> For the complete documentation index, see [llms.txt](https://docs.sealsecurity.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sealsecurity.io/step-by-step-onboarding-guides/rpm-no_scm-jfrog_xray-container-cli_remote-renamed.md).

# Step-by-Step Setup Guide

This guide walks you through the initial account setup, token generation, and connecting your first project to Seal Security.

## Account Creation & Token Generation

Follow these steps to access the platform and prepare your environment. If you already have a token, you can skip to the next section.

1. **Access the Invite:** Click on the **Sign in >** button in the Seal Security invite email you received.
2. **Log In:** Log in to the platform using your password or social login credentials.
3. **Start Onboarding:** We're starting the onboarding flow. Click **Next >** to begin.
4. **Generate Token:** First, you must generate a token to Seal's artifact server. This allows you to download our sealed versions.\
   ![Generate Token](/files/PavZ4q5NrXJse1vkrR0Y)
   1. **Generate:** Click on **Generate token**.
   2. **Copy:** Copy the newly generated token using the copy icon at the right of the text box.

      > **Important:** You will need this token later. While it should eventually be saved in a secure location (like a password manager or secret store), copy it now for immediate use in the next steps.
   3. **Continue:** Click **Next >**.
5. Click **Maybe later** to skip the GitHub integration.
6. **View Protection page:** You will land on the Protection screen.
   * **Status:** Since no projects are connected yet, we are not showing any results.
   * **Next Step:** We are now going to populate this data using the CLI. ![Empty Protection page](/files/Fgf0cjrcjNzbEzFu4thb)

## Integrate the Seal CLI

To start fixing vulnerabilities (and populate the Protection page), you must integrate the CLI into your build pipeline.

**Important Configuration:** For all integration methods, you must ensure the following environment variables are set:

* `SEAL_TOKEN`: The token you generated earlier.
* `SEAL_PROJECT`: The ID of your project on the Seal platform (e.g., "my-first-project").

Identify the location of your build pipeline. Typically, this is a `Dockerfile` in your repository.

Identify the final stage of the Dockerfile. Typically it is after the last `FROM` instruction.

Add the seal fix command to the end of the final stage of the Dockerfile:

```bash
ENV SEAL_TOKEN=${SEAL_TOKEN} # Notice, that for a secure setup we advice using Build secrets - https://docs.gitlab.com/ee/ci/build_secret/
ADD --chmod=755 https://github.com/seal-community/cli/releases/download/latest/seal-linux-amd64-latest seal
ENV SEAL_PROJECT="my-first-project"
ENV SEAL_USE_SEALED_NAMES=1
# JFrog Xray integration
ENV SEAL_JFROG_XRAY_ENABLED="true"
ENV SEAL_JFROG_INSTANCE_HOST=${JFROG_HOST}
ENV SEAL_JFROG_AUTH_TOKEN=${JFROG_TOKEN}
RUN ./seal fix os --mode remote
```

## Sealing a package

Once you have integrated the CLI into your pipeline, follow these steps to see the results.

1. **Trigger the Pipeline:** Run your build pipeline (Jenkins job, GitHub Action workflow, or Docker build). This execution will trigger the `seal fix` command, which scans your dependencies and reports back to the Seal Platform.
2. **View the Protection page:** Navigate to the [Protection page](https://app.sealsecurity.io/protection/vulnerable).
   * If the page is already open and empty, refresh it. You should now see a list of detected vulnerable packages.\
     ![Protection page with vulnerabilities](/files/XQHhwONeldfIPywa0Sxy)
3. **Remediate Vulnerabilities:** Now that we have visibility, let's look at how we apply fixes. In remote fix mode you have full control over the sealing process via the UI:
   * **Available Fixes:** Packages with a ready-to-use sealed version will display a blue Seal button.
   * **Action:** Click the Seal button, then confirm by clicking Seal package in the dialog box. This creates a sealing rule on the server to replace the vulnerable package with a sealed version of it.
   * **Apply:** Run your pipeline again. The CLI will now pick up the new rule, replace the package, and the status in the UI will change to a green Sealed label.\
     ![Sealing Modal](/files/AeMo59eV2A3gOZW8RW6H)
   * **Pending:** Packages without an existing sealed version will show a **Generate Fix** button.
