Winget on Windows: Complete guide to commands and advanced usage

Last update: February 20th 2026
  • Winget is the official Windows package manager that allows you to install, update, and uninstall applications from the command line.
  • The tool integrates with the Microsoft Store, a community repository, and private sources, and supports a wide variety of installer formats.
  • It allows you to automate entire teams using YAML configuration files, PowerShell scripts, and group policies in enterprise environments.
  • It includes advanced features such as no-install download, manifest validation, version PIN, and extensive security and registration options.

winget commands in Windows

If you use Windows daily and spend half your life installing, updating, or removing programs, learning to use Winget from the terminal can save you a lot of time. This official Microsoft package manager brings to Windows a way of working very similar to that of GNU/Linux distributions with apt or dnf, but without the need to install third-party tools.

With Winget, you can search for, install, update, uninstall, and configure applications simply by typing commands, as well as automate the complete setup of a PC using scripts or configuration files. Let's take a closer look at how it works, what commands are available, and how to get the most out of it, whether you're a home user, developer, or system administrator.

What is Winget and how does the Windows Package Manager work?

Winget is the command-line tool for the Windows Package Manager . It's a client that connects to various sources (the Microsoft Store, the Winget community repository, and private repositories) to locate installers, download them, and perform a controlled and repeatable installation.

In practice, winget is made up of several elements that work together to manage software on the system, so the core visible to the user is the winget command , but behind the scenes there are services and manifests that describe each package.

The complete Windows Package Manager solution includes three main pieces that are important to distinguish in order to understand the entire ecosystem:

  • Winget client: is the console executable you use in PowerShell, Terminal, or the command prompt to launch commands like winget install o winget upgrade.
  • Packaging and repository serviceMicrosoft maintains a community repository of manifests on GitHub and integrates with the Microsoft Store to host and distribute applications on Windows computers.
  • Winget configuration filesThese are YAML files that describe the "desired state" of a PC (applications, settings, scripts), allowing configure an entire device with a single command.

The philosophy is that you can define what software and configuration you want, and the Package Manager will take care of installing, updating, and maintaining everything automatically, minimizing human error and differences between machines.

Installing Winget on Windows 10, Windows 11, and Windows Server

On most modern devices, Winget comes ready to use because it is part of the App Installer It is distributed through the Microsoft Store in Windows 10 and Windows 11, and via updates in Windows Server 2025. Simply open a terminal and type winget to check if it is available.

If you see the list of options and the client version when you run the command, it means you have the Windows Package Manager correctly installed . Otherwise, you can go to the Microsoft Store, search for "App Installer," and update or install the package.

Install preview versions of winget (for developers)

If you want to try out new Winget features before anyone else, Microsoft offers preview builds . These are primarily intended for developers and advanced users who don't mind encountering the occasional bug.

There are two common ways to obtain the client preview:

  • Manually download the preview version package from the winget repository on GitHub and Install it to temporarily replace the stable client.You will not receive automatic updates for subsequent previews from the Store; you will have to repeat the process when a new one is released.
  • join the Windows Insider Program with a Microsoft account, work account, school account, or Entra ID (formerly AAD) on the Canary or Dev channels. On those channels, builds automatically include Winget updates from the Microsoft Store with the latest experimental functions.

Installing Winget in a Windows Sandbox (Isolated Space)

Windows Sandbox is a lightweight, disposable desktop environment where you can run applications in isolation from the main system . Anything you install inside is lost when you close the sandbox, making it ideal for testing.

This environment doesn't come with Microsoft Store or Winget pre-installed, so you'll have to install the client manuallyMicrosoft recommends using the PowerShell module Microsoft.WinGet.Client and the cmdlet Repair-WinGetPackageManager to "start" winget inside the sandbox.

From a PowerShell console in the sandbox, you can use a script like this (adapted and formatted) to deploy the stable version to all users in the environment:

$progressPreference = 'silentlyContinue'
Install-PackageProvider -Name NuGet -Force | Out-Null
Install-Module -Name Microsoft.WinGet.Client -Force -Repository PSGallery | Out-Null
Repair-WinGetPackageManager -AllUsers

If needed, the module can also be installed with user or machine scope using the parameter -Scope AllUsers en Install-Moduleand you can add -IncludePrerelease a Repair-WinGetPackageManager to test preview versions.

Important permitting and administrative considerations

The way installations behave with Winget changes depending on whether you run the commands with administrator privileges or as a normal user . This is key if you manage many computers or want to automate processes.

When you start Winget without elevated privileges, some applications will require elevation to install. In these cases, Windows will display a User Account Control (UAC) prompt asking for confirmation. If you decline the elevation, the installation or update of that specific package will fail.

