Connector Upgrade Produces GPG Error in APT

Last updated: September 23, 2026

Overview

When updating a Twingate Connector installed on Ubuntu or Debian using APT, you may encounter a GPG or repository-signing error when running:

sudo apt update

Symptoms

When running sudo apt update, you may see the following warning or error:

W: GPG error: https://packages.twingate.com/apt InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 5C363F09A9174A9E

Older Twingate guidance worked around this issue by marking the APT repository as trusted. Twingate’s current Linux APT configuration instead installs Twingate’s GPG key into a dedicated keyring and associates the repository with that key using the signed-by option.

Cause

APT uses repository signing keys to verify that packages originate from a trusted source.
Older Twingate installations may have an outdated repository configuration or may not have the current Twingate signing key configured.


Twingate’s current Linux repository configuration uses a dedicated GPG keyring and the APT signed-by option to verify packages.

Resolution

  1. Ensure the required APT and GPG utilities are installed:

sudo apt install -y curl gpg ca-certificates
  1. Install the Twingate repository signing key

curl -fsSL https://packages.twingate.com/apt/gpg.key \
  | sudo gpg --dearmor -o /usr/share/keyrings/twingate-client-keyring.gpg

If you are prompted to replace an existing Twingate keyring, confirm the replacement.

  1. Update the Twingate repository configuration

echo "deb [signed-by=/usr/share/keyrings/twingate-client-keyring.gpg] https://packages.twingate.com/apt/ * *" \
  | sudo tee /etc/apt/sources.list.d/twingate.list

You can confirm the configuration with:

cat /etc/apt/sources.list.d/twingate.list

Note: Older guidance may reference adding trusted=true to the Twingate repository. This should not normally be required with the current signed repository configuration.

  1. Refresh APT

sudo apt update

The Twingate NO_PUBKEY error should no longer appear.

If the issue continues
Check for duplicate or outdated Twingate repository entries:

grep -R "packages.twingate.com" \
  /etc/apt/sources.list \
  /etc/apt/sources.list.d/ 2>/dev/null

If multiple Twingate repository entries are returned, review them for duplicate or conflicting configurations.