<!-- https://zunder-design-preview.pages.dev/docs/deploy/macos · Markdown version of the page -->

# macOS

Run Guard as a managed mainnet service with System Keychain credentials.

Install Guard on the Mac where your bot runs:

```sh
curl -fsSL https://zunder-design-preview.pages.dev/i | sh -s -- --network mainnet
```

The command from [Set up Guard](https://zunder-design-preview.pages.dev/connect#guard) can also include your public account and rules. Setup asks for administrator authorization, separate account confirmation, an equity cap and the API wallet key through hidden input.

The verified installer creates a protected, versioned executable and a system LaunchDaemon. A privileged broker reads the account- and release-bound credential from **System Keychain**, then passes it over standard input to Guard running as the dedicated `_zunder_guard` user. It does not depend on a login Keychain or a desktop session. On an encrypted Mac, boot still requires the disk to be unlocked.

## Finish setup

The installer prints the exact journal and startup commands and leaves the mainnet service stopped. Use those commands with the service's home and protected executable; commands aimed at `~/.zunder-guard` would configure a different installation.

1. Save the bot client key and pairing code from setup.
2. Activate your [licence](https://zunder-design-preview.pages.dev/docs/start/licence) or approve [pay per order](https://zunder-design-preview.pages.dev/approve).
3. Explicitly initialize the account's mainnet journal only if none exists. Keep an existing journal and any halt it records.
4. Start the prepared service with the printed command. Check health, mainnet account, risk state and fee mode before starting your bot.

Guard listens on `127.0.0.1:8547`. A loaded LaunchDaemon alone is not proof that credentials, journal and venue synchronization are ready.

## Manage the installation

Use the protected executable and binding paths printed by setup. Stop bots and unload the service before pairing another client, changing admitted configuration or upgrading. Pairing and risk-policy edits require explicit configuration readmission; licence activation and renewal do not.

An upgrade verifies the new release, transfers the credential privately between the admitted old and new brokers, and preserves configuration, pairings, licence and journals. It leaves the replacement stopped for your explicit start. Keep the previous release and credential until the new service is verified.

Stopping or removing service registration does not delete your state. Credential deletion is a separate deliberate action while the service is unloaded; keep journals for recovery and records.

## Paper and Homebrew

For a paper rehearsal, use `--network paper` in the installer. [Homebrew](https://zunder-design-preview.pages.dev/docs/deploy/packages) provides the CLI and a paper service. Mainnet uses the separately verified machine service above, including when you already have Homebrew installed. Never run a Homebrew Cellar binary with `sudo` to provision the privileged broker.
