> Documentation index: https://docs.kiste.run/llms.txt, a list of every page in this documentation.

# Install the CLI

> Install kiste on macOS, Linux or Windows, verify the release, update it and remove it.

The Kiste CLI is one program, installed as `kiste` and as the short name `kst`.
It runs on macOS (Apple silicon and Intel), Linux on x86-64 (glibc and musl)
and 64-bit Windows.

## macOS and Linux

```bash
curl -fsSL https://kiste.run/install.sh | sh
```

> **Info:** CLI 0.1.1
>
> The steps below describe the installer of CLI 0.1.1, the release that is being
> published now. Until it is out, the installer at kiste.run installs 0.1.0,
> which checks only the SHA-256 checksum over HTTPS and verifies no signature.

The installer:

1. picks the build for your system (a Mac with Apple silicon gets the native
   build even in a Rosetta terminal; Alpine and other musl systems get the musl
   build);
2. downloads the archive, the checksum list and its signature over HTTPS;
3. verifies the signature of the checksum list with the Kiste release key, and
   that the signature names exactly the version it is installing, so an older
   release cannot be passed off as a newer one;
4. verifies the archive's SHA-256 checksum;
5. installs `kiste` into `~/.local/bin` and links `kst` to it.

If any check fails, nothing is installed. The signature is checked with
OpenSSL 3 when it is present, otherwise with the `perl` every Mac has.

Two environment variables change what it does:

| Variable | Effect |
| --- | --- |
| `KISTE_INSTALL_DIR` | Install somewhere else than `~/.local/bin` |
| `KISTE_VERSION` | Install a specific version, such as `0.1.1`, instead of the latest |

```bash
curl -fsSL https://kiste.run/install.sh | KISTE_INSTALL_DIR=/usr/local/bin sh
```

When the install directory is not on your `PATH`, the installer says so and
prints the directory to add.

## Windows

In PowerShell:

```text
irm https://kiste.run/install.ps1 | iex
```

It installs `kiste.exe` and `kst.exe` into `%LOCALAPPDATA%\Programs\Kiste`,
adds that folder to your user `PATH` and verifies the archive's SHA-256
checksum. `KISTE_INSTALL_DIR` and `KISTE_VERSION` work as on macOS and Linux.
Open a new terminal afterwards so the `PATH` change applies.

## Update

```bash
kiste self-update
```

`self-update` downloads the newest release, verifies its signature and
checksum like the installer, and replaces the running program. It refuses a
release whose signature is missing, made with another key, or made for another
version. `kiste self-update --check` only reports whether a newer release
exists.

## Shell completions

Completions know your commands, flags and the names of your Kisten. They ask
the installed CLI on every Tab, so they never go stale after an update.

### zsh

Add to `~/.zshrc`:

```bash
source <(kiste completions zsh)
```

### bash

Add to `~/.bashrc`:

```bash
source <(kiste completions bash)
```

### fish

Add to `~/.config/fish/config.fish`:

```bash
kiste completions fish | source
```

## Check the installation

```bash
kiste --version
kiste doctor
```

`kiste doctor` checks that kiste.run is reachable and healthy and that the CLI
is signed in.

## Verify a release yourself

From CLI 0.1.1 on, every release publishes `checksums.txt` and its signature
`checksums.txt.minisig`, made with this
[minisign](https://jedisct1.github.io/minisign/) public key:

```text
RWRqNbdNDw3TcrPUP83KtqWGpM+Kldb8WHmNi2efvBWrZ0CRhuP6iPx2
```

The files are at `https://kiste.run/downloads/cli/latest/` (or `v0.1.1/` and so
on for a specific version), next to the archives such as
`kiste-aarch64-apple-darwin.tar.gz`. With minisign installed:

```bash
minisign -Vm checksums.txt -P RWRqNbdNDw3TcrPUP83KtqWGpM+Kldb8WHmNi2efvBWrZ0CRhuP6iPx2
shasum -a 256 -c checksums.txt --ignore-missing
```

The trusted comment that minisign prints names the file and the version the
signature is for.

## Uninstall

Sign out first, so this computer's key is removed from your account, then
delete the program and its configuration:

```bash
kiste logout
rm ~/.local/bin/kiste ~/.local/bin/kst
rm -rf ~/.config/kiste
```

On Windows, delete `%LOCALAPPDATA%\Programs\Kiste` and `%APPDATA%\Kiste`.
The sign-in token lives in the system's credential store when there is one
(macOS Keychain, Windows Credential Manager, the Secret Service on a Linux
desktop) under the service name `run.kiste.cli`; `kiste logout` removes it.

## Related topics

- [What is Kiste](https://docs.kiste.run/get-started.md)
- [Quickstart](https://docs.kiste.run/get-started/quickstart.md)
- [Core concepts](https://docs.kiste.run/get-started/concepts.md)
- [FAQ](https://docs.kiste.run/get-started/faq.md)
- Previous: [Quickstart](https://docs.kiste.run/get-started/quickstart.md)
- Next: [Core concepts](https://docs.kiste.run/get-started/concepts.md)