If you open PowerShell or the Command Prompt as administrator and run `winget`, installations that require elevated privileges will not display the User Account Control (UAC) prompt , since the context is already elevated. This is convenient, but it means you must be very careful and only install trusted software , especially in corporate environments.

  My PC doesn't detect my mobile phone: causes and complete solutions

In mixed scenarios (programs that must run at user level versus machine level) it is common to combine winget executions as a user and as an administrator , or to use group policies to force certain behaviors and reduce warnings.

Basic use of winget: essential first commands

Once you have App Installer up to date, using winget is as simple as open PowerShell, Windows Terminal or CMD y escribir wingetYou will see the installed version, an overview, and a list of available commands.

The typical workflow almost always starts with a search, followed by the installation of the application you're interested in. The essential steps would be something like this:

  1. Search for an app: winget search <nombre_de_app>
  2. Check the name, identifier, and origin of the package you want.
  3. Install it: winget install <nombre_o_id>

During installation, winget downloads the correct installer for your architecture and source and launches it with the appropriate parameters (usually in silent mode or minimizing interaction), informing you at the end if everything went well.

If you want to see the applications you already have on your system, you can launch winget list so that a List of installed packages with their versionsThis command is very useful for checking what can be updated and what is recognized by Winget, even if it was not originally installed with this tool.

Complete list of main winget commands

The client supports a series of specific commands designed to cover the entire application lifecycle and configuration. Currently, the most important general commands are:

Command Description
install Install the application indicated from the configured source.
show Sample detailed information of a package (editor, version, origins, etc.).
source Allows add, remove or update package repositories.
search makes a search of applications in the configured sources.
list show the list of installed packages recognized by winget.
upgrade Update specific applications or all those that have a new version.
uninstall Uninstall a specific application.
hash Calculate the SHA256 hash from an installer.
validate Check the validity of a manifesto before sending it to the community repository.
settings Open and allow editing of the file winget configuration.
features It shows the status of the experimental functions.
export Exports to a file the list of installed packages.
import Install in bulk all packages listed in an exported file.
pin Allows anchor versions of packages so that they are not updated beyond a certain point.
configure Run files from declarative configuration to leave the system in a desired state.
download Download installers of applications without running them.
repair Try repair problematic facilities.
dscv3 Commands related to PowerShell DSC v3 and desired state configuration resources.

Global options and most used parameters

Almost all Winget commands accept global options that modify their behavior, such as displaying more information, controlling the proxy, or suppressing warnings. Some of the most relevant are:

Choice Function
-v, --version show the current version of the winget client.
--info Returns detailed installation information (licenses, privacy, group policies, etc.).
-?, --help Presents the specific help of a command.
--wait Makes winget Wait for a key before exiting, useful when running it in ephemeral windows.
--logs, --open-logs Open the default folder where the winget logs.
--verbose, --verbose-logs Activate a detailed log for debugging.
--nowarn, --ignore-warnings Hide the warning messages.
--disable-interactivity Try deactivating all interactive requests for automated use.
--proxy Establishes the HTTP/HTTPS proxy to be used during that execution.
--no-proxy Force a winget Do not use a proxy even if the system has it configured.

Main practical functions: search, install, list and update

In day-to-day use, you'll mostly use Winget for a few very direct commands that allow you to manage applications without manually touching installers , just like you would with a package manager in Linux.

To locate available software, you have at your disposal winget search <texto>which returns a list of names, identifiers, versions, and origins that match the search. This list also helps you identify the exact ID of the package you want to install.

To check which programs you have installed, simply run winget listThe command displays all applications that Winget recognizes, regardless of whether they were installed with the tool or not, and allows you to detect older versions that need updating.

The standard installation is done with winget install NOMBRE_APP or better yet with the Package ID, For example: winget install Microsoft.VisualStudioCodeIf the installation requires interaction (accepting the EULA, choosing options, etc.), it is usually done in simplified or silent mode as far as possible.

Sometimes, the installer pauses the process to ask you to accept a license agreement or confirm something on screen. To ensure everything runs smoothly from start to finish without prompts, you can use parameters such as --silent y --accept-package-agreements --accept-source-agreements, so that You will force acceptance of the agreements and remove unnecessary windows..

To keep the system up to date, winget offers several ways to update software. The command winget upgrade without further ado, it will show All applications with new versions availableWhile winget upgrade NOMBRE_APP will only update a specific package.

