<!-- https://zunderlabs.com/docs/deploy/packages · Markdown version of the page -->

# Homebrew and winget

Install Guard on macOS with Homebrew or on Windows with winget.

:::note[Planned]
No package is published yet. The tap and the package id are planned names.
:::

## macOS: Homebrew

```sh
brew install zunderlabs/tap/zunder-guard
zunder-guard init --interactive      # rules, account, mode; for testnet the key, hidden
brew services start zunder-guard
```

Homebrew on Linux works the same way.

## Windows: winget

```powershell
winget install ZunderLabs.ZunderGuard
zunder-guard init --interactive
zunder-guard run
```

The setup asks for the key itself (testnet and mainnet only). A testnet key goes into the system keychain. A mainnet key is checked and never stored: `zunder-guard run --network mainnet --key-stdin` takes it on standard input at every start.

## With your rules

```sh
zunder-guard init --interactive \
  --rules zr1_eyJ2IjoxLCJtYXhMZXZlcmFnZSI6NSwibWF4TG9zc0F0U3RvcFBjdCI6Miwic3RvcFBvbGljeSI6ImF0dGFjaCIsImRlZmF1bHRTdG9wRGlzdGFuY2VQY3QiOjIsIm1pbkxpcURpc3RhbmNlUGN0IjoxMCwibWF4UG9zaXRpb25QY3QiOjIwMCwibWF4T3BlblJpc2tQY3QiOjYsImRhaWx5TG9zc1N0b3BQY3QiOjYsImRyYXdkb3duSGFsdFBjdCI6MjUsIm1hcmtldHMiOlsiKiJdfQ
```

## Verify what the package manager installed

A package manager checks a checksum it got from the same place as the package. To check against the release itself:

Homebrew and winget check the SHA-256 that the release workflow wrote into the formula and the manifest. To check against the signed release yourself, download the same archive, verify it against `SHA256SUMS` and that file's signature ([Verify a release](https://zunderlabs.com/docs/deploy/verify)), and compare the binary inside with the installed one:

```sh
zunder-guard --version                       # the version you have
shasum -a 256 "$(command -v zunder-guard)"   # equals zunder-guard inside the verified archive
```
