Install
Install Pipelock: Go, Docker, Homebrew, or Binary
One binary. Pick your path, then protect your first agent in two minutes.
- Apache-2.0 core; Enterprise features under ELv2
- Signed releases with checksums and provenance
- Fail-closed defaults on mediated paths
Current release: v3.5.0
install · go
Signed Linux, macOS, and Windows releases include checksums and provenance.
Download v3.5.0 → then
pipelock --version confirms the buildTwo minutes
Three commands from install to proof
Start with one agent, mediate one real path, then verify the decision record. Each command stands on its own; there is no hidden setup sequence between them.
Put it in front of Claude Code
Wires Claude Code through the proxy and starts the scanner. Claude Code guide →
Wrap any stdio MCP server
The local subprocess servers most agents actually use, scanned both directions. MCP proxy guide →
Verify a real receipt
Configure receipt signing to produce signed evidence. The public replay gallery gives you a signed packet to check now. Verify a receipt →