Support
Get help with your autograph
The project's existing support community is 589 ManCave on Discord.
Axiom Risk Group support
Dev Autographs is operated by Axiom Risk Group LLC. Contact info@axiomriskgroup.com for product, privacy, billing or intellectual-property questions. The community remains available for general help.
Report a bug or ask a question
Include the component you used (desktop, CLI, web desk, registry, overlay or GitHub Action), your release version, operating system, the steps you took and the error shown. Remove private data from logs and screenshots before sharing them.
Never post an identity.json file, a generated setup file, private signing keys, GitHub tokens or device-login codes. Support does not need your private key.
Report a security issue privately
Please do not open a public issue with an exploitable vulnerability. Email info@axiomriskgroup.com with the subject Dev Autographs security report, or contact a maintainer privately in the support community. Include a description, reproduction steps and the affected version.
The repository's security policy describes the supported versions and disclosure process. Please allow time for remediation before public disclosure.
Use a local test registry and synthetic identities for security testing. Do not access other people's data or disrupt the hosted service.
Before retrying a failed setup
Use Node.js 20 or newer and Git. The web setup verifies the CLI release checksums before importing the key. Global hooks are installed only if you select that option before downloading setup. If verification, key protection or installation fails, read the error and retry after the cause is resolved; a failed run is not confirmation that hooks are installed.
A Windows identity protected by version 0.2.9 needs the original Windows user and a compatible CLI. Keep the existing identity if decryption fails; do not overwrite it with a new key or downgrade to version 0.2.8. The desktop stops a login when it cannot read its existing protected key.
A failed unlink leaves your browser identity available for another attempt. Removing browser storage by hand does not revoke exported copies of a signing key.