> ## Documentation Index
> Fetch the complete documentation index at: https://docs.requestly.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Verify Your Linux Download

> Check that the Requestly AppImage you downloaded is the genuine file signed by Requestly before you run it.

Every Requestly Linux release is signed. Before you run the AppImage for the first time, you can check that the file on your machine is exactly the one Requestly published and was not changed on the way to you.

This check is optional, and you only need it once. After the first install, the app checks the signature of every update for you before installing it.

## Before you start

You need:

* The AppImage you downloaded, for example `requestly-api-client-2610.8.1-linux-x86_64.AppImage`.
* A terminal with `curl` and `openssl`. Most Linux distributions include both.

Run the commands below from the folder that contains the AppImage.

## Step 1: Save the Requestly public key

This is the key Requestly uses to sign every Linux release. It is published on this page, separately from the download server, so that a problem with the download server cannot change both the file and the key you check it against.

```bash theme={null}
cat > requestly-linux-signing.pem <<'EOF'
-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAERdJfshk34vq+ORkA+acmSVwXb86f
3EqQJt8IFglNE5qi3fQgBDcZH97TOPQkEzICvbdrtA4RAuD9uUKACy/0rQ==
-----END PUBLIC KEY-----
EOF
```

## Step 2: Download the signature for your file

Each AppImage has a matching signature file. Set `APPIMAGE` to the name of the file you downloaded, and the commands fetch the signature for that exact version.

```bash theme={null}
APPIMAGE=requestly-api-client-2610.8.1-linux-x86_64.AppImage
VERSION=$(echo "$APPIMAGE" | sed -E 's/^requestly-api-client-(.+)-linux-x86_64\.AppImage$/\1/')
curl -fsSLO "https://assets.requestly.com/assets/desktop/releases/${VERSION}/${APPIMAGE}.sig"
```

## Step 3: Verify the file

```bash theme={null}
openssl dgst -sha256 -verify requestly-linux-signing.pem -signature "${APPIMAGE}.sig" "${APPIMAGE}"
```

If the file is genuine, the command prints:

```text theme={null}
Verified OK
```

You can now make the AppImage executable and run it.

## If verification fails

Any output other than `Verified OK` means the check failed. Depending on your OpenSSL version, the message is `Verification Failure` or `Verification failure`.

If that happens:

1. **Do not run the file.** Delete it.
2. Check that `APPIMAGE` matches your file name exactly, including the version number. A signature only matches the release it was made for.
3. Download the AppImage again from the [Getting Started](/api-client/overview) page and repeat the steps.

If a fresh download still fails, contact [Requestly support](mailto:contact@requestly.io) and do not run the file.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.