Every screen, one Aura

Take your identity with you.

Aura ships on four surfaces: the hosted web app, Android, macOS and Linux. There is no Windows build and no iOS app. Before you install anything, read the two warnings below — they are the difference between a download that works and one that your operating system refuses to open.

Two things you need to know before downloading.

1. The macOS builds are not code-signed or notarized. macOS will refuse to open them, most likely with the message "Aura is damaged and can't be opened." The app is not damaged; it is unsigned. The workaround is below — but understand what you are doing before you use it.

2. The Android app is not on Google Play. You install it as an APK, which means turning on "install from unknown sources" and clicking past a Play Protect warning. What that means is below.

Verify what you downloaded against the published SHA-256 checksums. It is the only integrity check available on these builds today.

Web

Use Aura immediately in a modern browser — no install required.

Android

APK for sideloading, version 1.47.0 (101). Not on Google Play — see what that means.

Link is generated fresh for each download and expires after a few minutes.

macOS

Apple Silicon and Intel, version 0.1.0. Unsigned — macOS will block it until you clear the quarantine flag.

Link is generated fresh for each download and expires after a few minutes.

Linux

AppImage, Debian or RPM, version 0.1.0. Packages are unsigned; verify by checksum.

Link is generated fresh for each download and expires after a few minutes.

Download by script — macOS & Linux

Detects your platform, fetches the current build into the current directory, and prints its SHA-256 so you can check it against the table below. It does not install anything, and it does not run the downloaded file.

curl -fsSL https://auratt.com/install.sh -o aura-download.sh && sh aura-download.sh

Downloaded to a file and run separately on purpose. Piping a script straight from a website into a shell asks you to execute code you never saw, on a page whose whole subject is what you are trusting — we are not going to recommend it here.

macOS: the builds are unsigned, and macOS will say so

Aura's macOS builds are not code-signed with an Apple Developer certificate and not notarized by Apple. Our release pipeline has no signing step and no Apple credentials in it. That is a gap in our process, not a property of the app, and we would rather tell you than let you conclude the download is corrupt.

What you will see: on first open, macOS refuses. On recent versions the message is usually "Aura is damaged and can't be opened. You should move it to the Trash." That wording is misleading — nothing is damaged. macOS attaches a quarantine flag to anything downloaded from the internet, checks it for a valid signature and notarization ticket, finds neither, and reports it in the most alarming way it has.

The workaround

Open the DMG, drag Aura to Applications, then in Terminal:

xattr -dr com.apple.quarantine /Applications/Aura.app

Then open the app normally. You only need to do this once per install.

Understand what that command does before you run it. It strips the flag that makes macOS check an app's signature — so it also disables the check that would have caught a tampered or substituted build. You are choosing to trust this download on our say-so instead of Apple's.

So do it in this order: verify the SHA-256 of the DMG first, then remove the quarantine flag. And never run that command on a path you did not download deliberately.

Prefer not to? The hosted web app needs no install — but read how its key custody differs first, because that trade-off is real too.

Android: this is a sideload, not a Play Store install

Aura is not published on Google Play. Downloading the APK here means installing an app from outside the store, and Android will make that clear at least twice.

What you will see

  1. "For your security, your phone is not allowed to install unknown apps from this source." Android asks you to grant install permission to the app you are downloading with — usually your browser or file manager. This is a per-source permission; turn it back off afterwards if you like.
  2. A Play Protect warning along the lines of "unsafe app blocked" or "app not scanned". Play Protect flags anything it has not seen distributed through Play. It is not a verdict about Aura; it is a statement that Google has no history for this package.

What sideloading actually costs you

  • No automatic updates. Play would update the app in the background. Here, you return to this page and install a newer APK yourself — including for a security fix. This is the real cost, and it is easy to underestimate.
  • No store review of the build you are installing, and no store-side integrity guarantee.
  • Upgrades must be signed by the same key. Android will refuse to install an update signed by a different key, which is the mechanism that stops someone else's "Aura" replacing ours. It also means that if you install a fake Aura first, the real one cannot replace it — you would have to uninstall, losing local data.

Confirm the APK really is ours

Two independent checks, and both are worth doing on a first install:

Check the file you downloaded against the published SHA-256. Then, after installing, confirm the signing certificate. If you have Android's build tools:

apksigner verify --print-certs Aura-1.47.0-101.apk

It should report a certificate with subject CN=Aura, OU=Aura, O=Aura, C=US and this SHA-256 digest:

d2273bdfce115f3f07742e94f98d4a0547356071c9f5ebd1f3e43801566aa0af

That certificate is the thing your phone will hold Aura to for every future update. If a build claiming to be Aura shows a different one, it is not from us — do not install it, and please tell us.

Verify your download

None of these artifacts carry a code signature that your operating system will check for you (the APK is signed, but only against future updates of itself). The checksum below is the integrity check available today. It confirms that the bytes you received are the bytes we published — a download that was truncated, corrupted, or swapped in transit will not match.

On macOS or Linux:

shasum -a 256 Aura_0.1.0_aarch64.dmg

On Windows PowerShell (if you are checking a file for someone else — there is no Windows build):

Get-FileHash -Algorithm SHA256 .\Aura-1.47.0-101.apk

Compare the output to the matching row. Every character must match; if it does not, delete the file and download it again rather than trying to work out why.

Fetching the current checksums from the release server…

Be clear about what this does and does not prove. These hashes are computed by the same server that hands you the file, and fetched live so they always describe the build currently being served. That removes one failure — a checksum going stale against a newer build — but not the important one: anyone who could substitute the file could substitute the digest alongside it. A checksum published beside its own artifact catches corruption and a broken mirror; it is not a substitute for a signature you can verify independently, and we are not going to claim it is. Signed releases with detached signatures are the fix, and they are not done yet.

Why the version numbers don't match

The Android app is at version 1.47.0 (101). The desktop builds are at version 0.1.0. That is not a mistake, and they are not the same application: Android is a mature, separately versioned app, while the desktop packages are early builds of the Aura web interface wrapped in a native shell. Treat the desktop version number as the honest signal it is.

Feature coverage differs accordingly. Appointments, group calls and push wake-up are Android-only today. The FAQ summarises what runs where.

What you're trusting when you install this

Worth stating plainly, since the rest of this page is about mechanisms:

  • That these binaries were built from the source they claim to be built from. There are no reproducible builds and no third-party attestation. You are trusting our release process.
  • That this website has not been tampered with, since both the download links and the checksums come from it.
  • For macOS and Linux: that skipping the OS's own signature check is acceptable to you. It is a real reduction in protection, and it applies to every unsigned app, not only ours.
  • For Android: that you will come back for updates yourself. Nothing will prompt you.
  • For the hosted web app: that we do not read your messages. On that surface the keys are on our servers — see the security page. Installing a native app is how you stop needing to trust us about that.

Found a problem with any of this? Report it, or see /.well-known/security.txt.