CLI documentation
HackerBlue CLI.
The terminal way to install the Hacker Blue theme you own: authorise a computer, install it into your app, and update it under the same licence.
What the CLI is
The HackerBlue CLI is the terminal way to install a Hacker Blue theme once you have purchased it. Buying on Hacker Blue gives your account a licence; the CLI signs this computer in, resolves the release your licence covers, verifies what it downloads, and writes the theme into the app you choose.
It has seven commands — list, login, logout, status, install, update and self-update — plus --help and --version. 31 themes are installable today — the list is on the homepage.
Installation
One file, checked before it runs.
The CLI is one compiled program — there is nothing to install first and no source to fetch. It runs on Linux (x86-64 and ARM64, on any distribution), macOS (Intel and Apple silicon) and Windows (x86-64 and ARM64). Run the installer for your system; it downloads the right program, checks it against the published SHA-256 list, and puts it where you can run it — no administrator rights.
Linux and macOS
curl -fsSL https://hackerblue.dev/install.sh | sh
The program is installed as ~/.local/bin/hackerblue; if that folder is not on your PATH the installer prints the one line to add. Set HACKERBLUE_INSTALL_DIR to install somewhere else.
Windows (PowerShell)
irm https://hackerblue.dev/install.ps1 | iex
The program is installed as %LOCALAPPDATA%\Programs\hackerblue\hackerblue.exe and that folder is added to your user PATH; open a new terminal to use it.
hackerblue@dev:~$ hackerblue --version
hackerblue 0.4.2build linux/amd64, commit 539c9b2c6742, built 2026-10-03
--version prints the version and the build — the platform, the commit and the date it was built from.
Direct downloads
Prefer to fetch it yourself? Each file is the whole program, and SHA256SUMS lists the SHA-256 of every one: compare with sha256sum (Linux), shasum -a 256 (macOS) or Get-FileHash (Windows), then make the file executable and put it on your PATH.
| Linux, x86-64 | hackerblue-linux-amd64 |
|---|---|
| Linux, ARM64 | hackerblue-linux-arm64 |
| macOS, Intel | hackerblue-darwin-amd64 |
| macOS, Apple silicon | hackerblue-darwin-arm64 |
| Windows, x86-64 | hackerblue-windows-amd64.exe |
| Windows, ARM64 | hackerblue-windows-arm64.exe |
Updating the program
hackerblue self-update fetches the newest program and replaces itself. It refuses unless the checksum list carries a valid signature from the Hacker Blue release key and the download matches its checksum; a failure leaves the running program as it was.
The first time you run it
The programs are not yet signed with an Apple or Microsoft developer certificate, so your operating system may warn the first time. The installers above avoid the warning on macOS and Windows; if you download a file in a browser instead, this is what to expect:
- macOS may say the program “cannot be opened because the developer cannot be verified”. Open System Settings → Privacy & Security and choose Open Anyway, or run
xattr -d com.apple.quarantine ./hackerblue-darwin-arm64once. - Windows SmartScreen may show “Windows protected your PC”. Choose More info → Run anyway.
A compiled program can still be inspected, so the protection that matters is on the server: nothing downloads without a licence, and the checksum list is what makes sure the file you run is the file that was published.
Quick start
The shortest working path from sign-in to an installed theme.
From nothing to a working theme in three commands and one click in the browser.
hackerblue@dev:~$ hackerblue login
Authorise this computer with Hacker Blue. 1. Open https://hackerblue.dev/activate?code=K7QW2M9X 2. Sign in if asked, then approve this device. Activation code: K7QW2M9X Opened https://hackerblue.dev/activate?code=K7QW2M9X in your browser.The code is only good for 10 minutes.
Approve the device on that page while signed in — the CLI finishes on its own. Then install:
hackerblue@dev:~$ hackerblue install obsidian
Hacker Blue for Obsidian 1.0.1 installed. Location /home/you/vaults/notes/.obsidian/themes/Hacker BlueChecksum verified (sha256) Open Obsidian → Settings → Appearance → Themes and select "Hacker Blue".Updates for this theme are included with your licence — no new purchase is needed.
hackerblue login— authorises this computer through your browser; you approve the device while signed in.hackerblue install obsidian— finds your vault, downloads the licensed release, verifies its checksum and installs it.- In Obsidian, open Settings → Appearance → Themes and select Hacker Blue.
