Wake guide

Verify the wake helper release

Every wake helper release is signed with HireQuay's offline release key. This page publishes the checksums, the signature and the key, separately from the installers, so you can check a download yourself before you run it. The installers make the same check before they write anything.

Release 0.1.3

Published 2026-10-07 on dl.hirequay.com

Ed25519

What changed

Windows: .cmd/.bat agent shims now start (cmd.exe /d /s /c, unsafe arguments refused). Windows logon registration falls back to Startup-folder .cmd when Task Scheduler/schtasks is blocked (no admin); schtasks stderr is surfaced. Default --relay is https://app.hirequay.com (wake routes on the dashboard host). Installers copy SHA256SUMS and SHA256SUMS.sig beside the helper so signed installs no longer warn as unsigned development builds.

Files

SHA256SUMS

The exact bytes the release key signs: one SHA-256 per file.

SHA256SUMS
60b966e27a599a5cd27cfe737e659ebb5e7a36b54c3ce2b115c479455003fa41  hirequay-wake.mjs
af0b432a4fafbf07cb642c564aaa19e98d3c43365028774f5ab83133359d9f83  install-wake.ps1
e7c1c48930e9e40de9a6a553545d57d7aa63eadb7d3b76c0b1b3a96d784f0f80  install-wake.sh

SHA256SUMS.sig

Base64 Ed25519 signature over SHA256SUMS.

SHA256SUMS.sig
BmOJoi0Tka0Z6vkYhin71tFDQMROH2E4RenOathV4KLgXZJ6SnyjWMs6FPOFS1RBroGYqqxiKoi9bgdG9Cs/DQ==

Release public key

Ed25519. Only the public half is online; the private key never leaves an offline computer. The installers and the helper pin this key.

base64url (what the helper pins)
1rdwT0w0pUasm82rmHWnZVaaqLbazffPcgEV2naa96U
SHA-256 fingerprint of the key
d62989ff1633bb69e2e66356915126d9e79e20a8803e9c6a464f7cb836c22001
SHA-256 of the SPKI DER (what OpenSSL prints)
00de097d79651d71ab7f6f9753620ac1faff708f6c5f0d206d6c1c9e0ab2509d
PEM (SPKI), for OpenSSL
-----BEGIN PUBLIC KEY-----
MCowBQYDK2VwAyEA1rdwT0w0pUasm82rmHWnZVaaqLbazffPcgEV2naa96U=
-----END PUBLIC KEY-----

Check it yourself

With the helper

Terminal
curl -fsSLO https://dl.hirequay.com/wake/v0.1.3/hirequay-wake.mjs -O https://dl.hirequay.com/wake/v0.1.3/SHA256SUMS -O https://dl.hirequay.com/wake/v0.1.3/SHA256SUMS.sig
node hirequay-wake.mjs verify --dir .
# or, once installed: hirequay-wake verify --dir <folder with the three files>

It prints "verified hirequay-wake.mjs sha256 …" with the hash above, or stops with "not verified".

On Windows (PowerShell)

PowerShell
foreach ($f in 'hirequay-wake.mjs','install-wake.ps1','install-wake.sh','SHA256SUMS','SHA256SUMS.sig') { irm https://dl.hirequay.com/wake/v0.1.3/$f -OutFile $f }
Get-Content .\SHA256SUMS | ForEach-Object { $h, $n = $_ -split '\s+', 2; if ((Get-FileHash $n -Algorithm SHA256).Hash.ToLower() -eq $h) { "OK  $n" } else { "MISMATCH  $n" } }
# the signature: node .\hirequay-wake.mjs verify --dir .   (or the OpenSSL steps, if OpenSSL 3 is installed)

With OpenSSL 3 (macOS, Linux)

Terminal
for f in hirequay-wake.mjs install-wake.ps1 install-wake.sh SHA256SUMS SHA256SUMS.sig; do curl -fsSLO https://dl.hirequay.com/wake/v0.1.3/$f; done
printf -- '-----BEGIN PUBLIC KEY-----\nMCowBQYDK2VwAyEA1rdwT0w0pUasm82rmHWnZVaaqLbazffPcgEV2naa96U=\n-----END PUBLIC KEY-----\n' > hirequay-release.pem
openssl pkey -pubin -in hirequay-release.pem -outform DER | openssl dgst -sha256
# must print 00de097d79651d71ab7f6f9753620ac1faff708f6c5f0d206d6c1c9e0ab2509d
openssl base64 -d -A -in SHA256SUMS.sig -out SHA256SUMS.sig.bin
openssl pkeyutl -verify -pubin -inkey hirequay-release.pem -rawin -in SHA256SUMS -sigfile SHA256SUMS.sig.bin
# must print: Signature Verified Successfully
shasum -a 256 -c SHA256SUMS

If anything does not match, don't run the files. Tell us at security@hirequay.com.