docs

Install Hugin

Run Hugin as a desktop app or headless from the command line. Both ship the same single binary.

Hugin is one hugin binary. With no arguments it launches the desktop GUI; with a subcommand it runs on the command line. On first launch it generates its CA and starts the Proxy on 127.0.0.1:8080.

Download

The quickest path on any platform:

curl -fsSL https://hugin.nu/install | sh

This detects your OS and architecture, downloads the latest release binary, and moves it to /usr/local/bin/hugin (or ~/.local/bin on Linux).

Prefer a download link? See hugin.nu/download.

Desktop app

A macOS .dmg (Apple Silicon) is on the releases page. Open the .dmg, drag Hugin to Applications, and launch it.

Package managers

# macOS (Homebrew)
brew install HuginCyber/tap/hugin

# Arch Linux (AUR — precompiled binary)
yay -S hugin-bin

# Cargo (build from source)
cargo binstall hugin

# Nix (flake)
nix build github:HuginCyber/Hugin

The AUR package installs hugin to /usr/bin/hugin. On Linux the desktop GUI needs webkit2gtk-4.1 and gtk3.

First run

The quickest way to get set up is the wizard:

hugin setup

It walks you through six steps: the Proxy and API ports, generating the CA certificate and trusting it in your system keychain (so HTTPS decrypts), an optional licence key for Pro, and downloading the community scanner modules plus registering Hugin as an MCP server for opencode. Use hugin setup --headless on a box with no interactive prompts.

Prefer to do it by hand? Each step has its own page: trust the CA certificate, configuration, and your account.

Headless

hugin start runs the Proxy and the control API with no GUI, on localhost:

hugin start --port 8080 --api-port 8081 --bind 127.0.0.1

--port is the Proxy (default 8080), --api-port is the REST/control API (default 8081), --bind is the listen address (default 127.0.0.1). Add --mcp to also start the MCP server.

To run Hugin as a shared, remotely reachable instance (for a team), use hugin serve — it binds 0.0.0.0 and requires a token; --no-auth turns auth off for a trusted network.

An intercepting proxy decrypts TLS and holds a CA key. Only run it on hosts and networks you are authorised to test, and keep the control API off the open internet.

Check it

hugin status
hugin doctor

hugin doctor runs local health and tamper checks (database file permissions, running-binary integrity, DNS consistency, suspicious system services, unexpected VPN tunnels). When it is happy, go to the quickstart.

Last updated 2026-07-10.