Get started

Install the CLI

Install kiste on macOS, Linux or Windows, verify the release, update it and remove it.

The Kiste CLI is one program, installed as kiste and as the short name kst. It runs on macOS (Apple silicon and Intel), Linux on x86-64 (glibc and musl) and 64-bit Windows.

macOS and Linux

curl -fsSL https://kiste.run/install.sh | sh

CLI 0.1.1

The steps below describe the installer of CLI 0.1.1, the release that is being published now. Until it is out, the installer at kiste.run installs 0.1.0, which checks only the SHA-256 checksum over HTTPS and verifies no signature.

The installer:

  1. picks the build for your system (a Mac with Apple silicon gets the native build even in a Rosetta terminal; Alpine and other musl systems get the musl build);
  2. downloads the archive, the checksum list and its signature over HTTPS;
  3. verifies the signature of the checksum list with the Kiste release key, and that the signature names exactly the version it is installing, so an older release cannot be passed off as a newer one;
  4. verifies the archive's SHA-256 checksum;
  5. installs kiste into ~/.local/bin and links kst to it.

If any check fails, nothing is installed. The signature is checked with OpenSSL 3 when it is present, otherwise with the perl every Mac has.

Two environment variables change what it does:

VariableEffect
KISTE_INSTALL_DIRInstall somewhere else than ~/.local/bin
KISTE_VERSIONInstall a specific version, such as 0.1.1, instead of the latest
curl -fsSL https://kiste.run/install.sh | KISTE_INSTALL_DIR=/usr/local/bin sh

When the install directory is not on your PATH, the installer says so and prints the directory to add.

Windows

In PowerShell:

irm https://kiste.run/install.ps1 | iex

It installs kiste.exe and kst.exe into %LOCALAPPDATA%\Programs\Kiste, adds that folder to your user PATH and verifies the archive's SHA-256 checksum. KISTE_INSTALL_DIR and KISTE_VERSION work as on macOS and Linux. Open a new terminal afterwards so the PATH change applies.

Update

kiste self-update

self-update downloads the newest release, verifies its signature and checksum like the installer, and replaces the running program. It refuses a release whose signature is missing, made with another key, or made for another version. kiste self-update --check only reports whether a newer release exists.

Shell completions

Completions know your commands, flags and the names of your Kisten. They ask the installed CLI on every Tab, so they never go stale after an update.

Add to ~/.zshrc:

source <(kiste completions zsh)

Check the installation

kiste --version
kiste doctor

kiste doctor checks that kiste.run is reachable and healthy and that the CLI is signed in.

Verify a release yourself

From CLI 0.1.1 on, every release publishes checksums.txt and its signature checksums.txt.minisig, made with this minisign public key:

RWRqNbdNDw3TcrPUP83KtqWGpM+Kldb8WHmNi2efvBWrZ0CRhuP6iPx2

The files are at https://kiste.run/downloads/cli/latest/ (or v0.1.1/ and so on for a specific version), next to the archives such as kiste-aarch64-apple-darwin.tar.gz. With minisign installed:

minisign -Vm checksums.txt -P RWRqNbdNDw3TcrPUP83KtqWGpM+Kldb8WHmNi2efvBWrZ0CRhuP6iPx2
shasum -a 256 -c checksums.txt --ignore-missing

The trusted comment that minisign prints names the file and the version the signature is for.

Uninstall

Sign out first, so this computer's key is removed from your account, then delete the program and its configuration:

kiste logout
rm ~/.local/bin/kiste ~/.local/bin/kst
rm -rf ~/.config/kiste

On Windows, delete %LOCALAPPDATA%\Programs\Kiste and %APPDATA%\Kiste. The sign-in token lives in the system's credential store when there is one (macOS Keychain, Windows Credential Manager, the Secret Service on a Linux desktop) under the service name run.kiste.cli; kiste logout removes it.

On this page