1. Download matching files
Keep the DMG, Authsia-<version>.provenance.json, and Authsia-<version>.spdx.json together.
Release verification
The verifier checks the downloaded DMG's outer SHA-256 first, then validates signing, notarization, Gatekeeper, the bundled CLI, and the SPDX SBOM.
Keep the DMG, Authsia-<version>.provenance.json, and Authsia-<version>.spdx.json together.
Compare the DMG and SPDX files to the provenance JSON before mounting. Then confirm Developer ID signing, notarization, and Gatekeeper:
shasum -a 256 Authsia-<version>.dmg Authsia-<version>.spdx.json
python3 -c 'import json,sys; p=json.load(open(sys.argv[1])); print(p["artifacts"]["dmg"]["sha256"]); print(p["artifacts"]["sbom"]["sha256"])' \
Authsia-<version>.provenance.json
codesign --verify --strict Authsia-<version>.dmg
codesign -dvvv Authsia-<version>.dmg 2>&1 | grep -E 'Authority=|TeamIdentifier='
xcrun stapler validate Authsia-<version>.dmg
spctl --assess --type open --context context:primary-signature Authsia-<version>.dmg
Official builds use the published Developer ID authority and Apple Team ID:
33M8QU65SP
Stop if the outer hash, SBOM hash, bundled CLI hash, signing identity, notarization, or Gatekeeper assessment differs.