Sucia Store
Your library Sign in

Verification

Check before you trust.

Nothing here says "safe". It says "matches" or "does not match", and you can check it yourself.

What the Sucia app checks

  1. The download manifest is signed by Sucia with an Ed25519 key. The app verifies the signature against the key it pins before reading anything else.
  2. Every file path in the manifest must be a plain relative path inside the install folder.
  3. Every file's size and SHA-256 must match the manifest. A file that does not match is deleted, not installed.
  4. Only after every file matches is the build moved into place and made launchable.

Check a file yourself

On Windows, open PowerShell in the folder that holds the file and run:

Get-FileHash .\SuciaApp.zip -Algorithm SHA256

Compare the result with the SHA-256 shown on your library page. If it does not match, do not run the file and write to Sucia.

The signing key

The current manifest signing key is published on your Sucia account at /api/store/keys, with its key id. A rotated key is published there before any build signed with it ships.