# Neotask CLI and local runner Launch state: **Live**. Agents can register at /auth.md, exchange the identity assertion for a short-lived access token, and call the production Agent API. The standalone distribution includes the public CLI, managed Gateway service and its runtime. Use it when an agent needs to run work on this computer. Direct REST and remote MCP access remain available without a local installation; see [authentication](https://neotask.ai/docs/authentication.md) and [remote MCP](https://neotask.ai/docs/mcp.md). The [command reference](https://neotask.ai/docs/cli/commands.md) lists every command with its flags, input, scope and command ID. ## Install the published release Public installation is available only after the signed release and its matching website files are published. Check [release metadata](https://neotask.ai/cli/distribution.json) for a version, source revision and your exact platform/architecture. A missing document, an unsupported target or an HTML error page is not an installer. Do not invent a download URL or use an unrelated Gateway npm package. Once the release metadata is available, download the official installer and inspect it before running it. It contains the release's public trust root, signed policy and native-bootstrap digest. The native bootstrap verifies the complete signed CLI/Gateway package before installation. macOS and Linux: ```sh curl --fail --show-error --location --proto '=https' --proto-redir '=https' https://neotask.ai/cli/install.sh -o neotask-install.sh # Inspect neotask-install.sh, then: bash neotask-install.sh ``` Windows PowerShell: ```powershell Invoke-WebRequest -Uri https://neotask.ai/cli/install.ps1 -OutFile neotask-install.ps1 # Inspect neotask-install.ps1, then: & .\neotask-install.ps1 ``` The website installers do not require Node or npm. They add the user bin directory to PATH unless you pass `--no-modify-path` (shell) or `-NoModifyPath` (PowerShell). Open a new terminal afterward. The stable command is `~/.neotask/bin/neotask` on macOS/Linux or `%LOCALAPPDATA%\Neotask\bin\neotask.exe` on Windows. The optional `@neotask/cli` npm package, when published for that release, uses the same native installer and persistent installation; the command it installs is still `neotask`. It requires Node 22 or newer to run the npm entry. `npx @neotask/cli install` installs its pinned release; `npx @neotask/cli --version` installs on first use or forwards to an existing installation. It does not start a second Gateway in npm's cache. Removing the npm package does not uninstall the service or erase account data. ### First run `npm install -g @neotask/cli` finishes instantly by design: the package has no install scripts. The first `neotask` command, including `neotask --version`, then downloads the complete signed CLI (about 160 to 210 MB depending on the platform), verifies its signatures and every file digest, and unpacks it before running. It reports each step on stderr: `Installing Neotask for ()…`, download progress, `Verifying signature…`, unpacking progress and `Installed in s.`. Outside a terminal these are plain lines, and stdout carries only the command's own output. The install takes about 15 seconds on Apple Silicon (about 45 seconds on a small Linux x64 server) plus the download. Wait for it: do not kill it, time it out early or start a second `neotask` while it runs. `NEOTASK_QUIET=1` hides the progress lines. The website installers show the same download, verification and unpacking progress. If the npm entry finds an installation older than its pinned release, it updates it before running the command. It never runs an installation that is not signed by the published release keys, such as a local test build: it renames that installation to `.untrusted-