English documentation · runtime 7.24.4 · SDK 2.6.7. Content is maintained with runtime development; see each guide's scope and review date.
Release Verification
Status: Active Scope: public, current-state Last reviewed: 2026-08-21 Owner: AX Code release engineering
ax-minisign.pub is the canonical public key for AX Code release signatures. Installers, release
workflows, and publishing scripts read this checked-in copy. The public download origin
also publishes the same key, and the website hosts it at
ax-code.app/docs-assets/release/ax-minisign.pub.
No source checkout is needed to verify an artifact with the pinned key below.
To verify a downloaded asset and its detached signature:
minisign -V \
-P 'RWSlDu++afxCz01OqhYWhfo8+L8pVbSYXJBEb2zoWBuK0WACIzbGVZRO' \
-m ax-code-darwin-arm64.zip \
-x ax-code-darwin-arm64.zip.minisig
On Windows (PowerShell), the same public key verifies CLI archives and the installer script:
# From a checkout, or use the key string from SECURITY.md / install.ps1
minisign -V -p docs/release/ax-minisign.pub -m ax-code-windows-x64.zip -x ax-code-windows-x64.zip.minisig
minisign -V -p docs/release/ax-minisign.pub -m install.ps1 -x install.ps1.minisig
# Inline key form (matches what install.ps1 uses)
$minisign = "RWSlDu++afxCz01OqhYWhfo8+L8pVbSYXJBEb2zoWBuK0WACIzbGVZRO"
minisign -Vm ax-code-windows-arm64.zip -x ax-code-windows-arm64.zip.minisig -P $minisign
The Bash and PowerShell installers fail closed when verification fails. When minisign is not already on
PATH, they download the pinned minisign 0.12 archives from download.ax-code.com, check the archive
SHA-256, and check the extracted executable again before caching it, unless AX_CODE_SKIP_MINISIGN_VERIFY=1
is set intentionally. A minisign binary already on PATH is the operator’s tool and is not re-hashed.
Treat a key mismatch or failed signature as a release-integrity failure. Do not replace the key without updating the release workflows, installer verification, and key-rotation guidance in the same change.
See Installation and Runtime Channels for supported distribution channels.
Rollback
If a published stable release must be withdrawn, follow the release rollback runbook.
Release notes
CLI/TUI releases are documented here and in the repository changelog. Desktop application changes are owned by the separate AX Coder project.