Web
Use Aura immediately in a modern browser — no install required.
Aura ships on four surfaces: the hosted web app, Android, macOS and Linux. There is no Windows build and no iOS app. Before you install anything, read the two warnings below — they are the difference between a download that works and one that your operating system refuses to open.
Use Aura immediately in a modern browser — no install required.
APK for sideloading, version 1.47.0 (101). Not on Google Play — see what that means.
Apple Silicon and Intel, version 0.1.0. Unsigned — macOS will block it until you clear the quarantine flag.
AppImage, Debian or RPM, version 0.1.0. Packages are unsigned; verify by checksum.
Detects your platform, fetches the current build into the current directory, and prints its SHA-256 so you can check it against the table below. It does not install anything, and it does not run the downloaded file.
curl -fsSL https://auratt.com/install.sh -o aura-download.sh && sh aura-download.sh
Downloaded to a file and run separately on purpose. Piping a script straight from a website into a shell asks you to execute code you never saw, on a page whose whole subject is what you are trusting — we are not going to recommend it here.
Aura's macOS builds are not code-signed with an Apple Developer certificate and not notarized by Apple. Our release pipeline has no signing step and no Apple credentials in it. That is a gap in our process, not a property of the app, and we would rather tell you than let you conclude the download is corrupt.
What you will see: on first open, macOS refuses. On recent versions the message is usually "Aura is damaged and can't be opened. You should move it to the Trash." That wording is misleading — nothing is damaged. macOS attaches a quarantine flag to anything downloaded from the internet, checks it for a valid signature and notarization ticket, finds neither, and reports it in the most alarming way it has.
Open the DMG, drag Aura to Applications, then in Terminal:
xattr -dr com.apple.quarantine /Applications/Aura.app
Then open the app normally. You only need to do this once per install.
Understand what that command does before you run it. It strips the flag that makes macOS check an app's signature — so it also disables the check that would have caught a tampered or substituted build. You are choosing to trust this download on our say-so instead of Apple's.
So do it in this order: verify the SHA-256 of the DMG first, then remove the quarantine flag. And never run that command on a path you did not download deliberately.
Prefer not to? The hosted web app needs no install — but read how its key custody differs first, because that trade-off is real too.
Aura is not published on Google Play. Downloading the APK here means installing an app from outside the store, and Android will make that clear at least twice.
Two independent checks, and both are worth doing on a first install:
Check the file you downloaded against the published SHA-256. Then, after installing, confirm the signing certificate. If you have Android's build tools:
apksigner verify --print-certs Aura-1.47.0-101.apk
It should report a certificate with subject CN=Aura, OU=Aura, O=Aura, C=US and this SHA-256 digest:
d2273bdfce115f3f07742e94f98d4a0547356071c9f5ebd1f3e43801566aa0af
That certificate is the thing your phone will hold Aura to for every future update. If a build claiming to be Aura shows a different one, it is not from us — do not install it, and please tell us.
None of these artifacts carry a code signature that your operating system will check for you (the APK is signed, but only against future updates of itself). The checksum below is the integrity check available today. It confirms that the bytes you received are the bytes we published — a download that was truncated, corrupted, or swapped in transit will not match.
On macOS or Linux:
shasum -a 256 Aura_0.1.0_aarch64.dmg
On Windows PowerShell (if you are checking a file for someone else — there is no Windows build):
Get-FileHash -Algorithm SHA256 .\Aura-1.47.0-101.apk
Compare the output to the matching row. Every character must match; if it does not, delete the file and download it again rather than trying to work out why.
| File | Size | SHA-256 |
|---|
Fetching the current checksums from the release server…
Be clear about what this does and does not prove. These hashes are computed by the same server that hands you the file, and fetched live so they always describe the build currently being served. That removes one failure — a checksum going stale against a newer build — but not the important one: anyone who could substitute the file could substitute the digest alongside it. A checksum published beside its own artifact catches corruption and a broken mirror; it is not a substitute for a signature you can verify independently, and we are not going to claim it is. Signed releases with detached signatures are the fix, and they are not done yet.
The Android app is at version 1.47.0 (101). The desktop builds are at version 0.1.0. That is not a mistake, and they are not the same application: Android is a mature, separately versioned app, while the desktop packages are early builds of the Aura web interface wrapped in a native shell. Treat the desktop version number as the honest signal it is.
Feature coverage differs accordingly. Appointments, group calls and push wake-up are Android-only today. The FAQ summarises what runs where.
Worth stating plainly, since the rest of this page is about mechanisms:
Found a problem with any of this? Report it, or see /.well-known/security.txt.