Download
Get the Hawkeye desktop app
No sign-in required to download. We picked the installer below based on your browser — every platform is always listed further down in case that guess was wrong.
Windows — Setup .exe
207 MB
- Signed (Azure Trusted Signing). Windows may still show a brief SmartScreen notice until the publisher builds download reputation — if so, choose More info → Run anyway.
Linux — .deb (Debian/Ubuntu)
208 MB — detected for your system
- Unsigned — Linux has no equivalent gate. Install with your package manager or dpkg -i.
Linux — AppImage (any distro)
255 MB
- Unsigned — Linux has no equivalent gate. chmod +x it, then run it.
macOS — Apple Silicon .dmg
253 MB
- Signed and notarized (Developer ID). The DMG itself is also notarized and stapled, not only the app inside it, so it opens cleanly even offline. Opens with a plain double-click, no right-click workaround needed. Then also install the permission-service .pkg below to make Screen Recording/Accessibility Request buttons work.
- Required 2nd step, same Mac: also install the permission-service .pkg (336 MB) — Signed, notarized .pkg (Developer ID). This does NOT install the Hawkeye app itself — install the .dmg above first. It installs the signed native permission service that Screen Recording/Accessibility grants are attributed to, so the in-app Request buttons actually work.
macOS — Intel .dmg
257 MB
- Signed and notarized (Developer ID). The DMG itself is also notarized and stapled, not only the app inside it, so it opens cleanly even offline. Opens with a plain double-click, no right-click workaround needed. No Intel permission-service installer exists yet — see release.ts.
Verify what you downloaded: SHA256SUMS.txt.
TODO — not filled in yet
These are deliberately blank rather than invented. Nothing below is a placeholder standing in for a real answer; where a fact is missing, it is missing.
- The Windows and macOS builds above are code-signed. Windows is signed
with a real Azure Trusted Signing certificate (chain to a public Microsoft
CA, RFC3161 timestamped) — a fresh publisher can still see a brief
SmartScreen notice while download reputation builds; if so, choose
More info → Run anyway, and you can verify the signature yourself
with
signtool verify /pa /v. macOS is signed with a real Developer ID Application certificate, notarized by Apple, and the .dmg itself is separately signed, notarized and stapled — not only the app inside it — so a plain double-click works with no right-click detour. Verified live, 2026-08-22:bin/verify-signing.shreports SIGNED on both platforms, and its--expect-unsignedcontrol correctly refuses to pass against either. The Linux .deb and AppImage remain unsigned — Linux has no equivalent publisher-signature mechanism to opt into, so this is not a gap, it is the whole story there.
After installing: sign in once and the app pairs with your account automatically — no key to copy, no terminal to keep open. Then connect your AI client to point it at your newly enrolled machine.
Phone or tablet: native iOS and Android apps are in active development (not yet published for general download). Until then, sign in to this site from your phone's browser — your machines, your agent and your approvals all work there too.