Install Hugin
Run Hugin as a desktop app or headless from the command line. Both ship the same single binary.
Hugin is one hugin binary. With no arguments it launches the desktop GUI; with
a subcommand it runs on the command line. On first launch it generates its CA and
starts the Proxy on 127.0.0.1:8080.
Download
The quickest path on any platform:
curl -fsSL https://hugin.nu/install | sh
This detects your OS and architecture, downloads the latest release binary, and
moves it to /usr/local/bin/hugin (or ~/.local/bin on Linux).
Prefer a download link? See hugin.nu/download.
Desktop app
A macOS .dmg (Apple Silicon) is on the releases page.
Open the .dmg, drag Hugin to Applications, and launch it.
Package managers
# macOS (Homebrew)
brew install HuginCyber/tap/hugin
# Arch Linux (AUR — precompiled binary)
yay -S hugin-bin
# Cargo (build from source)
cargo binstall hugin
# Nix (flake)
nix build github:HuginCyber/Hugin
The AUR package installs hugin to /usr/bin/hugin. On Linux the desktop GUI
needs webkit2gtk-4.1 and gtk3.
First run
The quickest way to get set up is the wizard:
hugin setup
It walks you through six steps: the Proxy and API ports, generating the CA
certificate and trusting it in your system keychain (so HTTPS decrypts), an
optional licence key for Pro, and downloading the community scanner modules plus
registering Hugin as an MCP server for opencode. Use
hugin setup --headless on a box with no interactive prompts.
Prefer to do it by hand? Each step has its own page: trust the CA certificate, configuration, and your account.
Headless
hugin start runs the Proxy and the control API with no GUI, on localhost:
hugin start --port 8080 --api-port 8081 --bind 127.0.0.1
--port is the Proxy (default 8080), --api-port is the REST/control API
(default 8081), --bind is the listen address (default 127.0.0.1). Add --mcp
to also start the MCP server.
To run Hugin as a shared, remotely reachable instance (for a team), use
hugin serve — it binds 0.0.0.0 and requires a token; --no-auth turns auth
off for a trusted network.
An intercepting proxy decrypts TLS and holds a CA key. Only run it on hosts and networks you are authorised to test, and keep the control API off the open internet.
Check it
hugin status
hugin doctor
hugin doctor runs local health and tamper checks (database file permissions,
running-binary integrity, DNS consistency, suspicious system services, unexpected
VPN tunnels). When it is happy, go to the
quickstart.