← Blog

How to Install Claude Code, and What to Configure Before Using It on Client Code

Marco Masut

Installing Claude Code means putting its command-line program, claude, on your computer and signing it in with an Anthropic account. According to the official documentation, consulted on 7 October 2026, the recommended method is the native installer: on macOS, Linux and WSL run curl -fsSL https://claude.ai/install.sh | bash, on Windows PowerShell run irm https://claude.ai/install.ps1 | iex. Open a new terminal, run claude --version to check, then claude from the project folder to log in. You need a Pro, Max, Team, Enterprise or Console account, at least 4 GB of RAM and a supported operating system, such as macOS 13, Ubuntu 20.04 or Windows 10. The installation, though, decides nothing that matters on someone else's code: permissions, files not to read, and where session transcripts end up. Those are the last sections of this guide, current as of 7 October 2026.

How do you install Claude Code, step by step?

The recommended method is the native installer, which updates itself in the background. On macOS, Linux and WSL, open a terminal and run:

curl -fsSL https://claude.ai/install.sh | bash

On Windows, from PowerShell:

irm https://claude.ai/install.ps1 | iex

When it finishes, open a new terminal and check with claude --version: if it prints a version number, it worked. If the shell says claude isn't found, the install folder isn't on your PATH yet. For a fuller check there is claude doctor, which prints installation and settings diagnostics without starting a session.

There are alternatives, useful when a company wants to control distribution:

MethodCommandUpdates
Native installer (recommended)curl or PowerShell, as aboveAutomatic, in the background
Homebrewbrew install --cask claude-codeManual: brew upgrade claude-code
WinGetwinget install Anthropic.ClaudeCodeManual: winget upgrade Anthropic.ClaudeCode
npmnpm install -g @anthropic-ai/claude-codeManual, with Node.js 22 or later
apt, dnf, apkRepositories signed by AnthropicThrough the normal system upgrade

Don't use sudo with npm: the documentation advises against it because of the permission and security problems it creates.

What do you need before installing?

According to Anthropic's documentation (consulted on 7 October 2026): macOS 13.0 or later, Windows 10 version 1809 or later, Ubuntu 20.04+, Debian 10+ or Alpine 3.19+, at least 4 GB of RAM, an x64 or ARM64 processor and an internet connection. The shell can be Bash, Zsh, PowerShell or CMD. On native Windows, Git for Windows is optional but recommended; WSL 2 supports sandboxing, which native Windows does not. You also need a Pro, Max, Team, Enterprise or Console account: the free claude.ai plan does not include Claude Code.

What is the first run and the minimum setup?

From the project folder you launch claude and follow the browser login. If the ANTHROPIC_API_KEY variable is set, Claude Code asks once whether to use that key. Beyond that, the minimum setup is:

  • claude doctor once, to see right away whether the install and the settings files are healthy;
  • the update channel: latest (the default) gets new releases immediately, stable runs about a week behind and skips releases with major regressions, set with autoUpdatesChannel in settings.json;
  • a CLAUDE.md file at the project root with the standing instructions, written once and versioned, instead of repeated on every request.

For how Claude Code sits next to other tools, the comparison is in Claude Code vs Cursor.

What should you configure before working on code that isn't yours?

This is where the installation ends and the real work begins. When you point it at a client's repository, three decisions belong before the first session, not after:

  1. Who is allowed to use it on that code, and with which account (company or personal).
  2. What it can read and write, expressed as permission rules in the settings.
  3. Which commands or events must leave a trace or be blocked, through hooks.

Settings live in JSON files with a precise precedence. Strongest to weakest: organization-managed settings, command line, .claude/settings.local.json (yours alone, for that project), .claude/settings.json (shared with the team in the repository), ~/.claude/settings.json (yours, for every project). For a team working on contract, the practical rule is to put shared limits in the versioned project file, so anyone opening the repository starts from the same constraints.

What must it not be able to touch?

deny rules go under permissions in the settings file. The documentation's own example blocks reading environment files:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(./.env.*)"
    ]
  }
}

deny and ask rules apply immediately; allow rules shared in the repository only count once each teammate has trusted the folder. A minimal list of what to exclude before working on a client's code:

What to protectHowWhy
Files with secrets (.env, keys, credentials)deny rules on Read(...)Whatever passes through a tool is written in plain text to the transcript
Folders outside the contract's scopedeny rules or separate working foldersThe authorized scope is set by the contract, not by the agent
Commands with external effects (deploy, push, network)ask or deny rules, plus hooksThey change something outside the session
Organization settingsManaged settingsNo developer setting overrides them

Rules say what the agent may do. To trigger a check or a block on a specific event, before or after a command, you need hooks: they are explained in Claude Code hooks.

Where do the logs go, and why do you need to know?

Claude Code writes the data it produces while working to ~/.claude/. According to the documentation (consulted on 7 October 2026), the full transcript of each session, with messages, tool calls and results, lives in projects/<project>/<session>.jsonl, and the files are plain text: everything that passes through a tool, file contents, command output, pasted text, is written to disk. Files older than cleanupPeriodDays are deleted, with a default of 30 days and a minimum of 1.

For anyone working on contract this has two opposite consequences. The first is confidentiality: pieces of the client's code sit in plain text on your laptop, and under the 30-day rule the trace of what was done disappears too. The second is evidence: the local transcript is a memory of the session, not deliverable proof, because it lives on the machine of whoever did the work, expires on its own and is not tied to a request, an authorized scope or the outcome of a check.

That is the subject of what Claude Code leaves when the session ends. This is where Detent, the end-to-end delivery system (detent-ai.com), comes in: request, scope, system-run verification and human signature stay in the project repository, not in the personal folder of whoever did the work. A demonstration on real tasks is on the /bench page. If you work for regulated clients, the next step is NIS2 and the AI Act, both written about the European rules.