Authentication
The CLI stores no password. hackerblue login authorises this computer: it asks Hacker Blue for a short activation code and opens hackerblue.dev/activate, where you approve the device while signed in to your Hacker Blue account. The page shows the requesting computer's name, system and CLI version, and takes an explicit approve or deny. The code is good for ten minutes; a headless or SSH session with no browser simply prints the URL and code to open anywhere.
Approval exchanges a device token for this computer, stored locally in credentials.json. Downloads, the status commands and updates present that token; the server stores only its hash. A licence covers up to three active devices — a fourth is refused with a pointer to your account page, where deactivating a device frees the slot. Signing a known device in again replaces its token instead of taking a new one.
hackerblue logout revokes the token server-side first, then removes the local credentials. Installed theme files are untouched and keep working.
Commands
Every public command, with the CLI's own one-line help.
hackerblue list
“show which themes are ready and which are coming soon” — printed the way the CLI prints it at a terminal. Piped into another program it prints one tab-separated row per app: slug, name, then available or coming-soon.
hackerblue@dev:~$ hackerblue list
HackerBlue themes Ready to install (31) ✓ Claude Code claude-code ✓ Gemini CLI gemini-cli ✓ OpenCode opencode ✓ Codex CLI codex-cli ✓ VS Code vs-code ✓ Cursor cursor ✓ Zed zed ✓ JetBrains jetbrains ✓ Neovim neovim ✓ Sublime Text sublime-text ✓ kitty kitty ✓ Ghostty ghostty ✓ WezTerm wezterm ✓ Alacritty alacritty ✓ Warp warp ✓ Konsole konsole ✓ foot foot ✓ Windows Terminal windows-terminal ✓ tmux tmux ✓ btop btop ✓ lazygit lazygit ✓ Yazi yazi ✓ Starship starship ✓ Obsidian obsidian ✓ Chrome chrome ✓ Chromium chromium ✓ Firefox firefox ✓ Brave brave-browser ✓ Omarchy omarchy ✓ Hyprland hyprland ✓ KDE Plasma kde-plasma Coming soon (0) Install one with: hackerblue install <name>
hackerblue login
“authorise this computer with Hacker Blue” — the browser-assisted device authorisation described under Authentication above. No arguments.
hackerblue logout
“revoke this computer's authorisation” — revokes the device token server-side and removes the local credentials. Installed themes keep working, and the device slot frees immediately. No arguments.
hackerblue status [app]
“show this computer's Hacker Blue state” — the account snapshot without an app, one app's detail with one. Without an app it prints the account, the licence and the device, then every theme's state on this computer:
hackerblue@dev:~$ hackerblue status
HackerBlue Account you@example.comLicense HackerBlue for ObsidianDevice laptopDevice usage 1 / 3Status Active Themes------------------------------------Claude Code Not installedGemini CLI Not installedOpenCode Not installedCodex CLI Not installedVS Code Not installedCursor Not installedZed Not installedJetBrains Not installedNeovim Not installedSublime Text Not installedkitty Not installedGhostty Not installedWezTerm Not installedAlacritty Not installedWarp Not installedKonsole Not installedfoot Not installedWindows Terminal Not installedtmux Not installedbtop Not installedlazygit Not installedYazi Not installedStarship Not installedObsidian Installed v1.0.1Chrome Not installedChromium Not installedHyprland Not installed
With an app, one theme's detail:
hackerblue@dev:~$ hackerblue status obsidian
HackerBlue for Obsidian Status InstalledInstalled 1.0.1Latest 1.0.1Location /home/you/vaults/notes/.obsidian/themes/Hacker BlueUpdate Up to dateLicense HackerBlue for Obsidian
Offline or logged out, the account and licence lines read Unavailable while the local installation state is still shown — a missing connection is never rendered as a missing licence.
