FFmpeg Download Verification
FFmpeg is an optional component downloaded separately from Motrix. The builds maintained at motrixapp/ffmpeg-static are third-party builds for Motrix, not official FFmpeg binaries.
This manual page is the independent public-key reference for those builds. It does not certify that a release is available or free of vulnerabilities.
Public signing key
Algorithm: Ed25519. Authenticate the exact ffmpeg-manifest.json bytes before trusting any fields or hashes inside it.
The signature covers the following UTF-8 domain, including its final newline, followed by the unmodified manifest bytes. The code block shows the newline as \n:
Motrix FFmpeg release manifest v1\n
The key ID is SHA-256 of the public key’s SPKI DER encoding, not of the PEM text:
sha256:2b5d2575808c8c0ef2a9d616e994ccc96c4af3c93e66fcf853f67dfb33866044
-----BEGIN PUBLIC KEY-----
MCowBQYDK2VwAyEASmn08KLiL7ElA9KURvsKBRAxEX9tgY7Ow4hWi/kmeL8=
-----END PUBLIC KEY-----
Verify before installing
- Obtain the trust root from this official HTTPS manual page or a trusted Motrix version that independently pins the same key. A key supplied beside a downloaded archive is not its own trust anchor. Do not automatically replace a pinned key from a network response.
- Download only published releases from the repository above. Verify the manifest signature, repository, explicit tag, target, archive size and SHA-256 before extraction. Unsigned workflow artifacts are not releases.
- On macOS, also verify Developer ID signatures and notarization. Expected signing evidence comes from the already authenticated manifest. Windows builds use the project manifest signature, not Authenticode; this does not remove SmartScreen or antivirus warnings. Stop on a failed check or system warning; do not disable protections.
Follow the complete download verification procedure before extracting or running either executable.
Important
A valid signature establishes publisher-key possession and byte integrity, not that the executable or its media parsers are free of vulnerabilities. Do not install a self-signed root certificate, remove quarantine attributes, or bypass a failed verification.
Key history
The initial key below is designated for the first formal release and remains active until a documented rotation or revocation.
| Published | Record | Release scope |
|---|---|---|
| 2026-10-01 | Initial Ed25519 key published; active. Key ID: sha256:2b5d2575808c8c0ef2a9d616e994ccc96c4af3c93e66fcf853f67dfb33866044 | First formal release onward, until a documented rotation or revocation. |
Future changes retain earlier records and state the affected release ranges. A routine rotation requires a reviewed Motrix pinned-key update before new-key releases. A compromised key must be explicitly revoked; never silently accept a replacement.