This is the official OpenPGP key used to sign stable JX software releases.
Trusted primary fingerprint
D8C8 0CB8 8562 D3C6 4114 5998 BF03 B66B 82FA A9C7
Use this primary fingerprint when checking that a JX release signature belongs to Jonix.
Verify a JX release
Fetch the signed release tag and ask Git/GnuPG to verify it:
git fetch --tags
git verify-tag v1.5.0
A successful verification may name a signing subkey. Confirm that GnuPG also reports the trusted primary fingerprint shown above.
Get the public key
- Download the ASCII-armored public key
- Download the primary fingerprint
- SHA-256 for the armored public-key file
Import the public key with:
curl -fsS https://key.jonix.systems/release.asc | gpg --import
Importing the key makes signature verification possible; trust the identity only after comparing its primary fingerprint with the value published above.
About this key
A valid OpenPGP signature proves that a release was signed by the corresponding
private key. This site provides the human-facing identity binding: it states
which primary OpenPGP fingerprint Jonix intentionally uses for stable software
releases and publishes the corresponding public key over the jonix.systems
domain.
The fingerprint displayed here, fingerprint.txt, and release.asc are all
built from JX’s tracked release trust policy rather than maintained separately.
The same key can also be published through independent discovery channels such as Codeberg, WKD, and public OpenPGP key directories. Those channels are useful cross-checks; this page remains the simple canonical reference for humans.