Run the Fystack Cosigner on your own servers
One command installs cosigner-cli. Every download is checked against signed checksums and Sigstore signatures before it runs.
$curl -sSL https://cosigner.fystack.io/install.sh | shCurrent release
Two artifacts, each with its own signature
cosigner-cli runs on your host. The Cosigner runtime runs in Docker. Each is built and signed by its own release workflow, and each is verified before it runs.
cosigner-cli v0.1.1
- Released
- Oct 11, 2026
- Commit
- 175aa02bf75e
- Signed by
- fystack/cosigner-cli/.github/workflows/release.yml@refs/tags/v0.1.1
- install.sh SHA-256
- 7eac5b3745c39ccd84406e002d83a474912935d545982de29d0bd89dc16c5f33
cosigner v0.1.14
- Built
- Oct 7, 2026
- Platforms
- linux/amd64, linux/arm64
- Signed by
- fystack/cosigner/.github/workflows/release.yml@refs/tags/v0.1.14
- Image digest
- sha256:c0f2c54a97444286158164b99354b306fb496fed7223189f5b6b5c3e8d3f056b
cosigner-cli up picks the newest signed release from ghcr.io/fystack/cosigner, verifies it with cosign and pins its digest. To install this exact image:
$cosigner-cli up \
--image ghcr.io/fystack/cosigner@sha256:c0f2c54a97444286158164b99354b306fb496fed7223189f5b6b5c3e8d3f056bVerify it yourself
Don't trust the pipe. Check it.
Everything the installer and cosigner-cli check, you can check by hand with the same commands.
Read install.sh before you run it
Each release has its own installer with that release's checksums written into it. Download the one for v0.1.1, compare its SHA-256 with the one published here, read it, then run it.
$curl -sSLO https://cosigner.fystack.io/v0.1.1/install.sh
$echo "7eac5b3745c39ccd84406e002d83a474912935d545982de29d0bd89dc16c5f33 install.sh" | shasum -a 256 -c
$less install.sh
$sh install.shGet started
From install to a running cosigner
Three commands. Your key shares, approval callback and encrypted database stay on your host.
- 1
Install
Installs cosign if needed, verifies cosigner-cli and checks Docker.
shell$curl -sSL https://cosigner.fystack.io/install.sh | sh - 2
Check the host
Confirms Docker, cosign, your config and the install state.
shell$cosigner-cli doctor - 3
Pair and start
Pulls the newest signed runtime, verifies it, pins its digest, then asks for your pairing token.
shell$export COSIGNER_HOME=/srv/cosigner $cosigner-cli up \ --apex-endpoint https://YOUR-APEX-HOST \ --config /secure/config.yaml
Before you start
- Linux for production. macOS or WSL 2 for development.
- Docker with Compose v2.
- cosign v3+ (the installer adds it if missing).
- A pairing token and your Apex endpoint.
// Running in a Nitro enclave? That setup is different, see the Fystack docs.
All releases
Every release, every checksum
Each cosigner-cli release keeps its own installer, so --version installs exactly what was published. Runtime images are listed with the digest that up pins.
| Version | Released | Commit | Install |
|---|---|---|---|
| v0.1.1Latest | Oct 11, 2026 | 175aa02bf75e | sh -s -- --version v0.1.1install.sh |