Docs / Install · Community Alpha
Verify your download
This is optional. It lets you confirm that the file on your computer is exactly the file TaktSignal published — not damaged, not replaced along the way.
What is a SHA-256 checksum?
A SHA-256 checksum is a 64-character fingerprint calculated from every byte of a file. Change a single byte and the fingerprint changes completely. If the checksum you calculate on your computer is identical to the one on the download page, you have the published file.
Where the published checksum comes from
The download page shows, for each file: version, platform, architecture, file size, SHA-256 and release channel.
These values are read from TaktSignal's release metadata, which is signed with the TaktSignal release key; the
website shows a download only if that signature is valid. The same metadata is what the installed app uses to check
updates. Nobody copies checksums by hand into the website. A SHA256SUMS file with all checksums is published next
to the downloads.
Calculate the checksum
Replace <file> with the name of the file you downloaded.
| Computer | How |
|---|---|
| macOS | Open Terminal and run shasum -a 256 ~/Downloads/<file> |
| Linux | Open a terminal and run sha256sum ~/Downloads/<file> |
| Windows | Open PowerShell and run Get-FileHash $HOME\Downloads\<file> (SHA-256 is the default algorithm) |
Compare the result with the SHA-256 on the download page. Upper or lower case does not matter; every character must match.
If it does not match
Do not open the file. Delete it and download it again from taktsignal.cloud/download. If it still does not match, report it privately — it could be a problem with the release host.
What a matching checksum does and does not tell you
It tells you the file is the one TaktSignal published. It does not replace code signing by Apple or Microsoft, which the Community Alpha does not have yet, and it is not a security audit of the software.