Hello,
Currently, when enforcing a branch protection policy with “Require signed commits”, merge commits made by the instance are not signed and thus cannot be performed.

Adding a signing key to the codefloe instance would be a great help to the workflow of repositories which enforce such policies.
CodeFloe now has an instance signing key, so pull requests into branches with “Require signed commits” can be merged from the web UI again.
The instance signs the commits it creates itself with an SSH key:
- merge commits and squash commits created when merging a pull request (the rebase merge styles rewrite commits without re-signing them, so use “Create merge commit” or “Create squash commit” on protected branches),
- commits made in the web editor,
- the first commit of a new repository.
These show up as verified, signed by “CodeFloe”.
On instance-signed merges, CodeFloe is the committer and the person who merged is the author.
To keep that signature meaningful, the instance only signs a merge when all of these are true:
- the person merging has an SSH or GPG key added to their account,
- the person merging has two-factor authentication enabled,
- the latest commit on the target branch is verified,
- every commit in the pull request is verified.
If any of these is missing, the merge stays blocked, same as before.
For a repository that requires signed commits, that normally means everyone signs their own commits and the maintainer who merges has 2FA enabled.
The public key is available at https://codefloe.com/api/v1/signing-key.ssh, fingerprint SHA256:PKT+oTn3Be7QgSZOB/sIKe5wW7rTFdekSZbuEMYGS0E.
To verify instance-signed commits locally, add it to your git allowed signers file:
# trust the CodeFloe instance key for commit signatures
echo 'noreply@codefloe.com namespaces="git" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIVvuV29MZN7nTTG6sZM0f++/KVoL7Lr+8IwiNVpla6k' >> ~/.config/git/allowed_signers
# point git at that file if you have not already
git config --global gpg.ssh.allowedSignersFile ~/.config/git/allowed_signers
All of this, plus a troubleshooting checklist for merges that stay blocked, is now in the docs: Commit Signing | CodeFloe
Let us know if anything still gets blocked!
Thanks very much for that, this has solved my workflow issue.