signed builds
Install
Each installer detects your OS and architecture, verifies the download end-to-end (minisign signature → SHA-256 → unzip), then runs the inner installer. There is no dispatcher — the binaries are invoked directly.
clawee — the terminal client
curl -fsSL --proto '=https' --tlsv1.2 https://release.clawee.org/clawee/install.sh | sh
clawee lands in $HOME/.local/bin and ensures
burrowee-cli is present.
claweed — the PTY daemon
curl -fsSL --proto '=https' --tlsv1.2 https://release.clawee.org/claweed/install.sh | sh
Run it as your user, never with sudo. claweed escalates with
sudo for four steps of its own: the root-owned daemon binaries, the root-owned
spawn policy files, the system boot unit, and — on macOS only — a sudoers
drop-in at /etc/sudoers.d/clawee-powermetrics granting the user who runs the
installer passwordless sudo for one fixed read-only command,
powermetrics --samplers thermal -n 1. That is a standing NOPASSWD rule; delete
the file to revoke it, and claweed simply reports thermal=unknown. Running the
whole installer under sudo instead installs the daemon against root's home rather than
yours. Without any sudo path the installer stops at the first step and installs nothing. It
cross-installs burrowee-gateway, and installs no setuid binary.
Every version this channel has ever served, with its per-platform downloads and checksums, is on the downloads page.