If you prefer to do it all at once, winget upgrade --all It will attempt to update all packages that have a newer version. This is where permissions come into play: if you run it as a user, UAC notices will be issued for each installation that requires liftingIf you do it as an administrator, they will be managed without displaying the dialog boxes.

  Business Intelligence Software: Key for Companies

Finally, uninstalling is also very easy with winget uninstall NOMBRE_APP, and you can even include multiple applications in the same command line so that they are removed one after another, as long as winget recognizes them in the system.

Less well-known but very useful commands

In addition to the basic commands, winget includes several functions that go unnoticed in many quick guides and that are very practical when working with many packages or need to avoid identification errors.

The command winget show NOMBRE_APP It's used to see all the details of a package before installing it: publisher, specific version, ID, source, installer type, and sometimes even the official link. You can also filter by identifier with winget show --id ID_PAQUETE to go for a sure thing.

If you're worried that the installation will stall waiting for you to accept license agreements, you can add the parameters --accept-package-agreements y --accept-source-agreements a winget install for The legal terms are automatically accepted. without dialog box.

Combining these options with --silent, for example winget install NOMBRE_APP --accept-package-agreements --accept-source-agreements --silent, you get completely unattended facilities, very useful in deployment scripts or when you want to leave the PC working while you do something else.

winget download command: download installers without installing

In certain situations you might want to download application installers but not run them yet : for example, to move them to offline machines, prepare a local repository, or manually review the content before installing.

That's what the command is for. winget download, whose basic use is winget download [[-q] <query>] [<options>]It supports both generic queries and filters by ID, name or moniker, and downloads the installer (or installers) corresponding to your selection.

When the package comes from the Microsoft Store and is a packaged application ( MSIX, APPX, bundles, etc. ), `winget` can also download the associated license file. In these cases, the command requires authentication with an Entra ID and that the account belongs to roles such as Global Administrator, User Administrator, or License Administrator to generate and retrieve that license file offline.

If you want to avoid dealing with the offline license, you can use the parameter --skip-license o --skip-microsoft-store-package-licenseso that winget Just download the installer and do not try to obtain the license file.

The command also allows filtering by platform or architecture. --platform You can choose between values ​​such as Windows.Desktop, Windows.Universal o Windows.Holographic all with limit downloads to a specific type of device.

Similarly, with --architecture you can indicate x86, x64, ARM or ARM64 to select only the installer appropriate for the target CPU. This is especially useful if you're going to move those files to other computers with a different architecture than yours.

Among the most frequent options of winget download include:

  • -d, --download-directory: folder where the downloaded installers will be saved.
  • -m, --manifest: path to a YAML manifest that describes what should be downloaded.
  • --id, --name, --moniker: filters to restrict the result to a specific package.
  • -v, --version: exact version to download, if you don't want the latest one.
  • -s, --source: limits the operation to a specific origin.
  • --scope, --installer-type, --locale, --skip-dependenciesAdvanced options to control in detail what is downloaded.

Some practical examples would be:

winget download --id Microsoft.PowerToys --version 0.15.2
winget download --id Microsoft.WingetCreate --installer-type msix
winget download --id Microsoft.PowerToys --scope machine --architecture x64 --download-directory C:\Instaladores

Installer formats compatible with Winget

To work consistently with thousands of applications, winget recognizes a good number of common Windows installer types , including modern packaged installers and classic installers.

Currently supported formats include:

  • Executables EXE with silent installation parameters (Silent o SilentWithProgress).
  • Archives ZIP that are deployed in portable mode.
  • Installers Inno Setup.
  • Installers Nullsoft (NSIS).
  • Packages MSI y WIX.
  • Packaged apps Appx y MSIX.
  • Installers type BURN.
  • Applications portable (without traditional installation, direct executables).

Thanks to this range, winget can manage both modern Store applications and traditional desktop programs , provided their manifests are correctly defined in the corresponding repository.

Scripting and automation with WinGet and PowerShell

If you like to automate tasks or manage multiple teams, combining Winget with PowerShell and declarative scriptsTo do this, Microsoft is publishing the module Microsoft.WinGet.Client in the PowerShell Gallery, which exposes specific cmdlets for interacting with the service.

With this module you can create scripts that install, update or repair packages using pure PowerShell, integrate winget into CI/CD pipelines or incorporate it into scripts for provisioning new machines.

Additionally, the YAML configuration files associated with the command winget configure allow you to describe in a single document:

  • Prerequisites (assertions), as a minimum version of Windows.
  • Resources, which include packages to install, scripts to run, system settings, etc.

