# 2026-09-30: Instance commit signing is now supported

**URL:** <https://forum.codefloe.com/t/2026-09-30-instance-commit-signing-is-now-supported/203>\
**Category:** Announcements\
**Tags:** changelog\
**Created:** [September 30, 2026, 3:55pm UTC](https://forum.codefloe.com/t/2026-09-30-instance-commit-signing-is-now-supported/203 "2026-09-30T15:55:51Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![codefloe](https://forum.codefloe.com/user_avatar/forum.codefloe.com/codefloe/32/42_2.png) [@codefloe](https://forum.codefloe.com/u/codefloe)\
**Post date:** [September 30, 2026, 3:55pm UTC](https://forum.codefloe.com/t/2026-09-30-instance-commit-signing-is-now-supported/203/1 "2026-09-30T15:55:51Z")

</div>

CodeFloe now signs the commits it creates itself with its own SSH key. This makes branch protection with “Require signed commits” work end to end: pull requests into protected branches can be merged straight from the web UI while every commit on the branch stays verified.

The instance signs:

- merge commits and squash commits created when merging a pull request,
- commits made in the web editor,
- the first commit of a new repository.

These commits are credited to the [CodeFloe organization](https://codefloe.com/codefloe) as committer and signer, and you stay the author:

 ![image](https://cdn.forum.codefloe.com/original/1X/db368495888991e1524cc6a58829e240c0ee7710.png)

The instance only signs a merge when the person merging has an SSH or GPG key on their account and two-factor authentication enabled. The latest commit on the target branch and every commit in the pull request must also be verified. The rebase merge styles rewrite commits without re-signing them, so use “Create merge commit” or “Create squash commit” on protected branches.

The public key is available at [https://codefloe.com/api/v1/signing-key.ssh](https://codefloe.com/api/v1/signing-key.ssh) (fingerprint `SHA256:PKT+oTn3Be7QgSZOB/sIKe5wW7rTFdekSZbuEMYGS0E`). The [commit signing docs](https://docs.codefloe.com/usage/commit-signing/) explain how to verify these signatures locally and what to check if a merge doesn’t get signed.

Thanks to @wcornish for [suggesting this](https://forum.codefloe.com/t/instance-signing-key/199)!
