<!-- https://zunder-design-preview.pages.dev/docs/deploy/packages · Markdown version of the page -->

# Homebrew

Install Guard on macOS or Linux with Homebrew.

:::note[Planned]
No package is published yet: the tap is the planned name. There is no Windows package in the first release, because Guard does not build for Windows yet; on Windows, use Docker Desktop or WSL with the Docker or Linux instructions.
:::

Use this alternative to install through your platform’s package manager. For choosing a machine and the complete paper-first sequence, start with [the setup journey](https://zunder-design-preview.pages.dev/docs/deploy).

## macOS: Homebrew

The Homebrew service keeps Guard's home in `$(brew --prefix)/var/zunder-guard`, not in `~/.zunder-guard`, so the setup has to write there:

```sh
brew install zunderlabs/tap/zunder-guard
ZUNDER_GUARD_HOME="$(brew --prefix)/var/zunder-guard" zunder-guard init --interactive   # rules, account, mode; for testnet the key, hidden
brew services start zunder-guard
```

The service starts `zunder-guard run` without a network, so it runs **paper mode only**. A testnet config makes it refuse to start. For testnet, run Guard yourself instead of the service:

```sh
ZUNDER_GUARD_HOME="$(brew --prefix)/var/zunder-guard" zunder-guard run --network testnet
```

Homebrew on Linux works the same way.

## Where the key goes

The setup asks for the key itself (testnet and mainnet only). A testnet key goes into the file `api-wallet-key` in Guard's home, mode 0600, readable only by you; Guard says at setup that it lies there in plain text, and `run --network testnet` reads it from there. There is no keychain support. A mainnet key is checked and never stored: it comes on standard input at every start, for example `your-key-command | ZUNDER_MAINNET_CONFIRM=0xYourAccountAddress zunder-guard run --network mainnet --key-stdin`.

## With your rules

For the Homebrew service, put `ZUNDER_GUARD_HOME="$(brew --prefix)/var/zunder-guard"` in front, as above.

```sh
zunder-guard init --interactive \
  --rules zr1_eyJ2IjoxLCJtYXhMZXZlcmFnZSI6NSwibWF4TG9zc0F0U3RvcFBjdCI6Miwic3RvcFBvbGljeSI6ImF0dGFjaCIsImRlZmF1bHRTdG9wRGlzdGFuY2VQY3QiOjIsIm1pbkxpcURpc3RhbmNlUGN0IjoxMCwibWF4UG9zaXRpb25QY3QiOjIwMCwibWF4T3BlblJpc2tQY3QiOjYsImRhaWx5TG9zc1N0b3BQY3QiOjYsImRyYXdkb3duSGFsdFBjdCI6MjUsIm1hcmtldHMiOlsiKiJdfQ
```

## Verify what the package manager installed

A package manager checks a checksum it got from the same place as the package. To check against the release itself:

Homebrew checks the SHA-256 that the release workflow wrote into the formula. To check against the signed release yourself, download the same archive, verify it against `SHA256SUMS` and that file's signature ([Verify a release](https://zunder-design-preview.pages.dev/docs/deploy/verify)), and compare the binary inside with the installed one:

```sh
zunder-guard --version                       # the version you have
shasum -a 256 "$(command -v zunder-guard)"   # equals zunder-guard inside the verified archive
```
