# Install and connect Kam AI developer tools

Set up the approved CLI candidate, add the repository-local SDK to an authorized backend, and connect the read-only MCP server to a compatible coding agent.

Status: Merged · local only. Prelaunch; not a live service guarantee.
Native toolkit 0.1.0 is merged into the backend (PR #176) and qualified in CI as a network-disabled Linux x64 artifact. No public binary release, macOS/Windows distribution, or live AWS connection is offered here. SDK 0.36.0 is source-implemented but not published to npm; an authorized service endpoint and tenant binding are separate prerequisites.

Reviewed: 2026-10-07.
Backend source: 1db8cf00a065e14311ce7eb518596759831892ec.
Native toolkit: merged in PR #176, reviewed at 1db8cf00a065e14311ce7eb518596759831892ec.
HTML: /docs/install

## In short

Set up the merged local CLI, add the unpublished SDK package to an authorized backend, and connect the CLI’s read-only MCP server to a compatible coding agent.

**Available today:** The CLI and MCP are merged and qualified for Linux x64. SDK 0.36.0 is implemented in source but not published to npm. Nothing is deployed.

> Use one reviewed contract across local CLI workflows, scoped service integration, and read-only coding-agent tools.

## Before you install

You need a Linux x64 development environment, an existing application directory, and the separately supplied Kam 0.1.0 artifact from the qualified backend CI run. Record its version, checksum, and provenance before use.

SDK use additionally requires an authorized backend source checkout, the exact approved SDK 0.36.0 package, a Kam service endpoint, and a server-authorized tenant binding. The CLI and MCP do not require AWS credentials or connect your account to the managed service.

There is no public CLI registry package, public SDK npm package, Homebrew formula, macOS build, or Windows distribution. Do not substitute similarly named packages from a public registry.

[Request candidate access](/support)

## Step 1: place the CLI on your PATH

Use the filename and checksum supplied with the approved artifact. The example keeps the binary in a user-owned directory; adapt the path to your organization’s software policy.

### Install and verify the approved candidate

```bash
mkdir -p "$HOME/.local/bin"
install -m 0755 ./kam "$HOME/.local/bin/kam"
export PATH="$HOME/.local/bin:$PATH"

kam --version
kam capabilities --json
```

> **Verify before use**
> Do not substitute an artifact from an unreviewed source. A successful version command establishes local execution only—not service access, deployed IAM, or production qualification.

## Step 2: initialize one project

Run from the application directory you want Kam to inspect. The first command prints the proposed changes. Nothing is written until you repeat it with --write.

### Plan, write, and check local setup

```bash
cd /path/to/your-application
kam init --template deployment-agent
kam init --template deployment-agent --write
kam doctor --json
kam generate --check
```

> **Local diagnostic boundary**
> kam doctor checks local configuration, declarations, and generated-file drift. It is separate from the authenticated kam-history doctor command and does not prove cloud permissions.

## Step 3: add the SDK to an authorized backend

Use the exact approved SDK source supplied for your evaluation and preserve its version with the backend that calls it. The current import is repository-local; there is no supported npm install command.

Configure endpoint, tenant, and access-token inputs through your backend’s existing secret and deployment controls. Never embed credentials in browser code, generated agent guidance, MCP configuration, or this static website.

### Create a scoped client and preserve exact references

```javascript
// Save as a .mjs file in an authorized backend source checkout. SDK candidate 0.36.0.
// This is a read-only example, not code executed by the website.
import { createKamClient } from './server/trajectory/sdk/index.mjs';
const kam = createKamClient({
  baseUrl: process.env.KAM_API_URL,
  tenantId: process.env.KAM_TENANT_ID,
  accessToken: () => process.env.KAM_ACCESS_TOKEN,
});
const deployments = kam.scope({ subjectId: 'checkout', type: 'deployment' });
const page = await deployments.allIds({ day: '2026-10-06', limit: 16 });
if (page.status === 'ready' && page.items.length > 0) {
  const exact = await deployments.byIds({
    day: page.day,
    generation: page.generation,
    refs: page.items,
  });
  console.log(exact.records); // Keep every position and result status.
}
// A short page is not the end when nextCursor is present.
// Continue with the SAME generation and returned cursor.
```

> **Service access is separate**
> Possessing the SDK does not authorize a tenant or AWS account. Validate the approved endpoint, principal, server-side tenant binding, lifecycle status, and supported scope before sending outcomes.

[Read the full SDK integration guide](/docs/integrate)

## Step 4: connect the read-only MCP server

Add the server to a coding agent that supports local stdio MCP processes. Client configuration locations differ, but the server command and arguments follow this shape. Use the absolute path returned by command -v kam.

The client starts kam mcp and communicates over stdio. Do not wrap it in a TCP listener or add shell, credential, arbitrary-path, or write capabilities.

### Generic MCP client configuration

```json
{
  "mcpServers": {
    "kam": {
      "command": "/home/you/.local/bin/kam",
      "args": ["mcp"]
    }
  }
}
```

## Step 5: verify the connection

1. **Restart or reload the MCP client** — The client should start the local stdio process itself; a separate hosted Kam endpoint is not involved.

2. **List the Kam tools** — Confirm the client exposes only the documented read-only tools, including project status, View manifest, fixture replay, reference Atlas, and bundled docs.

3. **Read project status** — Call kam_project_status in the application directory and review configuration or drift findings. This is a local filesystem assessment, not an AWS account check.

4. **Keep effects explicit** — Use the CLI with --write for reviewed generation changes. MCP remains read-only and cannot install packages, edit files, run a shell, or deploy infrastructure.

[Understand every MCP tool](/docs/agent-tooling)

[Continue with the CLI workflow](/docs/toolkit)

## Update or remove the candidate

There is no public self-update channel for the local CLI artifact. Replace it only with a separately supplied artifact from an approved qualification run, verify the new version and checksum, then rerun kam doctor and kam generate --check.

Update the SDK only from an approved source revision and review its API and service compatibility before changing the pinned package in your backend. Do not replace the repository-local package with an unverified registry package.

To disconnect MCP, remove the kam server entry from your client and reload it. Remove the local binary or SDK package only after confirming no project, backend, or client configuration still references it.
