Get Started

Install

Install DefenseClaw on macOS, Linux, or Windows with one command, or build the current checkout from source.

Install

macOS and Linux:

curl -LsSf https://github.com/cisco-ai-defense/defenseclaw/releases/latest/download/install.sh | bash

Windows (PowerShell):

irm https://github.com/cisco-ai-defense/defenseclaw/releases/latest/download/install.ps1 | iex

When it finishes, run defenseclaw init to configure DefenseClaw. To pick an agent during the install, pass options: on macOS/Linux, end the command above with bash -s -- --connector codex --quickstart instead of bash; on Windows, run

& ([scriptblock]::Create((irm https://github.com/cisco-ai-defense/defenseclaw/releases/latest/download/install.ps1))) -Connector codex -Quickstart

The installer downloads the release's gateway, CLI wheel, and a hash-pinned list of the CLI's Python dependencies, and checks each file against the release's checksums.txt. When cosign 2.0 or later is installed it also verifies the Sigstore signature on checksums.txt. It installs uv if you do not have it, and uv provides the Python runtime; nothing else is required.

The same command upgrades or repairs an existing install and keeps your configuration and data. Day to day, use defenseclaw upgrade, which runs the latest release's installer for you.

Option (install.sh / install.ps1)What it does
--yes / -YesDo not prompt
--version X.Y.Z / -Version X.Y.ZInstall a specific release
--local DIR / -Local DIRTake every release file from a directory instead of GitHub
--rollback / -RollbackRestore the install that the last upgrade replaced
--connector NAME / -Connector NAMEFirst install only: the agent to guard
--quickstart / -QuickstartFirst install only: run defenseclaw quickstart afterwards

Supported platforms

macOS on Apple Silicon (arm64), Linux on x86_64 and arm64, and Windows on x64. Intel Macs are unsupported; the installer stops before changing anything. Rosetta does not make an Intel Mac a supported target.

Installing as root is supported but discouraged — DefenseClaw is per-user by design so each operator's audit DB and connector state stays isolated.

Prerequisites for source builds

RequirementVersion
Python3.10-3.13 for source builds
Go1.26.4+ (only for source builds)
GitRequired to clone and identify a source checkout
GNU Make and a POSIX shellRequired by the documented source workflow
uvRequired by make all / the pycli target
Node.js and npmRequired only when a source build selects the OpenClaw plugin; use the runtime version required by that OpenClaw release
DockerOptional, for local observability and Splunk bundles

Agent-specific dependencies and quirks live on the connector pages.

What's bundled (LLM backends)

The base install ships everything DefenseClaw needs to talk to the major LLM backends out of the box:

BackendStatusNotes
OpenAI / Anthropic / generic OpenAI-compatiblebundledLiteLLM, the default LLM transport, is a base dependency.
AWS Bedrockbundledboto3 ships in [project].dependencies so SigV4, IAM credential modes, and Anthropic-on-Bedrock bearer tokens work without a follow-up pip install.
Google Vertex AIGateway bundled; Python SDK opt-inThe Go gateway routes Vertex through its bundled Bifrost backend. Python CLI scanner/judge paths use LiteLLM and require the [vertex] extra for the Google SDK and supported Vertex authentication; the SDK pulls ~286 MB of transitive dependencies. Source contributors can add it to their isolated checkout with uv sync --extra vertex; never modify a release-managed runtime. There is no documented SDK-less Python fallback.
Azure OpenAIbundledRouted via LiteLLM's azure_openai adapter.
Self-hosted / internal endpointsbundledConfigure via defenseclaw setup provider add → see Unified LLM key → Custom providers.

Install from source

Release version versus source metadata

A source build reports the checked-in source version. The Release workflow stamps the release version into its own build checkout, so a source build must not be represented as a published artifact.

GoalCommand
Normal same-checkout developmentmake all
Build artifacts without installingmake build
Show developer workflow helpmake help
Upgrade a release installdefenseclaw upgrade
git clone https://github.com/cisco-ai-defense/defenseclaw.git
cd defenseclaw
make all CONNECTOR=none
defenseclaw init

make all installs the editable Python CLI, builds and installs the Go gateway, updates your PATH, and normally runs quickstart. The example sets CONNECTOR=none to skip that automatic first-run configuration, then invokes defenseclaw init explicitly. Omit CONNECTOR=none when you want make all to run quickstart itself. The OpenClaw plugin is installed when CONNECTOR=openclaw is selected.