hackerblue install <app> [--vault PATH]
“install a theme you own on this computer” — resolves the vault, downloads the licensed release, verifies it and installs it. Without --vault, the vaults Obsidian itself knows are read: one known vault is used, and several are only ever resolved by asking on a terminal. With no terminal it refuses and asks for --vault — it never guesses between vaults. --vault is validated before anything is downloaded, so a typo cannot create folders in a random directory. For codex-cli, --vault names Codex CLI's config folder — the one that holds config.toml — and without it the CLI uses CODEX_HOME, then ~/.codex. For claude-code, --vault names Claude Code's configuration folder — ~/.claude, or the one CLAUDE_CONFIG_DIR names — and the one theme setting in Claude Code's configuration file is changed to select the theme, with a copy of the file kept first. For jetbrains, --vault names the plugins folder of one JetBrains IDE — ~/.local/share/JetBrains/<IDE><version> on Linux — and is required only when more than one JetBrains IDE is installed. For lazygit it names lazygit's config folder — the one that holds config.yml — and without it the CLI uses CONFIG_DIR, then $XDG_CONFIG_HOME/lazygit, then ~/.config/lazygit. For yazi, it names Yazi's config folder — the one that holds theme.toml — and without it the CLI uses YAZI_CONFIG_HOME, then ~/.config/yazi; nothing else on the computer is changed:
hackerblue install obsidian --vault ~/Documents/MyVault
hackerblue self-update
“update this program to the newest hackerblue” — checks hackerblue.dev for a newer program, verifies its signature and checksum, and replaces the one you are running. It touches nothing else; installed themes are updated with hackerblue update <app>, below.
hackerblue update <app> [--vault PATH]
“update an installed theme on this computer” — fetches the latest release once and replaces each installation that is behind it. One already at the published version says so without downloading; one newer than the release is left alone. With --vault, only that vault's installation is touched:
hackerblue@dev:~$ hackerblue update obsidian
What changed in Hacker Blue for Obsidian 1.0.1: 1.0.1 — 23 September 2026 Maintenance release — no visible changes. Hacker Blue for Obsidian updated to 1.0.1. Location /home/you/vaults/notes/.obsidian/themes/Hacker BlueWas 1.0.0Checksum verified (sha256) Updates for this theme are included with your licence — no new purchase is needed.
Updating never asks you to buy the theme again — the licence you already hold covers it. There is no uninstall command: removing the theme folder from the vault's .obsidian/themes/ directory is all it takes (for Claude Code, choose another theme in /theme and delete themes/hacker-blue.json from its configuration folder), and hackerblue status then reports it as not found.
The theme workflow
hackerblue install obsidian and hackerblue update obsidian are the two commands that write, and both only ever write inside a vault's own theme folder. The order is fixed, and a failure at any step leaves the vault exactly as it was:
- The vault.
--vaultnames it, or Obsidian's own vault list is read — one known vault is used, several are resolved by asking on a terminal, never guessed. - The release. The protected release endpoint checks the device token, the active device and the licence first, so a download URL only exists for an entitled account. Without a licence the CLI prints where to buy instead.
- The download. The artifact is streamed to a temporary file, and its SHA-256 must equal the release's — a mismatch is discarded.
- The archive. It must be a plain zip of ordinary files (
manifest.jsonandtheme.cssrequired) naming the version the release advertised. Absolute paths,.., symlinks and anything oversized are refused before a single file reaches the vault. - The placement. The release is staged inside the vault's themes directory, the previous installation is backed up, and two renames complete the install — Obsidian never sees a half-written theme.
A theme folder the CLI did not create is never replaced — the command refuses and asks you to move it aside. Sibling themes and the rest of the vault are never read or written. An installation whose recorded folder has disappeared is reinstalled by running install again; the stale record is replaced once the new files are in place.
In your terminal
What the rest of your terminal looks like once a Hacker Blue terminal theme is applied.
The CLI prints plain text. What colours everything else you run — ls, git, your prompt — is the terminal, and a Hacker Blue terminal theme sets all sixteen of its colours. Below is real ls and git log output from a small demo folder and repository, drawn the way a terminal with the theme paints it.
hackerblue@dev:~/vaults/notes$ ls
Inbox Projects README.md scratch sync.sh
hackerblue@dev:~/vaults/notes$ git log --graph --oneline --no-decorate
*-------. 7b1c517 Merge the six feature branches|\ \ \ \ \ | | | | | * e75ca57 Add a daily note template| | | | * | 70e0ea6 Use the Hacker Blue theme| | | | |/ | | | * / 392c096 Export to PDF| | | |/ | | * / 4b9b4fb Search inside notes| | |/ | * / 419ef46 Tidy the tag panel| |/ * / c7e74df Sync on save|/ * 60bc9ba Start the vault
Local state and configuration
The CLI keeps small JSON files under your OS user config directory, and never stores a password, a Whop token or a hardware identifier — the device UUID is random, generated on first run.
