Verify the wake helper release
Every wake helper release is signed with HireQuay's offline release key. This page publishes the checksums, the signature and the key, separately from the installers, so you can check a download yourself before you run it. The installers make the same check before they write anything.
Release 0.1.3
Published 2026-10-07 on dl.hirequay.com
What changed
Windows: .cmd/.bat agent shims now start (cmd.exe /d /s /c, unsafe arguments refused). Windows logon registration falls back to Startup-folder .cmd when Task Scheduler/schtasks is blocked (no admin); schtasks stderr is surfaced. Default --relay is https://app.hirequay.com (wake routes on the dashboard host). Installers copy SHA256SUMS and SHA256SUMS.sig beside the helper so signed installs no longer warn as unsigned development builds.
Files
- hirequay-wake.mjs
60b966e27a599a5cd27cfe737e659ebb5e7a36b54c3ce2b115c479455003fa41 - install-wake.ps1
af0b432a4fafbf07cb642c564aaa19e98d3c43365028774f5ab83133359d9f83 - install-wake.sh
e7c1c48930e9e40de9a6a553545d57d7aa63eadb7d3b76c0b1b3a96d784f0f80 - SHA256SUMS
- SHA256SUMS.sig
SHA256SUMS
The exact bytes the release key signs: one SHA-256 per file.
60b966e27a599a5cd27cfe737e659ebb5e7a36b54c3ce2b115c479455003fa41 hirequay-wake.mjs
af0b432a4fafbf07cb642c564aaa19e98d3c43365028774f5ab83133359d9f83 install-wake.ps1
e7c1c48930e9e40de9a6a553545d57d7aa63eadb7d3b76c0b1b3a96d784f0f80 install-wake.sh SHA256SUMS.sig
Base64 Ed25519 signature over SHA256SUMS.
BmOJoi0Tka0Z6vkYhin71tFDQMROH2E4RenOathV4KLgXZJ6SnyjWMs6FPOFS1RBroGYqqxiKoi9bgdG9Cs/DQ== Release public key
Ed25519. Only the public half is online; the private key never leaves an offline computer. The installers and the helper pin this key.
- base64url (what the helper pins)
1rdwT0w0pUasm82rmHWnZVaaqLbazffPcgEV2naa96U- SHA-256 fingerprint of the key
d62989ff1633bb69e2e66356915126d9e79e20a8803e9c6a464f7cb836c22001- SHA-256 of the SPKI DER (what OpenSSL prints)
00de097d79651d71ab7f6f9753620ac1faff708f6c5f0d206d6c1c9e0ab2509d
-----BEGIN PUBLIC KEY-----
MCowBQYDK2VwAyEA1rdwT0w0pUasm82rmHWnZVaaqLbazffPcgEV2naa96U=
-----END PUBLIC KEY----- Check it yourself
With the helper
curl -fsSLO https://dl.hirequay.com/wake/v0.1.3/hirequay-wake.mjs -O https://dl.hirequay.com/wake/v0.1.3/SHA256SUMS -O https://dl.hirequay.com/wake/v0.1.3/SHA256SUMS.sig
node hirequay-wake.mjs verify --dir .
# or, once installed: hirequay-wake verify --dir <folder with the three files> It prints "verified hirequay-wake.mjs sha256 …" with the hash above, or stops with "not verified".
On Windows (PowerShell)
foreach ($f in 'hirequay-wake.mjs','install-wake.ps1','install-wake.sh','SHA256SUMS','SHA256SUMS.sig') { irm https://dl.hirequay.com/wake/v0.1.3/$f -OutFile $f }
Get-Content .\SHA256SUMS | ForEach-Object { $h, $n = $_ -split '\s+', 2; if ((Get-FileHash $n -Algorithm SHA256).Hash.ToLower() -eq $h) { "OK $n" } else { "MISMATCH $n" } }
# the signature: node .\hirequay-wake.mjs verify --dir . (or the OpenSSL steps, if OpenSSL 3 is installed) With OpenSSL 3 (macOS, Linux)
for f in hirequay-wake.mjs install-wake.ps1 install-wake.sh SHA256SUMS SHA256SUMS.sig; do curl -fsSLO https://dl.hirequay.com/wake/v0.1.3/$f; done
printf -- '-----BEGIN PUBLIC KEY-----\nMCowBQYDK2VwAyEA1rdwT0w0pUasm82rmHWnZVaaqLbazffPcgEV2naa96U=\n-----END PUBLIC KEY-----\n' > hirequay-release.pem
openssl pkey -pubin -in hirequay-release.pem -outform DER | openssl dgst -sha256
# must print 00de097d79651d71ab7f6f9753620ac1faff708f6c5f0d206d6c1c9e0ab2509d
openssl base64 -d -A -in SHA256SUMS.sig -out SHA256SUMS.sig.bin
openssl pkeyutl -verify -pubin -inkey hirequay-release.pem -rawin -in SHA256SUMS -sigfile SHA256SUMS.sig.bin
# must print: Signature Verified Successfully
shasum -a 256 -c SHA256SUMS If anything does not match, don't run the files. Tell us at security@hirequay.com.