// OPENBOX DOCS

Enterprise

License, signing, and verification for production use.

Enterprise

Use this page when you need to verify what you are running.

License

OpenBox Game Launcher is released under GNU Affero General Public License v3.0. Source is at vindeckyy/OpenBoxGL and the full text is at LICENSE. Trademark references to LaunchBox, Steam, Heroic, Lutris, RetroArch, and other third party products are used for compatibility description only. See Legal and trademarks and Disclaimer.

Signed releases

Every release is signed with Ed25519. On Linux the installer selects the matching AppImage architecture and verifies the release against a pinned public key and a published SHA-256 checksum. On Windows the release asset install.ps1 runs the same trust ladder: it fetches openbox-release.pub and checks its SHA-256 against a pinned bootstrap anchor (unless -PublicKeyPath is given), then verifies the archive's .sha256 sidecar and its Ed25519 .sig before extracting. Windows installs land under %LOCALAPPDATA%\OpenBox by default (-InstallDir or OPENBOX_INSTALL_DIR overrides it), with the previous tree kept at <InstallDir>\share\openbox.previous for rollback.

ArtifactWhat it isWhere to find it
OpenBox-x86_64.AppImagex86_64 release binaryReleases
OpenBox-x86_64.AppImage.sigx86_64 Ed25519 signatureSame release assets
OpenBox-aarch64.AppImageaarch64 release binarySame release assets
OpenBox-aarch64.AppImage.sigaarch64 Ed25519 signatureSame release assets
OpenBox-x86_64-windows.zipx86_64 Windows portable source tree under one OpenBox/ folderReleases
OpenBox-x86_64-windows.zip.sigWindows archive Ed25519 signatureSame release assets
OpenBox-x86_64-windows.zip.sha256Windows archive SHA-256 checksumSame release assets
openbox-release.pubPinned public keyApplication repository at openbox-release.pub, pinned by SHA-256 in scripts/install.sh and in the bootstrap anchor of scripts/install.ps1
OpenBox-x86_64.AppImage.sha256 and OpenBox-aarch64.AppImage.sha256Architecture-specific SHA-256 checksumsSame release assets
OpenBox-<version>-sbom.json and arch-suffixed SBOMCycloneDX 1.4 SBOMSame release assets
OpenBox-x86_64.flatpakx86_64 Flatpak bundleSame release assets
install.shCryptographically verified Linux installerSame release assets
install.ps1Cryptographically verified Windows installer (PowerShell 5.1, standard library only)Same release assets

Verify path: on Linux, download the AppImage matching your architecture, its .sig and .sha256, and the openbox-release.pub you pin, then run the installer with OPENBOX_RELEASE_TAG="v1.15.0" as shown in Downloads. The installer refuses a release when the key, checksum, or signature does not match. On Windows, download OpenBox-x86_64-windows.zip with its .sha256 and .sig and run the released install.ps1, which applies the same key-pin, checksum, and signature checks before extracting. The uninstaller is not a standalone release asset — it ships inside the zip and the installed tree, so it is run from the install at scripts\uninstall.ps1 (for a default install, %LOCALAPPDATA%\OpenBox\share\openbox\scripts\uninstall.ps1); it removes exactly what the installer created and never touches your library. See Updating for architecture-matched rollback and Windows for the platform guide.

Build and CI

SignalWhere to check
CI on push, pull request, and weeklyActions (Linux jobs plus a windows-latest job)
Lint, type, and test gatesmake check and scripts/check_tests.py
Release verificationtest_release_signing.py

The application uses only the Python standard library at runtime (plus ctypes on Windows). Build tooling is described in Project and policies.

Data and privacy

Library data is local JSON at ~/.local/share/openbox-game-launcher/library.json, or at %LOCALAPPDATA%\openbox-game-launcher\library.json on Windows. Set OPENBOX_DATA_DIR before launch to relocate it on either platform. The server binds to 127.0.0.1 on a random port, requires a per launch token on every request, and never listens on the network. No account, no vendor-hosted cloud, no telemetry. Local mounted-folder statistics and catalog synchronization remain opt-in. See Interfaces and data, Data and recovery, and Privacy.

Support and notices