go to sigmashake.com/pricing and pick Pro ($5/month, unlimited evaluations) or Enterprise (contact sales). If you're already signed in and just want the direct checkout link, it's billing.sigmashake.com/start-checkout.
There is no free tier or trial of the governed value surfaces — rule evaluation, the audit trail, the dashboard, and Fleet are all gated fail-closed until an active subscription is on file for your account.
2. Activate the license on this machine
If you're already signed in (see Sign in), the license attaches to your account automatically after payment — there's no key to copy or paste. Re-run login to force a refresh if it doesn't pick up right away:
ssg auth login
or, without a full re-login:
ssg auth refresh
3. Headless, Docker, Kubernetes, or CI environments
Two headless options. If the target machine can't open a browser but you can, run ssg auth login --no-browser there — it prints a sign-in URL and code you open from any browser, and the license lands on the target machine. If you have an API key for your account (stored locally with ssg auth login --token=KEY), pass it as an environment variable instead and ssg exchanges it for a license at startup — no browser involved at all:
export SSG_API_KEY=<your-token>
ssg status
docker run --rm -e SSG_API_KEY ghcr.io/sigmashakeinc/ssg:latest status
4. What unlocks
Once activated:
- Unlimited rule evaluations (no monthly cap on Pro or Enterprise)
- Every built-in and Hub-installed rule
- The local audit log and the dashboard's Audit view
- Fleet features, if your organization has Fleet configured
Until then, an unlicensed install runs the CLI but blocks the governed value surfaces. The exact message you'll see from a direct call is:
Pro license required to use ssg. Start your subscription: https://billing.sigmashake.com/start-checkout
Note the two enforcement paths differ on purpose: a direct ssg eval call fails closed (blocks) when the license can't be verified, because a caller expecting a governance decision shouldn't get a silent pass. The PreToolUse hook that runs inside your AI agent fails open (allows, with a warning to stderr) instead, because blocking every tool call in your editor until a license issue resolves is worse than a visible warning. See Plans & Limits for the full breakdown.
Verify
ssg probe onboard
Check the auth object in the JSON output:
"auth":{"licensed":true,"tier":"pro","expiresMs":1755043200000}
auth.licensed: true means you're done. If it's false, follow the nextStep field the probe returns.
You can also check with:
ssg status
ssg status --json
The dashboard's Overview card shows the same tier and this month's evaluation count in real time — open it with ssg serve --open.
If something goes wrong
| Symptom | Cause | Next step |
|---|---|---|
Payment succeeded but auth.licensed still shows false | The CLI hasn't re-checked since payment | ssg auth refresh (forces a re-exchange of your stored token for a fresh license) |
Pro license required to use ssg from a direct command | No active subscription linked to your signed-in account, or you're not signed in at all | Confirm sign-in with ssg auth status, then subscribe at sigmashake.com/pricing |
| License worked yesterday, warning about expiry now | Subscription is nearing renewal or lapsed — ssg surfaces a soft warning 7 days out and an urgent one 1 day out | Check your payment method is current; manage or cancel from your account at accounts.sigmashake.com |
| CI/Docker run can't open a browser to activate | Browser-based auth login doesn't work headlessly | Run ssg auth login --no-browser and open the printed URL from any browser, or pass an API key for your account as SSG_API_KEY |
| Subscribed on the web but using the Mac App Store build of Desktop | Apple's App Review policy doesn't allow an external subscription to carry over into a Mac App Store build | Purchase the in-app Pro upgrade separately inside the Mac App Store app, or use the direct-download .dmg build instead, which does honor a web subscription |
| Want to change or cancel the plan | Billing is managed outside the CLI | Go to accounts.sigmashake.com and use the billing management link there |
Next
- Sign in — if
ssg auth statusshows no linked account yet. - Let your agent write rules — once licensed, this is how you safely let an agent author
.rulesfiles. - Plans & Limits — the full fail-open/fail-closed policy and usage reporting reference.