Skip to main content

Verifying Your Download

Every Knowii Voice AI release is cryptographically signed.

In everyday use you don't have to do anything. When the app updates itself, it checks that signature automatically and refuses any download that doesn't match. That protection is always on and can't be switched off.

This page is for the extra-careful moment when you install manually and want to confirm for yourself that the file really came from us.

Every installer ships with its signature, so you have everything you need: download the installer and its matching .sig file from the same place — your Gumroad Library or the Knowii Community website, whichever you bought through.

The public key​

Releases are signed with a minisign key. The matching public key — the same one embedded in the app for automatic updates — is:

RWSxpIDA1rb2czTBbfwlmm2Vw4QyjmZYBQ77KgZS/HcmnCU2SBLJEF8y

(Key ID 73F6B6D6C080A4B1.)

What is signed​

A signature file is a small file sitting next to the installer, with the same name plus .sig. You'll find one for the Linux .deb, .rpm, and .AppImage, and for the Windows -setup.exe.

The macOS .dmg has no .sig file, and doesn't need one: it is signed and notarized through Apple instead, which macOS verifies automatically the first time you open it.

How to verify​

You need the free minisign tool:

  • Linux: sudo apt install minisign (Debian 12+ / Ubuntu 24.04+), sudo dnf install minisign (Fedora), sudo pacman -S minisign (Arch). On older Debian/Ubuntu releases the package isn't available — grab the binary from the minisign releases instead.
  • macOS: brew install minisign
  • Windows: scoop install minisign or download it from the minisign releases

Download the installer and its .sig file into the same folder, then:

Linux / macOS:

# The .sig file is base64-wrapped; unwrap it first.
# (On macOS, use -D instead of -d if your system rejects -d.)
base64 -d "Knowii.Voice.AI_0.9.0_amd64.deb.sig" > installer.minisig

# Verify the installer against the public key
minisign -Vm "Knowii.Voice.AI_0.9.0_amd64.deb" -x installer.minisig \
-P RWSxpIDA1rb2czTBbfwlmm2Vw4QyjmZYBQ77KgZS/HcmnCU2SBLJEF8y

Windows (PowerShell):

# Unwrap the base64 .sig file
$sig = Get-Content "Knowii.Voice.AI_0.9.0_x64-setup.exe.sig" -Raw
[IO.File]::WriteAllBytes("$PWD\installer.minisig", [Convert]::FromBase64String($sig))

# Verify the installer against the public key
minisign -Vm "Knowii.Voice.AI_0.9.0_x64-setup.exe" -x installer.minisig `
-P RWSxpIDA1rb2czTBbfwlmm2Vw4QyjmZYBQ77KgZS/HcmnCU2SBLJEF8y

Replace the file names with the ones you downloaded. A successful check prints:

Signature and comment signature verified

That's your proof: the file is byte-for-byte the one we built and signed.

On macOS​

The .dmg is verified for you. It is signed and notarized by Apple, so macOS checks it the first time you open it and refuses anything that has been altered — there is nothing to run by hand.

If verification fails​

Don't run the installer. A failed check usually means an incomplete download — download the installer and its .sig again and retry. If it still fails, let us know and mention where you downloaded the file from.