Install
Install DefenseClaw on macOS, Linux, or Windows with one command, or build the current checkout from source.
Install
macOS and Linux:
curl -LsSf https://github.com/cisco-ai-defense/defenseclaw/releases/latest/download/install.sh | bashWindows (PowerShell):
irm https://github.com/cisco-ai-defense/defenseclaw/releases/latest/download/install.ps1 | iexWhen it finishes, run defenseclaw init to
configure DefenseClaw. To pick an agent during the install, pass options: on
macOS/Linux, end the command above with bash -s -- --connector codex --quickstart
instead of bash; on Windows, run
& ([scriptblock]::Create((irm https://github.com/cisco-ai-defense/defenseclaw/releases/latest/download/install.ps1))) -Connector codex -QuickstartThe installer downloads the release's gateway, CLI wheel, and a hash-pinned
list of the CLI's Python dependencies, and checks each file against the
release's checksums.txt. When cosign 2.0 or later is installed it also verifies the
Sigstore signature on checksums.txt. It installs uv if you do not have it,
and uv provides the Python runtime; nothing else is required.
The same command upgrades or repairs an existing install and keeps your
configuration and data. Day to day, use defenseclaw upgrade,
which runs the latest release's installer for you.
Option (install.sh / install.ps1) | What it does |
|---|---|
--yes / -Yes | Do not prompt |
--version X.Y.Z / -Version X.Y.Z | Install a specific release |
--local DIR / -Local DIR | Take every release file from a directory instead of GitHub |
--rollback / -Rollback | Restore the install that the last upgrade replaced |
--connector NAME / -Connector NAME | First install only: the agent to guard |
--quickstart / -Quickstart | First install only: run defenseclaw quickstart afterwards |
Supported platforms
macOS on Apple Silicon (arm64), Linux on x86_64 and arm64, and Windows on
x64. Intel Macs are unsupported; the installer stops before changing
anything. Rosetta does not make an Intel Mac a supported target.
Installing as root is supported but discouraged — DefenseClaw is per-user by design so each operator's audit DB and connector state stays isolated.
Prerequisites for source builds
| Requirement | Version |
|---|---|
| Python | 3.10-3.13 for source builds |
| Go | 1.26.4+ (only for source builds) |
| Git | Required to clone and identify a source checkout |
| GNU Make and a POSIX shell | Required by the documented source workflow |
uv | Required by make all / the pycli target |
| Node.js and npm | Required only when a source build selects the OpenClaw plugin; use the runtime version required by that OpenClaw release |
| Docker | Optional, for local observability and Splunk bundles |
Agent-specific dependencies and quirks live on the connector pages.
What's bundled (LLM backends)
The base install ships everything DefenseClaw needs to talk to the major LLM backends out of the box:
| Backend | Status | Notes |
|---|---|---|
| OpenAI / Anthropic / generic OpenAI-compatible | bundled | LiteLLM, the default LLM transport, is a base dependency. |
| AWS Bedrock | bundled | boto3 ships in [project].dependencies so SigV4, IAM credential modes, and Anthropic-on-Bedrock bearer tokens work without a follow-up pip install. |
| Google Vertex AI | Gateway bundled; Python SDK opt-in | The Go gateway routes Vertex through its bundled Bifrost backend. Python CLI scanner/judge paths use LiteLLM and require the [vertex] extra for the Google SDK and supported Vertex authentication; the SDK pulls ~286 MB of transitive dependencies. Source contributors can add it to their isolated checkout with uv sync --extra vertex; never modify a release-managed runtime. There is no documented SDK-less Python fallback. |
| Azure OpenAI | bundled | Routed via LiteLLM's azure_openai adapter. |
| Self-hosted / internal endpoints | bundled | Configure via defenseclaw setup provider add → see Unified LLM key → Custom providers. |
Install from source
Release version versus source metadata
A source build reports the checked-in source version. The Release workflow stamps the release version into its own build checkout, so a source build must not be represented as a published artifact.
| Goal | Command |
|---|---|
| Normal same-checkout development | make all |
| Build artifacts without installing | make build |
| Show developer workflow help | make help |
| Upgrade a release install | defenseclaw upgrade |
git clone https://github.com/cisco-ai-defense/defenseclaw.git
cd defenseclaw
make all CONNECTOR=none
defenseclaw initmake all installs the editable Python CLI, builds and installs the Go gateway,
updates your PATH, and normally runs quickstart. The example sets
CONNECTOR=none to skip that automatic first-run configuration, then invokes
defenseclaw init explicitly. Omit CONNECTOR=none when you want make all
to run quickstart itself. The OpenClaw plugin is installed when
CONNECTOR=openclaw is selected.
