Installation and setup
One matched runtime, explicit platform selection and a safe first-run setup.
Download the matching Semwright 1.0.0 bundle and SHA256SUMS, verify the checksum, extract, install and run semwright setup. No Rust build is required. The homepage installation panel lists the six portable archives with their hashes and sizes; Linux .deb alternatives are available on the release page.
Independent security review is incomplete. This release is published under an explicit maintainer exception.
Build from source remains an alternative for contributors. The procedure below uses the verified public native bundles.
Choose the matching package
Section titled “Choose the matching package”| Platform | Public native archives | Installer inside the extracted archive |
|---|---|---|
| Linux | x86_64 / aarch64 .tar.gz; amd64 / arm64 .deb alternatives |
./install.sh |
| macOS | Apple Silicon arm64 / Intel x86_64 .tar.gz |
./install.sh |
| Windows | x86_64 / ARM64 .zip |
.\Install-Semwright.ps1 |
Compare the archive with the external SHA256SUMS before extraction. Read the included helper before running it. The portable installer checks internal package hashes and installs per-user. Matching hashes establish matching bytes; they do not establish that an unknown publisher is trustworthy.
macOS archives remain unsigned and unnotarized until signing infrastructure is established. Installation does not disable Gatekeeper, SIP or TCC. Native package CI is distinct from physical desktop certification.
Install the core once
Section titled “Install the core once”The bundle contains one matched version of five commands:
| Command | Purpose |
|---|---|
semwright |
CLI and first-run setup |
semwrightd |
Local broker |
semwright-mcp |
Stdio MCP frontend |
semwright-inspect |
Read-only terminal inspector |
semwright-sandbox |
Platform isolation helper or fail-closed sentinel |
Third-party applications, models and optional application integrations are separate. The core does not silently install them.
Run setup, then start the broker
Section titled “Run setup, then start the broker”Run the installed semwright setup command printed by the installer. Setup creates missing private observe-only configuration and a ready-to-copy MCP client snippet. It preserves existing files, grants no desktop authority and starts no background service.
Use semwright --dry-run --json setup to inspect the intended paths first. Setup prints the exact broker, doctor, inspector and MCP executable paths for your OS. Start the printed broker command, then run the printed doctor command from a second terminal.
Do not guess an executable path or copy a Linux prefix onto Windows or macOS. MCP configuration uses the installed path produced by setup.
Keep installation reversible
Section titled “Keep installation reversible”Use the removal helper supplied with the same package and read its preservation rules. Uninstall is distinct from removing user configuration and project data. Never bypass an operating-system security policy to finish setup.
Source: installation and quick start, source references checked 7 October 2026.