← Back to HQ

Alien apps on the Linux desktop: install and verify the Flatpak

by Alien Investor

Three of my apps have been available for the Linux desktop since September 2026: Alien Pass (since v1.7), the Sachwert-Tresor (since v3.3) and Alien Notes (since v0.1). All three run as a Flatpak (x86_64) with the same shell: no network, no file access, files only through the system dialog. They are deliberately not on Flathub and do not update themselves — you download the file from the Codeberg release, verify the signature and install it yourself. This page shows the way once for all three apps.

1. Prerequisite: Flatpak with Flathub

The apps need the runtime org.freedesktop.Platform 25.08, which Flatpak fetches from Flathub during installation. Once, as a user (no root, no sudo):

flatpak remote-add --user --if-not-exists flathub https://dl.flathub.org/repo/flathub.flatpakrepo

2. Download three files from the release

From the latest release on Codeberg you need the bundle, the checksum file and its signature:

An -rN in the file name (such as alien-pass-1.8-r2-…) is a rebuild of the shell with the app unchanged.

3. Verify authenticity: GPG-signed checksum

The file SHA256SUMS is signed with the Alien Investor GPG release key — the same key for all desktop apps. The public part is here on the website (alien-investor-release-key.asc) and in all three repos. Compare the fingerprint through a second channel before trusting the key:

100F 9E25 BFAE A807 DBC3  57D7 50C0 D785 83BF CB81
gpg --show-keys alien-investor-release-key.asc   # prints the fingerprint — compare with the line above
gpg --import alien-investor-release-key.asc
gpg --verify SHA256SUMS.asc SHA256SUMS      # expected: Good signature from "Alien Investor (Release-Signatur) …"
sha256sum -c SHA256SUMS                     # expected: …flatpak: OK

The checksum is signed, not the bundle itself — hence both commands: gpg --verify proves the checksum comes from me, sha256sum -c proves the bundle matches that checksum. If either fails, do not install.

4. Install and run

flatpak install --user alien-pass-X.Y-linux-x86_64.flatpak
flatpak run org.alieninvestor.pass
flatpak install --user sachwert-tresor-X.Y-linux-x86_64.flatpak
flatpak run org.alieninvestor.tresor
flatpak install --user alien-notes-X.Y-linux-x86_64.flatpak
flatpak run org.alieninvestor.notes

The apps then appear in the application menu. A backup from the phone (.vault, for Alien Notes .notes) is imported through the file dialog — the format is identical.

5. Update: uninstall, reinstall

Flatpak (as of 1.14) does not install a new bundle over an existing installation. Download and verify the new version (steps 2 and 3), then:

flatpak uninstall --user org.alieninvestor.pass       # deletes NO data (without --delete-data)
flatpak install --user alien-pass-X.Y-linux-x86_64.flatpak

For the vault the same with org.alieninvestor.tresor, for Alien Notes with org.alieninvestor.notes. Your data stays in place:

Still make a backup before every update. Close a running window first — otherwise the old version keeps running.

6. Check for yourself that the app has no network

flatpak info --user --show-permissions org.alieninvestor.pass

Expected exactly this output (identical for the vault and for Alien Notes):

[Context]
shared=ipc;
sockets=wayland;fallback-x11;
devices=dri;

No network, no filesystem. This is not a setting inside the app but the system itself: inside the Flatpak sandbox there is no network without the network permission, and the app only reaches files you pick in the dialog.

What the desktop version can do — and where its limits are

Details per app: Alien Pass on the desktop · Sachwert-Tresor on the desktop · Alien Notes on the desktop.

Sources & links

Further reading

On the phone the same apps run without Google Play: Obtainium pulls updates straight from Codeberg, the Zap Store distributes them over Nostr. All apps: Apps.


Recharge (Donate)

Send fuel to the mothership

Thanks for your support — for free content, financial sovereignty, and the extraterrestrial resistance!