Skip to navigation

Installation

The CLI is distributed as standalone binaries attached to each GitHub release and as an npm package. Both distributions install the same deel command. Use the installer on macOS and Linux; use npm on Windows or where Node.js is already part of the toolchain.

Prerequisites

Node.js 22.18 or later, for the npm method, the default Windows method, and installing from source. The macOS/Linux installer and the direct Windows binary download need no runtime at all; the resulting deel binary runs on its own.

Install

Recommended on macOS and Linux. Downloads the standalone binary for your platform. The binary runs on its own, with no separate runtime such as Node.js required.

curl -fsSL https://cli.deel.com/install.sh | sh

The installer detects the operating system, CPU architecture, and C library (glibc or musl), downloads the matching binary, verifies its SHA-256 checksum against the release’s SHA256SUMS, and places it in /usr/local/bin or, when that directory is not writable, in ~/.local/bin.

To install a specific version, use its versioned URL:

curl -fsSL https://cli.deel.com/v0.1.1/install.sh | sh
VariableEffect
DEEL_INSTALL_DIRInstall location (default /usr/local/bin, then ~/.local/bin)
DEEL_VERSIONRelease tag to install (default latest)
DEEL_REQUIRE_COSIGNSet to 1 to abort when cosign is not installed instead of skipping signature verification

Installing for an AI agent

Install the CLI on the machine or in the container where the agent executes commands, not only on your own. The installer downloads a binary with no runtime dependency, so the same command works on a developer machine, in a container, and in a hosted agent sandbox; use npm where Node.js is already present. See Set up a coding agent.

Verify the installation

deel --version

The command prints deel <version> and exits with status 0. Run deel --help to list the available command groups and global options.

Verify a downloaded binary

Every release ships SHA256SUMS, a Sigstore bundle SHA256SUMS.sigstore, and the release public key cosign.pub. The installer checks the checksum automatically and verifies the signature when cosign is installed. To verify a binary you downloaded manually:

1

Install cosign

brew install cosign
2

Download the release artifacts

Replace the version with the release you downloaded.

VERSION=v0.1.1
BASE=https://github.com/letsdeel/deel-cli/releases/download/$VERSION
curl -sLO $BASE/SHA256SUMS
curl -sLO $BASE/SHA256SUMS.sigstore
curl -sLO $BASE/cosign.pub
3

Verify the checksum file signature

cosign verify-blob \
--key cosign.pub \
--bundle SHA256SUMS.sigstore \
--insecure-ignore-tlog \
SHA256SUMS

Expected output: Verified OK.

--insecure-ignore-tlog is required because the release pipeline does not upload to the Sigstore public transparency log. The integrity guarantee comes from cosign.pub, not from the log.

4

Verify the binary checksum

Run this in the directory that contains the downloaded binary.

sha256sum --check SHA256SUMS --ignore-missing

Expected output: deel-<platform>: OK.

Upgrade

Upgrade using the same method you installed with:

Installation methodUpgrade command
InstallerRe-run the installer command; it replaces the binary in place
npmnpm install -g @deel-org/cli@latest
Windows binaryDownload the new deel-windows-x64.exe and replace the existing file

Uninstall

Remove the CLI with the command for your install method:

Installation methodCommand
Installerrm "$(command -v deel)"
npmnpm uninstall -g @deel-org/cli

Removing the CLI does not remove tokens stored in the OS keychain. Run deel auth logout for each environment before uninstalling, or remove the deel entries from your keychain manually. Local logs remain in the log directory.

Next steps