For AI agents: a documentation index is available at https://www.mongodb.com/docs/llms.txt — markdown versions of all pages are available by appending .md to any URL path.
See how MongoDB 9.0 delivers up to 2x higher throughput.
MongoDB Branding Shape
Register now >
Docs Menu

Verify Integrity of mongot Packages

The MongoDB search release team digitally signs all software packages to certify that a particular mongot package is a valid and unaltered mongot release. Before installing mongot, you should validate the container image or the tarball.

1

If you don't already have Cosign installed, follow the cosign installation instructions.

On macOS with Homebrew, run the following command:

brew install cosign
2

Run the following command to save the PEM file as mongodb-search-community.pem:

curl -fsSL https://cosign.mongodb.com/mongodb-search-community.pem -o mongodb-search-community.pem
3

Replace {VERSION_NUMBER} with the version of the mongot container image from Docker Hub and run the following command to verify the container image:

COSIGN_REPOSITORY=docker.io/mongodb/signatures cosign verify --insecure-ignore-tlog --key=./mongodb-search-community.pem "docker.io/mongodb/mongodb-community-search:{VERSION_NUMBER}"

The output should be similar to the following:

Verification for index.docker.io/mongodb/mongodb-community-search:latest --
The following checks were performed on each of these signatures:
- The cosign claims were validated
- The signatures were verified against the specified public key
[{"critical":{"identity":{"docker-reference":"docker.io/mongodb/mongodb-community-search:latest"},
"image":{"docker-manifest-digest":"sha256:b41f73a33aa62a62596b6aeaf4c177e47dc3a5901701f6d8d46f498a45f7ac53"},
"type":"cosign container image signature"},"optional":null}]
1

Run the following command to save the PGP key as atlas-search.asc:

curl -fsSL https://pgp.mongodb.com/atlas-search.asc -o atlas-search.asc
2
gpg --import atlas-search.asc
3

Replace {VERSION_NUMBER} with the version of mongot that you want to verify and run the following commands to download both the tarball and its signature for your system architecture.

curl -fsSL https://downloads.mongodb.org/mongodb-search-community/{VERSION_NUMBER}/mongot_community_{VERSION_NUMBER}_linux_aarch64.tgz -o mongot_community_{VERSION_NUMBER}_linux_aarch64.tgz
curl -fsSL https://downloads.mongodb.org/mongodb-search-community/{VERSION_NUMBER}/mongot_community_{VERSION_NUMBER}_linux_aarch64.tgz.sig -o mongot_community_{VERSION_NUMBER}_linux_aarch64.tgz.sig
curl -fsSL https://downloads.mongodb.org/mongodb-search-community/{VERSION_NUMBER}/mongot_community_{VERSION_NUMBER}_linux_x86_64.tgz -o mongot_community_{VERSION_NUMBER}_linux_x86_64.tgz
curl -fsSL https://downloads.mongodb.org/mongodb-search-community/{VERSION_NUMBER}/mongot_community_{VERSION_NUMBER}_linux_x86_64.tgz.sig -o mongot_community_{VERSION_NUMBER}_linux_x86_64.tgz.sig

To download a different version, replace instances of {VERSION_NUMBER} with the desired version number.

4

Replace {VERSION_NUMBER} with your version of mongot and run the following command to verify the tarball:

gpg --verify mongot_community_{VERSION_NUMBER}_linux_aarch64.tgz.sig mongot_community_{VERSION_NUMBER}_linux_aarch64.tgz
gpg --verify mongot_community_{VERSION_NUMBER}_linux_x86_64.tgz.sig mongot_community_{VERSION_NUMBER}_linux_x86_64.tgz

To verify a different version, replace instances of {VERSION_NUMBER} with the desired version number.

The output should be similar to the following:

gpg: Signature made Fri Sep 5 15:37:47 2025 PDT
gpg: using RSA key 55C58636FD6CEE2B789B6F49516C2412904B6C26
gpg: Good signature from "MongoDB Atlas Search Release Signing Key <packaging@mongodb.com>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: 55C5 8636 FD6C EE2B 789B 6F49 516C 2412 904B 6C26