Source builds are development tooling, not a packaged upgrade path. make all
is the explicit developer reinstall workflow: it may reclaim markerless or
older source state only when the installed CLI belongs to this exact checkout.
It validates marker ownership, rejects foreign and newer source identities,
and records the current strict marker after a successful rebuild. Direct
make install, scripts/install-dev.sh, and release-managed hosts remain
fail-closed. Release installations must use defenseclaw upgrade; do not aim a
raw pip, uv, or editable install at a release-managed virtual environment.
The lower-level install targets are for fresh or isolated development homes,
not the normal repeated-development path.
Local dist output is not a release
make dist builds release-shaped files for testing the installer with
--local dist. They are unsigned; do not present them as published binaries.
What the install creates
The installer also keeps ~/.defenseclaw/installer/ (the installer that
performed the current install, used by defenseclaw rollback),
~/.defenseclaw/previous/ (the install the last upgrade replaced), and
~/.defenseclaw/logs/.
On Windows the same layout lives under %USERPROFILE%:
%USERPROFILE%\.defenseclaw\ holds configuration, data, and the Python
environment, and %USERPROFILE%\.local\bin\ holds defenseclaw.cmd,
defenseclaw-gateway.exe, defenseclaw-hook.exe, and defenseclaw-acp.exe.
The installer adds %USERPROFILE%\.local\bin to your user PATH.
Verify
defenseclaw --version
defenseclaw doctorDoctor verifies:
| Check | What it verifies |
|---|---|
| Configuration | The canonical config exists, loads, and validates. |
| Audit and identity state | File custody, SQLite integrity and required schema, storage capacity, device-key custody, and HMAC-bound provenance. |
| Components and connectors | CLI/gateway/plugin alignment and active connector versions against registered compatibility contracts. |
| Gateway | Managed process and listener identity, public health, and authenticated /status using the locally resolved token. |
| Guardrail, scanners, and credentials | Enabled service reachability, required scanner binaries, and configured credential availability without printing secret values. |
| Observability | Effective destination routes, queue/delivery health, and each destination/signal circuit while mandatory local SQLite remains available. |
Useful modes:
# Avoid billable, content-submitting, and synthetic probes
defenseclaw doctor --passive
# Machine-readable schema v2
defenseclaw doctor --json-output
# Preview eligible repairs without mutation
defenseclaw doctor --fix --dry-run
# Apply eligible safe and disruptive repairs
defenseclaw doctor --fix --yes
# Select one repair and its declared dependencies
defenseclaw doctor --fix --fix-id doctor.state.audit-db.initialize
# Identity recovery is always attended; do not add --yes
defenseclaw doctor --fix --fix-id doctor.identity.device-key.initializeDoctor executes skill-scanner --version through the resolved installed
launcher. A stale launcher or interpreter mismatch is therefore reported as a
failure instead of appearing merely "installed" because a file exists.
--fix applies selected repairs before the health pass, so its summary
describes post-repair state. A failed health check or failed or blocked repair
exits 1. See the Doctor CLI reference for the
machine contract and Reporting and diagnosis
for token, recovery, compatibility, and approval boundaries.
Uninstall
defenseclaw uninstall # reversible — keeps ~/.defenseclaw/ and binaries
defenseclaw uninstall --all # also delete ~/.defenseclaw/ (audit log, config, secrets)
defenseclaw uninstall --binaries # also remove managed CLI and scanner launchers
defenseclaw uninstall --all --binaries --yes # full nuke, no confirm promptThe default tears down connector integrations and leaves
~/.defenseclaw/ and the installed binaries on disk so a subsequent
defenseclaw setup guardrail can pick up where you left off. An unchanged
managed connector file is restored byte-for-byte from its hash-checked
snapshot; after user edits, connector-specific cleanup removes only
DefenseClaw-owned entries and preserves unrelated changes. Use --all and/or
--binaries to make the removal total. On POSIX installs, --binaries also
removes the managed skill-scanner, skill-scanner-api,
skill-scanner-pre-commit, mcp-scanner, mcp-scanner-api, and litellm
launchers from ~/.local/bin. --dry-run previews the plan.