Ed25519 is recommended - modern, fast, compact. ECDSA P-256 works on older browsers.
Runs 100% client-side - keys, messages and signatures never leave your browser.
(Tài liệu bằng tiếng Anh)
What it does
The Digital Signature tool proves who wrote a message without revealing any secret. It generates a real asymmetric key pair - Ed25519 or ECDSA P-256 - in your browser, signs any text with the private key, and verifies signatures with the matching public key. A valid signature is mathematical proof that the holder of the private key signed exactly this message: change one character of the message, or verify with any other key, and the check fails. This property is called non-repudiation - unlike a shared password, the signer cannot later deny having signed, because only their private key could have produced the signature.
Everything runs through the browser’s Web Crypto API. Keys are generated locally, exported as standard hex-encoded DER (SPKI public / PKCS8 private), and never touch a server. Both algorithms produce compact 64-byte signatures over the SHA-256 digest (ECDSA) or the raw message (Ed25519).
How to use it
- Pick an algorithm - Ed25519 (recommended: modern, fast, deterministic signatures) or ECDSA P-256 (best old-browser support).
- On Generate, press Generate key pair. Copy the public key (share freely) and the private key (keep secret).
- On Sign, paste the private key, type the message, press Sign message. Copy the hex signature.
- On Verify, paste the public key, the message, and the signature, then press Verify signature. A green badge means the signature is authentic; a red badge means the message, signature, or key does not match.
Examples
Sign and verify round-trip (Ed25519):
message: "Invoice #42, total $1,200 - GΛB"
signature: 9a3f…(128 hex chars = 64 bytes)
verify with the signer's public key → ✅ Valid signature
Tampered message:
message: "Invoice #42, total $9,200 - GΛB" ← one digit changed
same signature + same public key → ❌ Invalid signature
Wrong key:
verify the original signature with ANY other public key → ❌ Invalid signature
Good to know
- Zero server contact: keys, messages and signatures exist only in your browser tab. Nothing is uploaded, logged, or stored. You can sign offline.
- Ed25519 vs ECDSA P-256: Ed25519 is the modern default - fast verification, deterministic signatures (the same message + key always yields the same bytes), 64-byte signatures, and resistance to side-channel pitfalls. ECDSA P-256 (over SHA-256) is the NIST curve with the widest support in older browsers and smartcards. Both are considered secure; Ed25519 is the better ergonomic choice when available.
- The private key is the identity. There is no revocation and no recovery: anyone who obtains your private key can sign as you. Generate keys for real use in a trusted environment and store them encrypted.
- Interop note: ECDSA signatures here are in the raw IEEE P1363
r||slayout that Web Crypto uses - notASNASNA number identifying one routing domain on the internet (one AS = one network under a single policy), used by BGP to exchange routes.Learn more
.1 DER. OpenSSL users needopenssl pkeyutl -rawin/ conversion to compare against DER signatures. Ed25519 signatures are the standard RFC 8032 64-byte format everywhere. - Signatures prove authorship, not secrecy. The message stays in the clear - to hide content, combine with the File Encryptor. For shared-secret (symmetric) message authentication instead of public-key proof, see the
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
Generator. - Related tools:
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
Generator, File Encryptor,HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
Generator.