Verify your download

It takes a couple of minutes, and it tells you the file you got is exactly the one we published, not something swapped in along the way.

The release signing key

Every release is signed with this key. Its fingerprint is what identifies it: compare it with the one your tools show.

NameBiscuit Wallet releases
TypeRSA 4096
FingerprintD714 332E 6101 C1DA AC60  E644 202F 1FA3 98DE CEFA

The public key is on the download page, in SECURITY.md, and built into Biscuit: the app installs an update only after checking this signature.

1. Check the signature of the checksums

Each release has a list of SHA-256 checksums, hashes-<version>-plain.txt, signed with the key above. With GnuPG installed (on a Mac, from GPG Suite or Homebrew; on Windows, Gpg4win):

gpg --import biscuit-release-key.asc
gpg --verify hashes-1.0.9-plain.txt

The output must say Good signature from “Biscuit Wallet releases”, and the fingerprint must match the one above. GnuPG may add that the key is not certified with a trusted signature: that only means you haven’t signed our key yourself.

2. Check the file against the list

Compute the checksum of the file you downloaded and find the same value, next to the same file name, in the signed list.

macOSshasum -a 256 biscuit-1.0.9-mac-arm64.zip
Linuxsha256sum biscuit-1.0.9-linux-appimage.zip
Windowscertutil -hashfile biscuit-1.0.9-win.zip SHA256

If the values differ, don’t open the file: download it again from biscuitwallet.com.

Going further

Releases are built with Guix, so you can also rebuild one yourself and compare: see Reproducible builds.