Release verification

Check before you mount.

The verifier checks the downloaded DMG's outer SHA-256 first, then validates signing, notarization, Gatekeeper, the bundled CLI, and the SPDX SBOM.

1. Download matching files

Keep the DMG, Authsia-<version>.provenance.json, and Authsia-<version>.spdx.json together.

2. Check hashes and signing

Compare the DMG and SPDX files to the provenance JSON before mounting. Then confirm Developer ID signing, notarization, and Gatekeeper:

shasum -a 256 Authsia-<version>.dmg Authsia-<version>.spdx.json
python3 -c 'import json,sys; p=json.load(open(sys.argv[1])); print(p["artifacts"]["dmg"]["sha256"]); print(p["artifacts"]["sbom"]["sha256"])' \
  Authsia-<version>.provenance.json
codesign --verify --strict Authsia-<version>.dmg
codesign -dvvv Authsia-<version>.dmg 2>&1 | grep -E 'Authority=|TeamIdentifier='
xcrun stapler validate Authsia-<version>.dmg
spctl --assess --type open --context context:primary-signature Authsia-<version>.dmg

3. Confirm the expected identity

Official builds use the published Developer ID authority and Apple Team ID:

33M8QU65SP

Stop if the outer hash, SBOM hash, bundled CLI hash, signing identity, notarization, or Gatekeeper assessment differs.