A simplified example configuration might include an assertions section where the minimum Windows 10 build is set , and a resources section with Visual Studio Code, Google Chrome, and a PowerShell script to prepare other modules. Once you have that YAML file, simply run:

winget configure --file ruta\a\winget.yaml

In this way, a single command leaves a computer with the same set of applications and settings time after time, perfect for corporate environments, classrooms, laboratories, or your own PC after formatting.

Add repositories and work with custom sources

By default, Winget uses the Microsoft Store and the community repository maintained on GitHub as its primary sources. However, you can also add additional repositories to expand the catalog or work with your organization's internal packages.

Many enterprise environments create their own REST source with manifests for their corporate applications, so that users can install them using winget just as if they were public packages , but controlling versions, licenses, and distribution.

To add a new font, open PowerShell as administrator and run a command like this:

winget source add --name MiRepositorio --arg https://url.de.mi.repo/api

The command supports additional options such as --type (origin type, usually REST), --trust-level (for example Trusted o none) and --accept-source-agreements, That works for automatically accept the agreements of that repository without having to confirm it manually.

  Complete guide to optimizing Windows 10 on older computers

To verify that the source has been added correctly, you can use winget source list and review the list of registered sources. You can also update or delete sources when you no longer need them.

Winget for developers, ISVs and businesses

Although any user can benefit from winget, it truly shines in the hands of developers, software manufacturers, and IT administrators who need to standardize installations and working environments.

Developers can describe their essential tools (editors, SDKs, compilers, various utilities) in a file and let the Windows Package Manager take care of installing all dependencies correctly , without omissions or inconsistent versions between machines.

Software vendors (ISVs) have access to the Winget community repository on GitHub, where they can upload their application manifests so that the tool includes them in the default source. Packages are automatically validated and can also undergo manual review to ensure their quality.

In corporate environments, Winget simplifies the task for security and IT teams, as it can be used in conjunction with Microsoft Intune and group policies to enforce strict policies on what is installed, from which sources, and under what conditions, reducing risks and maintaining a consistent level of updates and hardening.

Security, certificate anchoring, and group policies

The connection between Winget, Microsoft Store, and other REST sources is protected by certificate checks and security mechanisms to prevent man-in-the-middle (MITM) attacks and theft of credentials or data.

In the specific case of the Microsoft Store, there is a policy called BypassCertificatePinningForMicrosoftStore that Check if Winget validates the Store certificate hash against a list of known certificates. This is key when the organization uses firewalls with SSL inspection that can interfere with validation.

The options in this policy are:

  • Without configuration (default): winget respects the standard Package Manager settings and checks the Store certificates.
  • EnableMicrosoft Store certificate validation is omitted, which may be necessary in some SSL inspection scenarios, but The risk of MITM attacks increases..
  • Disable: Winget is forced to validate that the certificate really belongs to the Store before starting the connection.

Certificate pinning is an extra layer of security that ensures communication between the Winget client and the Microsoft Store cannot be easily intercepted or manipulated . Disabling it without a good reason is a bad idea from a security standpoint.

In addition to this policy, each version of Windows 11 includes specific ADMX/ADML templates for Winget that extend the configuration options in the Group Policy Management Console (GPMC). These are organized into categories such as allowed source control, local development (experimental features, local manifests), and proxy execution and usage policies.

To use these templates, you can download the file from GitHub. DesktopAppInstallerPolicies.zip corresponding to the version of Winget you are interested in, extract it and copy the files .admx y .adml to the standard routes of C:\Windows\PolicyDefinitions and its language subfolder. From there, the new options will appear in GPMC and you'll be able to apply them to OUs, sites, or the entire domain.

Debugging, logging, and sending new packages

When something goes wrong (failed downloads, installations that don't finish, version conflicts), winget generates detailed logs that are very useful for finding the source of the problem.

You can open the logs folder with the option --open-logs or activating --verbose-logs so that the tool saves more information about each operation. The official repository winget-cli It also maintains a list of common problems and recommended solutions, where it's a good idea to take a look before opening a new issue.

If you're missing a program from the catalog, you can always create and submit a manifest to the community repository. This way, not only will it be available to you, but other users and organizations can also easily install it from Winget.

The tool itself is open source and lives in the repository microsoft/winget-cliIt's written in C++ and designed to be compiled with Visual Studio 2022. If you want to contribute, you'll need to accept and sign the Contributor License Agreement (CLA) from Microsoft and push the changes from a branch of your fork.

Ultimately, knowing and mastering Winget gives you the ability to treat your Windows PC more like a "server" or serious development system: everything scriptable, everything reproducible, and with fine control over what is installed and how , avoiding unnecessary clicks and surprises in the form of misaligned versions or programs that no one knows how they got onto the computer.