Source builds are development tooling, not a packaged upgrade path. make all is the explicit developer reinstall workflow: it may reclaim markerless or older source state only when the installed CLI belongs to this exact checkout. It validates marker ownership, rejects foreign and newer source identities, and records the current strict marker after a successful rebuild. Direct make install, scripts/install-dev.sh, and release-managed hosts remain fail-closed. Release installations must use defenseclaw upgrade; do not aim a raw pip, uv, or editable install at a release-managed virtual environment. The lower-level install targets are for fresh or isolated development homes, not the normal repeated-development path.

Local dist output is not a release

make dist builds release-shaped files for testing the installer with --local dist. They are unsigned; do not present them as published binaries.

What the install creates

config.yaml
audit.db

The installer also keeps ~/.defenseclaw/installer/ (the installer that performed the current install, used by defenseclaw rollback), ~/.defenseclaw/previous/ (the install the last upgrade replaced), and ~/.defenseclaw/logs/.

On Windows the same layout lives under %USERPROFILE%: %USERPROFILE%\.defenseclaw\ holds configuration, data, and the Python environment, and %USERPROFILE%\.local\bin\ holds defenseclaw.cmd, defenseclaw-gateway.exe, defenseclaw-hook.exe, and defenseclaw-acp.exe. The installer adds %USERPROFILE%\.local\bin to your user PATH.

Verify

defenseclaw --version
defenseclaw doctor

Doctor verifies:

CheckWhat it verifies
ConfigurationThe canonical config exists, loads, and validates.
Audit and identity stateFile custody, SQLite integrity and required schema, storage capacity, device-key custody, and HMAC-bound provenance.
Components and connectorsCLI/gateway/plugin alignment and active connector versions against registered compatibility contracts.
GatewayManaged process and listener identity, public health, and authenticated /status using the locally resolved token.
Guardrail, scanners, and credentialsEnabled service reachability, required scanner binaries, and configured credential availability without printing secret values.
ObservabilityEffective destination routes, queue/delivery health, and each destination/signal circuit while mandatory local SQLite remains available.

Useful modes:

# Avoid billable, content-submitting, and synthetic probes
defenseclaw doctor --passive

# Machine-readable schema v2
defenseclaw doctor --json-output

# Preview eligible repairs without mutation
defenseclaw doctor --fix --dry-run

# Apply eligible safe and disruptive repairs
defenseclaw doctor --fix --yes

# Select one repair and its declared dependencies
defenseclaw doctor --fix --fix-id doctor.state.audit-db.initialize

# Identity recovery is always attended; do not add --yes
defenseclaw doctor --fix --fix-id doctor.identity.device-key.initialize

Doctor executes skill-scanner --version through the resolved installed launcher. A stale launcher or interpreter mismatch is therefore reported as a failure instead of appearing merely "installed" because a file exists.

--fix applies selected repairs before the health pass, so its summary describes post-repair state. A failed health check or failed or blocked repair exits 1. See the Doctor CLI reference for the machine contract and Reporting and diagnosis for token, recovery, compatibility, and approval boundaries.

Uninstall

defenseclaw uninstall              # reversible — keeps ~/.defenseclaw/ and binaries
defenseclaw uninstall --all        # also delete ~/.defenseclaw/ (audit log, config, secrets)
defenseclaw uninstall --binaries   # also remove managed CLI and scanner launchers
defenseclaw uninstall --all --binaries --yes   # full nuke, no confirm prompt

The default tears down connector integrations and leaves ~/.defenseclaw/ and the installed binaries on disk so a subsequent defenseclaw setup guardrail can pick up where you left off. An unchanged managed connector file is restored byte-for-byte from its hash-checked snapshot; after user edits, connector-specific cleanup removes only DefenseClaw-owned entries and preserves unrelated changes. Use --all and/or --binaries to make the removal total. On POSIX installs, --binaries also removes the managed skill-scanner, skill-scanner-api, skill-scanner-pre-commit, mcp-scanner, mcp-scanner-api, and litellm launchers from ~/.local/bin. --dry-run previews the plan.

Next