2026-09-30: Instance commit signing is now supported

CodeFloe now signs the commits it creates itself with its own SSH key. This makes branch protection with “Require signed commits” work end to end: pull requests into protected branches can be merged straight from the web UI while every commit on the branch stays verified.

The instance signs:

  • merge commits and squash commits created when merging a pull request,
  • commits made in the web editor,
  • the first commit of a new repository.

These commits are credited to the CodeFloe organization as committer and signer, and you stay the author:

The instance only signs a merge when the person merging has an SSH or GPG key on their account and two-factor authentication enabled. The latest commit on the target branch and every commit in the pull request must also be verified. The rebase merge styles rewrite commits without re-signing them, so use “Create merge commit” or “Create squash commit” on protected branches.

The public key is available at https://codefloe.com/api/v1/signing-key.ssh (fingerprint SHA256:PKT+oTn3Be7QgSZOB/sIKe5wW7rTFdekSZbuEMYGS0E). The commit signing docs explain how to verify these signatures locally and what to check if a merge doesn’t get signed.

Thanks to @wcornish for suggesting this!