Diagnosing Unverified Commits in TortoiseGit GPG Signing
Learn why TortoiseGit commits show as 'Unverified' on GitHub/GitLab and how to systematically check the GPG agent, key configuration, and TortoiseGit settings to restore signed commits.
25 Mar 2026, 17:03 UTC

Recognizable condition
After creating a commit with TortoiseGit, the commit appears as "Unverified" on the remote hosting service (e.g., GitHub, GitLab) and the TortoiseGit "Show Log" window does not display a GPG signature badge next to the commit message.
Cause & diagnostic table
| Possible cause | Check to perform | Expected result if healthy |
|---|---|---|
| GPG agent not running | Run gpgconf --launch gpg-agent then gpg-connect-agent /bye | Agent responds with "OK" and returns to prompt without error |
Missing or incorrect user.signingkey | Run git config --global --get user.signingkey | Outputs a key ID that matches a subkey capable of signing (listed by gpg --list-secret-keys --keyid-format LONG) |
TortoiseGit cannot find gpg.exe | Open TortoiseGit → Settings → General → Git executable path and verify the directory containing gpg.exe is in the system PATH | The path shown points to a valid gpg.exe file; where gpg (cmd) or which gpg (PowerShell) returns that location |
| Commit amended or created without signing | Inspect the TortoiseGit commit dialog for the "Sign commit" checkbox state | Checkbox is checked before committing |
Ordered diagnostic checks
- Verify GPG agent is active: Open a command prompt (no admin needed) and execute
gpgconf --launch gpg-agentfollowed bygpg-connect-agent /bye. If you see an error, start the agent manually or ensure it is launched by your login session. - Confirm TortoiseGit’s GPG program setting: In TortoiseGit → Settings → General, ensure the "Git executable" field points to a
git.exethat itself can locategpg.exe(usually via PATH). You can also set the full path togpg.exeunder Settings → General → "GPG executable" if TortoiseGit provides that field. - Check
user.signingkey: Rungit config --global --get user.signingkey. If empty, set it:git config --global user.signingkey. Verify the key has a signing subkey:gpg --list-secret-keys --keyid-format LONGshould show "sub rsa4096/... ... [S]" (the S flag indicates signing capability). - Test signing from the command line: In a repository folder, run
git -c gpg.program=gpg commit -S -m "test-sign" --allow-empty. If this succeeds andgit log --show-signatureshows "Good signature", the GPG toolchain works. - Inspect the TortoiseGit commit dialog: Right‑click → TortoiseGit → Commit… Ensure the "Sign commit" box is checked. Note that this setting is stored per‑repository in
.git/configundertortoisegit.signcommit; changing the global preference does not flip existing repos.
Fixes tied to findings
- Start or configure the GPG agent: If the agent is not running, launch it with
gpgconf --launch gpg-agent. For persistent availability, add the launch command to your login scripts or enable the "Start gpg-agent on login" option in tools like Gpg4win’s Kleopatra. - Set the signing key: Via TortoiseGit → Settings → Git → Config, add a global entry
user.signingkeywith your key ID, or edit%USERPROFILE%\.gitconfigdirectly. - Make
gpg.exediscoverable: Add the directory containinggpg.exe(e.g.,C:\Program Files (x86)\GnuPG\bin\) to the system PATH, or specify the full path in TortoiseGit → Settings → General → "GPG executable". - Enable signing per commit: In the commit dialog, check "Sign commit". To make it the default for a repository, run
git config tortoisegit.signcommit true(or check the box and click "Remember this setting"). - Use Pageant‑compatible agent: If you rely on Pageant for SSH keys, load the GPG private key into
gpg-agent(which can act as an SSH agent) or ensuregpg-agentis started with the--enable-ssh-supportflag.
Escalation criteria
If after completing the five checks and applying the corresponding fixes the commit still appears as "Unverified":
- Verify that the remote service actually has your GPG public key uploaded (GitHub → Settings → SSH and GPG keys; GitLab → Profile → GPG keys).
- Check for interference from antivirus or security software that may block
gpg.exe; temporarily disable such software to test. - Consider upgrading TortoiseGit and/or Gpg4win to the latest stable releases, as older versions had bugs in the GPG integration.
- Collect verbose output: run
GIT_TRACE=1 GIT_CURL_VERBOSE=1 git -c gpg.program=gpg commit -S -m "verbose" --allow-emptyand examine where the signing step fails. - If the problem persists, open a support ticket with TortoiseGit, providing the version numbers of TortoiseGit, Git, and Gpg4win, plus the verbose log.
Limitations and practical verification
The steps above assume a standard Windows installation with Gpg4win’s Kleopatra distribution. They do not cover smart‑card based GPG keys (e.g., YubiKey) beyond ensuring the agent supports the card interface.
To confirm a fix worked:
- Create a new commit with the "Sign commit" box checked.
- Run
git log --show-signature -1and look for a line beginning withGood signature from "followed by your key ID. - Push the commit to the remote and verify the web UI shows a "Verified" badge.
- Optionally, in TortoiseGit open "Show Log", right‑click the commit, and select "Verify Signature" to see the GUI verification result.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.