FFmpeg Download Verification

FFmpeg is an optional component downloaded separately from Motrix. The builds maintained at motrixapp/ffmpeg-static are third-party builds for Motrix, not official FFmpeg binaries.

This manual page is the independent public-key reference for those builds. It does not certify that a release is available or free of vulnerabilities.

Public signing key

Algorithm: Ed25519. Authenticate the exact ffmpeg-manifest.json bytes before trusting any fields or hashes inside it.

The signature covers the following UTF-8 domain, including its final newline, followed by the unmodified manifest bytes. The code block shows the newline as \n:

Motrix FFmpeg release manifest v1\n

The key ID is SHA-256 of the public key’s SPKI DER encoding, not of the PEM text:

sha256:2b5d2575808c8c0ef2a9d616e994ccc96c4af3c93e66fcf853f67dfb33866044
-----BEGIN PUBLIC KEY-----
MCowBQYDK2VwAyEASmn08KLiL7ElA9KURvsKBRAxEX9tgY7Ow4hWi/kmeL8=
-----END PUBLIC KEY-----

Download public key (PEM)

Verify before installing

  1. Obtain the trust root from this official HTTPS manual page or a trusted Motrix version that independently pins the same key. A key supplied beside a downloaded archive is not its own trust anchor. Do not automatically replace a pinned key from a network response.
  2. Download only published releases from the repository above. Verify the manifest signature, repository, explicit tag, target, archive size and SHA-256 before extraction. Unsigned workflow artifacts are not releases.
  3. On macOS, also verify Developer ID signatures and notarization. Expected signing evidence comes from the already authenticated manifest. Windows builds use the project manifest signature, not Authenticode; this does not remove SmartScreen or antivirus warnings. Stop on a failed check or system warning; do not disable protections.

Follow the complete download verification procedure before extracting or running either executable.

Important

A valid signature establishes publisher-key possession and byte integrity, not that the executable or its media parsers are free of vulnerabilities. Do not install a self-signed root certificate, remove quarantine attributes, or bypass a failed verification.

Key history

The initial key below is designated for the first formal release and remains active until a documented rotation or revocation.

PublishedRecordRelease scope
2026-10-01Initial Ed25519 key published; active. Key ID: sha256:2b5d2575808c8c0ef2a9d616e994ccc96c4af3c93e66fcf853f67dfb33866044First formal release onward, until a documented rotation or revocation.

Future changes retain earlier records and state the affected release ranges. A routine rotation requires a reviewed Motrix pinned-key update before new-key releases. A compromised key must be explicitly revoked; never silently accept a replacement.

Report a suspected signature or key compromise privately.