Begin with provenance
The safest installation starts before the file reaches your device. Session’s primary download page is getsession.org/download, and desktop releases are also published through the project’s official GitHub organization. A familiar filename in a forum attachment or file-sharing link says nothing about who built it or whether it was altered. Check the domain first and keep the release details with the installer. Imitation pages often rely on haste rather than technical sophistication.
Choose the package for your platform
iPhone users should follow the official link to the App Store. Android users may choose the store build, official APK, or F-Droid route according to their needs. Windows, macOS, and Linux users should match both operating system and processor architecture. Avoid “unlocked” or “optimized” packages from third parties: they can add code, suppress updates, or change network behavior without an obvious warning.
Verify when the stakes are higher
An official store or website is sufficient for many people. Journalists, researchers, administrators, and users facing targeted attacks should go further by comparing published hashes or signatures and checking release notes through a separate trusted channel. Verification answers two narrow but important questions: did the expected publisher release this file, and did the file change on its way to you?
Get Session from an official source
Before installing, confirm that the download page uses the getsession.org domain.
Open official downloads ↗
Guide