---
title: "Install"
description: "One binary, on Linux, macOS or Windows."
url: "https://saved.sh/docs/cli/install"
---

`sctl` is a single static binary. It has no runtime dependencies of its own, though a few
commands shell out to tools you probably already have.

## Quick install [#quick-install]

```bash
curl -fsSL https://saved.sh/cli.sh | sh
```

Works on Linux and macOS. It detects your platform, downloads the matching binary, verifies
its checksum, and installs to `/usr/local/bin`.

```powershell
# Windows PowerShell
irm https://saved.sh/cli.ps1 | iex
```

<Callout>
  Piping a script to a shell is a reasonable thing to be uncomfortable with. Both scripts are
  short and do nothing clever; read one first with `curl -fsSL https://saved.sh/cli.sh | less`,
  or use the manual route below.
</Callout>

## Manual install [#manual-install]

Releases are published on GitHub with a `SHA256SUMS` covering every asset.

| OS      | Architectures                            |
| ------- | ---------------------------------------- |
| Linux   | `amd64`, `arm64`                         |
| macOS   | `amd64` (Intel), `arm64` (Apple silicon) |
| Windows | `amd64`, `arm64`                         |

### Linux and macOS [#linux-and-macos]

```bash
VERSION=v1.0.0
OS=$(uname -s | tr '[:upper:]' '[:lower:]')     # linux or darwin
ARCH=$(uname -m | sed 's/x86_64/amd64/;s/aarch64/arm64/')

curl -fsSLO "https://github.com/savedhq/sctl/releases/download/${VERSION}/sctl-${OS}-${ARCH}"
curl -fsSLO "https://github.com/savedhq/sctl/releases/download/${VERSION}/SHA256SUMS"
```

Verify, then install:

```bash
# Linux
grep "sctl-${OS}-${ARCH}\$" SHA256SUMS | sha256sum -c -

# macOS
shasum -a 256 -c --ignore-missing SHA256SUMS
```

```bash
chmod +x "sctl-${OS}-${ARCH}"
sudo install -m 0755 "sctl-${OS}-${ARCH}" /usr/local/bin/sctl
```

<Callout type="warn">
  On macOS, a binary downloaded through a browser carries a quarantine attribute and Gatekeeper
  will refuse it. Downloading with `curl` avoids that; if you hit it anyway, clear it with
  `xattr -d com.apple.quarantine ./sctl`.
</Callout>

### Windows [#windows]

```powershell
$Version = 'v1.0.0'
Invoke-WebRequest "https://github.com/savedhq/sctl/releases/download/$Version/sctl-windows-amd64.exe" -OutFile sctl.exe
Invoke-WebRequest "https://github.com/savedhq/sctl/releases/download/$Version/SHA256SUMS" -OutFile SHA256SUMS

$expected = (Select-String -Path SHA256SUMS -Pattern 'sctl-windows-amd64.exe').Line.Split()[0]
$actual   = (Get-FileHash .\sctl.exe -Algorithm SHA256).Hash.ToLower()
if ($expected -ne $actual) { throw "checksum mismatch" }
```

Put it somewhere on `PATH`:

```powershell
New-Item -ItemType Directory -Force "$env:LOCALAPPDATA\Programs\saved" | Out-Null
Move-Item .\sctl.exe "$env:LOCALAPPDATA\Programs\saved\sctl.exe" -Force

$path = [Environment]::GetEnvironmentVariable('Path', 'User')
[Environment]::SetEnvironmentVariable('Path', "$path;$env:LOCALAPPDATA\Programs\saved", 'User')
```

Open a new terminal for the `PATH` change to take effect.

## Verify [#verify]

```bash
sctl --help
sctl login
```

## Optional tools [#optional-tools]

`sctl` works without these. Individual commands need them.

| Command                                 | Needs                  | Why                                         |
| --------------------------------------- | ---------------------- | ------------------------------------------- |
| `sctl restore` on an encrypted artifact | `gpg`                  | Decryption uses your own keyring            |
| `sctl restore` of a `postgres` backup   | `pg_restore` or `psql` | The dump is replayed by Postgres' own tools |

If a command needs one and cannot find it, it says which tool and stops, rather than failing
partway through a restore.

See [installing gpg](/docs/security/key-management#installing-gpg) for all three platforms.

## Upgrading [#upgrading]

Re-run the install script, or repeat the manual steps with a newer version. There is no state
to migrate: your session lives in the config file and is untouched.

```bash
curl -fsSL https://saved.sh/cli.sh | sh
sctl --help
```

## Uninstalling [#uninstalling]

Remove the binary and the config directory. The config holds your session token, so removing
it is the effective sign-out on a machine you are handing back.

```bash
sudo rm /usr/local/bin/sctl
rm -rf ~/.config/sctl                        # Linux
rm -rf ~/Library/Application\ Support/sctl   # macOS
```

```powershell
Remove-Item "$env:LOCALAPPDATA\Programs\saved\sctl.exe"
Remove-Item -Recurse "$env:AppData\sctl"
```

## Next [#next]

<Cards>
  <Card href="/docs/cli/login" title="Login" description="Signing in and choosing a workspace." />

  <Card href="/docs/quickstart" title="Quickstart" description="First backup, end to end." />
</Cards>
