> For the complete documentation index, see [llms.txt](https://docs.sealsecurity.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sealsecurity.io/step-by-step-onboarding-guides/python_poetry-no_scm-snyk-local-cli_remote-keep_names.md).

# Step-by-Step Setup Guide

This guide walks you through the initial account setup, token generation, and connecting your first project to Seal Security.

## Account Creation & Token Generation

Follow these steps to access the platform and prepare your environment. If you already have a token, you can skip to the next section.

1. **Access the Invite:** Click on the **Sign in >** button in the Seal Security invite email you received.
2. **Log In:** Log in to the platform using your password or social login credentials.
3. **Start Onboarding:** We're starting the onboarding flow. Click **Next >** to begin.
4. **Generate Token:** First, you must generate a token to Seal's artifact server. This allows you to download our sealed versions.\
   ![Generate Token](/files/PavZ4q5NrXJse1vkrR0Y)
   1. **Generate:** Click on **Generate token**.
   2. **Copy:** Copy the newly generated token using the copy icon at the right of the text box.

      > **Important:** You will need this token later. While it should eventually be saved in a secure location (like a password manager or secret store), copy it now for immediate use in the next steps.
   3. **Download CLI:** Download the appropriate CLI binary for your machine.
   4. **Continue:** Click **Next >**.
5. Click **Maybe later** to skip the GitHub integration.
6. **View Protection page:** You will land on the Protection screen.
   * **Status:** Since no projects are connected yet, we are not showing any results.
   * **Next Step:** We are now going to populate this data using the CLI. ![Empty Protection page](/files/Fgf0cjrcjNzbEzFu4thb)

## Integrate the Seal CLI

To start fixing vulnerabilities (and populate the Protection page), you must integrate the CLI into your build pipeline.

**The Golden Rule:** In all cases, the CLI step must be added **immediately after** dependencies are pulled/installed (from standard registries or your artifact server) but before the final build/compilation.

**Important Configuration:** For all integration methods, you must ensure the following environment variables are set:

* `SEAL_TOKEN`: The token you generated earlier.
* `SEAL_PROJECT`: The ID of your project on the Seal platform (e.g., "my-first-project").

Identify the location of your build pipeline.

In the pipeline, identify the step where dependencies are installed (e.g., `poetry install`).

Identify the location of the `pyproject.toml` file.

Add the seal fix command:

```bash
poetry install
export SEAL_TOKEN=${YOUR_TOKEN}
export SEAL_PROJECT="my-first-project"
# Snyk integration
export SEAL_SNYK_URL="https://api.snyk.io"
export SEAL_SNYK_TOKEN=${SNYK_TOKEN}
export SEAL_SNYK_ORG_ID=${SNYK_ORG_ID}
export SEAL_SNYK_PROJECT_ID=${SNYK_PROJECT_ID}
seal fix --mode remote pyproject.toml
```

## Sealing a package

Once you have integrated the CLI into your pipeline, follow these steps to see the results.

1. **Trigger the Pipeline:** Run your build pipeline (Jenkins job, GitHub Action workflow, or Docker build). This execution will trigger the `seal fix` command, which scans your dependencies and reports back to the Seal Platform.
2. **View the Protection page:** Navigate to the [Protection page](https://app.sealsecurity.io/protection/vulnerable).
   * If the page is already open and empty, refresh it. You should now see a list of detected vulnerable packages.\
     ![Protection page with vulnerabilities](/files/XQHhwONeldfIPywa0Sxy)
3. **Remediate Vulnerabilities:** Now that we have visibility, let's look at how we apply fixes. In remote fix mode you have full control over the sealing process via the UI:
   * **Available Fixes:** Packages with a ready-to-use sealed version will display a blue Seal button.
   * **Action:** Click the Seal button, then confirm by clicking Seal package in the dialog box. This creates a sealing rule on the server to replace the vulnerable package with a sealed version of it.
   * **Apply:** Run your pipeline again. The CLI will now pick up the new rule, replace the package, and the status in the UI will change to a green Sealed label.\
     ![Sealing Modal](/files/AeMo59eV2A3gOZW8RW6H)
   * **Pending:** Packages without an existing sealed version will show a **Generate Fix** button.
