Pragma Download & Install
Pragma is the native desktop IDE for CredVault. Users install it on their own computer, sign in with a CredVault account, and then use the local terminal, editor, AI agent, Drive, secrets, and remote development tools from one app.
The download page is available at:
/download
The download page is public. Users do not need a CLI command just to reach it.
The product page is available at:
/pragma
Supported Operating Systems
Pragma is prepared for the three major desktop operating systems:
| OS | Typical installer | Who should use it |
|---|---|---|
| macOS | .dmg | MacBook, iMac, Mac mini, Apple Silicon, or Intel Mac users |
| Windows | .exe | Windows 10 and Windows 11 users |
| Linux | .AppImage now, package formats later | Ubuntu, Debian, Fedora, RHEL, Arch, and other Linux users |
macOS Install
Apple does not treat a downloaded .dmg like a Windows installer. The disk image is only a temporary volume. The real install is: copy Pragma.app into /Applications, eject the image, then open it from Applications.
- Download
pragma-latest.dmgfrom CredVault, not a random Drive link if you can avoid it. - Double-click the
.dmg. Finder opens a window named Pragma. - Drag Pragma onto Applications. Do not double-click the app inside the disk image.
- Eject the disk image (eject icon in Finder, or right-click the Pragma volume).
- Open Pragma from
/Applications. - Sign in with the user's CredVault account.
How macOS decides whether the app can run
Every file Chrome, Safari, or Drive saves from the internet gets a quarantine flag (com.apple.quarantine). The first time the user opens the app, Gatekeeper (Apple’s OS security, not CredVault) checks:
- Developer ID signature — signed by an Apple Developer Program Developer ID Application certificate.
- Notarization — Apple scanned the build with
notarytooland a ticket was stapled onto the DMG. - The app was not modified after signing.
If those pass, macOS shows a one-time prompt: this app was downloaded from the internet, Open. After that it runs normally and shows the real app icon.
If they fail, current macOS (Sequoia / Tahoe) shows "Pragma is damaged and can't be opened. You should eject the disk image." That is Gatekeeper’s block for an unsigned or un-notarized download. The file is not actually damaged. The generic document icon in that Finder window is the same block: macOS will not treat the bundle as a trusted app.
Our GitHub macOS job currently builds with --nosign, so public DMGs will keep hitting this until we sign and notarize with a CredVault Apple team (not Warp’s leftover 2BBY89MBSN certs).
If a tester already sees the damaged dialog
They should Cancel, eject the DMG if Finder will let them, and install correctly:
- Drag Pragma to Applications if it is not there yet.
- Eject
pragma-latest.dmg. - Open System Settings → Privacy & Security, scroll to Security, and use Open Anyway after the blocked launch.
- Only if that is missing, a tester can clear quarantine on the copy in Applications:
xattr -dr com.apple.quarantine /Applications/Pragma.app
Do not tell customers to disable Gatekeeper or SIP. That is not how Mac software is supposed to ship.
Windows Install
The Windows build is distributed as an installer.
- Download the
.exe. - Run the installer.
- Follow the install steps.
- Open Pragma from the Start Menu or desktop shortcut.
- Sign in with the user's CredVault account.
Windows users may see a security prompt if the installer is not signed. For production distribution, the installer should be code-signed so SmartScreen can build trust for the app.
No command-line step is required for Windows installation.
Linux Install
Linux users should use the public AppImage release we publish today.
Universal Linux AppImage
chmod +x Pragma-*.AppImage
./Pragma-*.AppImage
The AppImage is useful when the user does not want a system install or when their distribution does not match a package-manager install.
If we publish .deb or .rpm later, those will be linked from the same public download page.
Running Without System Installation (Portable Mode)
If users cannot or prefer not to run system installers (for example, if they lack Administrator permissions), they can still execute Pragma directly while preserving the application icon.
Windows (Portable Extraction)
- Extract Files: The Windows
.exeinstaller is built with Inno Setup and can be unpacked without execution. Right-clickPragmaSetup.exe, select 7-Zip (or a similar archive utility), and extract the package. - Execute directly: Open the extracted directory and run the main
pragma.exebinary. - Application Icon: The icon is embedded directly inside the
pragma.exeexecutable's resource header. Windows Explorer automatically displays it, and users can create a desktop icon by right-clickingpragma.exeand choosing Send to -> Desktop (create shortcut).
macOS (install, then run)
- Mount DMG: Double-click the downloaded
.dmg. - Install: Drag
Pragma.appinto/Applications. Do not run it from the disk image window. - Eject the Pragma volume, then open Pragma from Applications.
- Application Icon: After a trusted launch, Finder and the Dock use the icon inside
Pragma.app/Contents/Resources. A generic document icon usually means Gatekeeper blocked the unsigned bundle.
Linux (AppImage Natively Portable)
- Make Executable: AppImages run without setup. Grant execution rights:
Terminal chmod +x Pragma-*.AppImage - Execute directly: Run
./Pragma-*.AppImage. - Application Icon: The icon is integrated into the binary. To register a desktop shortcut icon manually, create a launcher file at
~/.local/share/applications/pragma.desktoppointing to the AppImage executable and its internal icon resources.
First Launch
On first launch, Pragma should guide the user through:
- Sign in or account connection.
- Default AI model choice.
- Agent autonomy level.
- Terminal and editor layout.
- Optional Drive, secrets, and remote server setup.
After this, the user lands inside the IDE with terminal, editor, AI tools, and account-connected features available.
What The Download Must Include
Each release should include:
- macOS installer.
- Windows installer.
- Linux AppImage.
- Version number.
- Release notes.
- Checksums.
Checksums help users and admins verify that downloaded files were not changed after release.