Skip to main content
Every Requestly Linux release is signed. Before you run the AppImage for the first time, you can check that the file on your machine is exactly the one Requestly published and was not changed on the way to you. This check is optional, and you only need it once. After the first install, the app checks the signature of every update for you before installing it.

Before you start

You need:
  • The AppImage you downloaded, for example requestly-api-client-2610.8.1-linux-x86_64.AppImage.
  • A terminal with curl and openssl. Most Linux distributions include both.
Run the commands below from the folder that contains the AppImage.

Step 1: Save the Requestly public key

This is the key Requestly uses to sign every Linux release. It is published on this page, separately from the download server, so that a problem with the download server cannot change both the file and the key you check it against.

Step 2: Download the signature for your file

Each AppImage has a matching signature file. Set APPIMAGE to the name of the file you downloaded, and the commands fetch the signature for that exact version.

Step 3: Verify the file

If the file is genuine, the command prints:
You can now make the AppImage executable and run it.

If verification fails

Any output other than Verified OK means the check failed. Depending on your OpenSSL version, the message is Verification Failure or Verification failure. If that happens:
  1. Do not run the file. Delete it.
  2. Check that APPIMAGE matches your file name exactly, including the version number. A signature only matches the release it was made for.
  3. Download the AppImage again from the Getting Started page and repeat the steps.
If a fresh download still fails, contact Requestly support and do not run the file.