Skip to main content
Packfiles takes the security of our products and protection of our customers extremely seriously. To prevent tampering, all Warp Vault releases are cryptographically signed using industry-standard techniques. To verify the authenticity and integrity of your Warp Vault download, we recommend following the steps below for your host operating system. Jump to instructions for:

macOS

On macOS systems, the code signature of Warp Vault can be inspected with the following command:
This will produce output similar to the below. Verify that the Authority field matches Developer ID Application: Packfiles Inc (LQ28J3F3JH), and that the TeamIdentifier field matches LQ28J3F3JH.

Windows

On Windows, you can inspect the certificate chain of Warp Vault’s MSIX installer or .exe file to verify its authenticity. Right click on your downloaded copy of the Warp Vault installer and select Properties.
In the Properties view, select Digital Signatures, then click on Details.
In the Details view, select Advanced. Verify that the Serial number field of the signature has a value of 67d7636c9135682d620110e6.

Linux

Linux builds of Warp Vault are signed with the Packfiles’ Vault Linux Releases (A) PGP key. This key’s fingerprint is:
The public key is:
You can check the signature of a given Warp Vault release with the following process.

1. Import the Key

Save the PGP public key block above to a file on disk. Then run:

2. Verify the Signature

After downloading a Linux release of Warp Vault, extract the contents of the archive and run the following command to verify the signature.
You should see output like the following:
In the output from the verification command, ensure that the Primary key fingerprint field matches the Packfiles’ Vault Linux Releases (A) PGP key fingerprint of ED67E8E35FB2EB52F6C81937BD4C2E3452360800.