Skip to content

Installation and setup

One matched runtime, explicit platform selection and a safe first-run setup.

Download the matching Semwright 1.0.0 bundle and SHA256SUMS, verify the checksum, extract, install and run semwright setup. No Rust build is required. The homepage installation panel lists the six portable archives with their hashes and sizes; Linux .deb alternatives are available on the release page.

Independent security review is incomplete. This release is published under an explicit maintainer exception.

Build from source remains an alternative for contributors. The procedure below uses the verified public native bundles.

Platform Public native archives Installer inside the extracted archive
Linux x86_64 / aarch64 .tar.gz; amd64 / arm64 .deb alternatives ./install.sh
macOS Apple Silicon arm64 / Intel x86_64 .tar.gz ./install.sh
Windows x86_64 / ARM64 .zip .\Install-Semwright.ps1

Compare the archive with the external SHA256SUMS before extraction. Read the included helper before running it. The portable installer checks internal package hashes and installs per-user. Matching hashes establish matching bytes; they do not establish that an unknown publisher is trustworthy.

macOS archives remain unsigned and unnotarized until signing infrastructure is established. Installation does not disable Gatekeeper, SIP or TCC. Native package CI is distinct from physical desktop certification.

The bundle contains one matched version of five commands:

Command Purpose
semwright CLI and first-run setup
semwrightd Local broker
semwright-mcp Stdio MCP frontend
semwright-inspect Read-only terminal inspector
semwright-sandbox Platform isolation helper or fail-closed sentinel

Third-party applications, models and optional application integrations are separate. The core does not silently install them.

Run the installed semwright setup command printed by the installer. Setup creates missing private observe-only configuration and a ready-to-copy MCP client snippet. It preserves existing files, grants no desktop authority and starts no background service.

Use semwright --dry-run --json setup to inspect the intended paths first. Setup prints the exact broker, doctor, inspector and MCP executable paths for your OS. Start the printed broker command, then run the printed doctor command from a second terminal.

Do not guess an executable path or copy a Linux prefix onto Windows or macOS. MCP configuration uses the installed path produced by setup.

Use the removal helper supplied with the same package and read its preservation rules. Uninstall is distinct from removing user configuration and project data. Never bypass an operating-system security policy to finish setup.

Source: installation and quick start, source references checked 7 October 2026.