multAIplayergroup chat for Codex
HomeFAQReport a vulnerability
Verification guide
Trust Out-of-band updater anchor

Updater signing key.

This page publishes the desktop updater public-key fingerprint outside the GitHub release channel. Record and compare it before a first install, key rotation, or compromise recovery.

A matching fingerprint identifies the expected public key. It does not prove that a release, signing workflow, maintainer account, or device is uncompromised.

Current key

Minisign key id: 5F97AE260BE16B2F

SHA-256 of the exact apps/desktop/src-tauri/updater-public.key file:

626f3a15f71fc8c5794c9ce00392a12f782cd05ec47a88ce27858b43ce774673

From a trusted source checkout, run shasum -a 256 apps/desktop/src-tauri/updater-public.key. The output must match this page and the fingerprint recorded in the application repository.

Rotation and suspected compromise

Routine rotation requires an old-key-signed bridge release that embeds the new key. The new fingerprint must appear here before that bridge is published.

If the current key may be compromised, do not trust an updater transition signed only by that key. Stop the update manifest, verify the incident and replacement fingerprint through channels that do not depend on GitHub, and use a manually downloaded recovery build only after verifying its Apple signature, notarization, and published checksum.

multAIplayerBuild with Codex. Together.
Verify releasesThreat modelSecurity

Independent open-source project · Not affiliated with or endorsed by OpenAI