-
device.json
device identity
The random device UUID, a display name, and when it was created. Survives
logout, so the next login re-authorises the same device. -
credentials.json
device token
The device token, the account and API it belongs to, and when it was issued. Removed by
hackerblue logout. -
installs.json
install records
One record per installed theme — platform, version, folder, vault, checksum. Written by
install/update, read bystatus; it surviveslogoutbecause the installation does. -
backups/
update backups
The theme folder as it was before an update replaced it — kept outside the vault so Obsidian never sees it as a theme. Remove old backups by hand if you want the space.
Where the files live: ~/.config/hackerblue on Linux, %APPDATA%\hackerblue on Windows, or $XDG_CONFIG_HOME/hackerblue when that variable is set. $HACKERBLUE_CONFIG_DIR moves the whole directory. On POSIX the directory is created with mode 0700 and the token-bearing files with mode 0600, replaced atomically so a crash cannot leave a half-written token.
Supported platforms
Linux on x86-64 and ARM64 (static, so it runs on any distribution, glibc or musl), macOS on Intel and Apple silicon, and Windows on x86-64 and ARM64. App config locations are resolved per platform (XDG on Linux, ~/Library/Application Support on macOS, %APPDATA% on Windows).
A session with no display and no Wayland compositor — a server or an SSH session — gets the activation URL printed instead of an opened browser, always safe to open on another device.
Troubleshooting
What the CLI says, and what to do about it.
| command not found | The folder the program was installed into is not on your PATH — the installer prints the line to add (~/.local/bin on Linux and macOS); on Windows open a new terminal after installing. |
|---|---|
| “cannot be opened because the developer cannot be verified” (macOS) | Choose Open Anyway under System Settings → Privacy & Security, or run xattr -d com.apple.quarantine on the file once. Installing with install.sh avoids it. |
| “Windows protected your PC” | Choose More info → Run anyway. Installing with install.ps1 avoids it. |
“failed its checksum” from the installer or self-update | The download did not match the published list, so nothing was installed. Run it again; if it repeats, do not run the file. |
| the activation code expired | The code is good for ten minutes. Run hackerblue login again for a new one. |
| “This account already has the maximum number of active devices.” | Deactivate a device at your account page, then run hackerblue login again. |
| “no Obsidian vault was found” | Pass the vault explicitly: hackerblue install obsidian --vault /path/to/vault. |
| “is not an Obsidian vault (no .obsidian folder)” | The path exists but is not a vault. Open the folder in Obsidian once, or pass the vault that holds your notes. |
| “no JetBrains IDE was found” | Start your JetBrains IDE once so it creates its folders, or pass its plugins folder: hackerblue install jetbrains --vault ~/.local/share/JetBrains/IntelliJIdea2025.3. |
| “Codex CLI's config folder was not found” | Run codex once so it creates its folder, or pass it: hackerblue install codex-cli --vault ~/.codex. |
| “btop's config folder was not found” | Run btop once so it creates its folder, or pass it: hackerblue install btop --vault ~/.config/btop. |
| “Yazi's config folder was not found” | Run yazi once, or create the folder, or pass it: hackerblue install yazi --vault ~/.config/yazi. |
| “No active licence for the Obsidian theme” | The account has no licence for this theme — see Pricing. Nothing was downloaded or changed. |
| “failed its checksum” | The download did not match the release. Nothing reached your vault — run the command again. |
| “Hacker Blue could not be reached” | status keeps showing local state; install and update refuse and change nothing. Installed themes keep working offline. |
| “Status Inactive” or “this computer is not signed in” | The device token is no longer recognised — the device may have been deactivated at /account. Run hackerblue login to authorise this computer again. |
| “This release needs hackerblue CLI X or newer” | The published release asks for a newer CLI. Nothing was downloaded or changed. |