My Quick Notes

Ain't Nobody Got Time to Read

January 9, 2026

Git - Sign your commit with GPG key

Why should we sign git commit?

Git author name and email can easily be fake. Signing a commit will verify that the author is really you.

This practice also helps your commit look more trustworthy when contribute to open source projects.

What is GPG?

GPG (GNU Privacy Guard) is a free tool for encrypting, decrypting, and signing data. It ensures secure communication and data integrity by using public-key cryptography. GPG is commonly used for encrypting emails, signing software, and securely transmitting files. It’s widely supported and integrates with many systems to provide data security and authenticity verification.

How to sign a git commit?

Create GPG key

Ignore this step if you already have a GPG key.

Generate a GPG key pair:

gpg --full-generate-key

Email address should be set to same as your account on GitHub/Gitlab.

Get the secret key

  • List the long form of the GPG keys for which you have both a public and private key. A private key is required for signing commits or tags. From the list of GPG keys, copy the long form of the GPG key ID you'd like to use. In this example, the GPG key ID is 3AA5C34371567BD2:

    gpg --list-secret-keys --keyid-format=long
    /Users/hubot/.gnupg/secring.gpg
    ------------------------------------
    sec   4096R/3AA5C34371567BD2 2016-03-10 [expires: 2017-03-10]
    uid                          Hubot <hubot@example.com>
    ssb   4096R/4BB6D45482678BE3 2016-03-10
  • If the email in GPG key is already matched with your GitHub/Gitlab account, move to the next step. If not, add your email to your GPG key. Enter gpg --edit-key GPG_key_ID, substituting in the GPG key ID you'd like to use. In the following example, the GPG key ID is 3AA5C34371567BD2:

    gpg --edit-key 3AA5C34371567BD2
  • Enter adduid to add the user ID details:

    gpg> adduid
  • Follow the prompts to supply your real name, email address, and any comments. You can modify your entries by choosing N, C, or E:

    Real Name: OCTOCAT
    Email address: "hubot@example.com"
    Comment: GITHUB-KEY
    Change (N)ame, (C)omment, (E)mail or (O)kay/(Q)uit?
  • Save the changes:

    gpg> save

Add the public key to GitHub/Gitlab

  • Enter gpg --armor --export GPG_key_ID, substituting in the GPG key ID you'd like to use. In the following example, the GPG key ID is 3AA5C34371567BD2:

    gpg --armor --export 3AA5C34371567BD2
    # Prints the GPG key, in ASCII armor format
  • Add your public key to git server:

Commit

Now you can sign when commit with option -S :

git commit -S -m "commit"

or permanent enable in git config:

git config --global commit.gpgSign true  # execute once
git commit -m "commit"
PreviousImplement basic authentication in actix-web
NextUpgrade Fedora 42 to Fedora 43

Comments