File Signature Workbench

File Signature Workbench

Browser-local digital signatures · no upload. A valid signature needs an independently trusted public key before you can name a signer.

1. Choose task

File up to 16 MiB · detached manifest up to 8 KiB · key JSON up to 4 KiB · version 1 ECDSA P-256 / SHA-256 only.

2. Signing key

A new key stays in this tab until you leave. Download the unencrypted private JSON explicitly if you need to keep it; a public key alone cannot sign.

3. Select file and signature

Choose a task and local files.

Comments & questions

File Signature Workbench

This tool signs a bounded local file with a user-held ECDSA P-256 private key. The detached version 1 JSON manifest records the exact filename, byte length, SHA-256 digest and public key; its canonical fields are signed with SHA-256 ECDSA. Verification rereads the selected file and checks both its digest and the signature. A plain checksum cannot authenticate the key holder. This format is specific to this site and is not a PDF/CMS signature or certificate.

Key features

  • Generate a signing key or import a local P-256 private JWK
  • Sign exact local bytes and bind filename, size, SHA-256 and public key
  • Download a detached version 1 .ttsig.json manifest and public JWK
  • Verify a received file and reject changed bytes, damaged signatures and wrong keys
  • Compare the SHA-256 fingerprint of the public key through an independent trusted channel

How to use

  1. Choose Sign, create or import a local signing key, and select a file up to 16 MiB.
  2. Sign and download the detached .ttsig.json manifest; share the public key separately if the verifier needs an independent comparison.
  3. Protect the private-key JSON if you explicitly choose to export it. It is not encrypted.
  4. Choose Verify, select the original file and its detached manifest, and optionally select the public JWK received through another channel.
  5. Read the byte-integrity and signature result, then compare the public-key fingerprint with a trusted source before attributing an identity.

Use cases

  • Detect whether a small delivered binary changed after signing
  • Share a detached signature alongside a file without embedding it in the file
  • Check a release artifact against a public key already known to your team
  • Demonstrate why a checksum and an authenticated public key answer different questions

Frequently asked questions

Does a successful check prove who signed the file?

No. A manifest can include any self-generated public key. It proves that the matching private key signed these fields, but identity needs a separately trusted key or fingerprint.

Can the key in the manifest be replaced?

The public key is inside the signed payload. Replacing it without resigning fails verification. An attacker could still create a new key and new manifest, so compare a separately obtained trusted key.

Does renaming the file affect verification?

Yes. The exact filename and byte length are signed along with the SHA-256 digest. Renaming or changing one byte requires a new signature.

Is the exported private key protected by a password?

No. The private JWK is unencrypted JSON and is downloaded only after a separate acknowledgement. Anyone who gets it can sign files under that key.

Can I use the manifest with PDF/CMS/OpenSSL tools?

The cryptographic operation is Web Crypto ECDSA P-256 with SHA-256 and P1363 signatures. The surrounding canonical JSON manifest is this site's own version 1 format, not PDF/CMS or an OpenSSL detached-signature container.

What limits apply?

Files are limited to 16 MiB, manifests to 8 KiB and key JSON to 4 KiB. Files are read in browser memory; large files and unsupported Web Crypto browsers are not accepted.

Privacy

File and key bytes stay in this browser tab's memory. Nothing is uploaded or automatically stored. The private key is exported only after you explicitly acknowledge that its JSON download is unencrypted. Keep that file private and backed up; anyone with it can sign as this key.

References

Related Tools

Hash GeneratorFile Manifest VerifierSignature & Stamp MakerWasm Module InspectorHreflang Matrix CheckerAST Query PlaygroundContainer Build GraphDependency Graph ExplorerSemver Range LabCron Schedule AuditorPatch Review WorkbenchSource Map ExplorerLocalization Catalog AuditorStructured Data ReviewerHTTP Archive AnalyzerWebhook Signature LabProtobuf Schema WorkbenchGraphQL Schema LabAvro Schema EvolutionLocal SQL WorkbenchSchema Form BuilderMesh Repair WorkbenchPipe Network LabRobot Arm Kinematics LabThermal Network LabBeam Response LabGear Train DesignerTolerance Stackup LabSensor Calibration FitPCB Stackup PlannerDigital Filter DesignerNetwork Reachability MapSun Shadow MapGPS Error SimulatorDigital Logic SimulatorAnalog Circuit LabMechanism Linkage LabAnalysis Mesh GeneratorOpenAPI Contract InspectorDatabase Migration PlannerDimensional Equation CheckerTruss Force LabBoolean Minimization LabControl Response LabQueueing Simulation LabGeofence Event SimulatorCoordinate Reference LabSurvey Traverse LabRaster Classification LabChoropleth Design LabMap Print ComposerRaster Reprojection LabElevation Contour MakerTerrain Viewshed LabWatershed DelineatorMap Tile PackagerText File Encoding WorkbenchFilesystem Portability AuditorSBOM License ExplorerFile Signature Auditornpm Lockfile Conflict ResolverSource Secret AuditorOffline Web Package BuilderCertificate Chain InspectorTorrent Metainfo InspectorChunked File PackagerEncrypted File VaultDuplicate File FinderArchive WorkbenchDesign Token ManagerSpacing Token DesignerResponsive Type SystemPackaging Dieline DesignerSVG Icon Sprite PackerFlex Layout PlaygroundCSS Grid PlaygroundRegex Equivalence LabMarkdown Repository AuditorLog Template MinerResponsive Layout AuditorEmail Template PreviewInternal Link GraphState Machine TesterPetri Net SimulatorGit History VisualizerCurl Request WorkbenchBinary Protocol DesignerHex File EditorBinary Patch WorkbenchAPI Mock SandboxSchema Column MapperEvent Log SessionizerER Diagram DesignerTime Series Gap AuditorStratified Data SplitterData Lineage DesignerDecision Tree LabData Anonymization WorkbenchData Expectation RunnerJSON Schema ValidatorBasket Pattern AnalyzerRobots Policy TesterSEO HTML AuditorAccessibility Structure AuditorSyndication Feed WorkbenchIndexNow Payload BuilderCrawl Log AnalyzerCSP Policy WorkbenchSearch Performance AnalyzerCSV Formula Risk AuditorCORS Response SimulatorCache Header LabCookie Policy InspectorWeb Vitals Trace LabSitemap Health AuditorBatch File RenamerFolder Space MapFolder Difference ReviewerRoute Order OptimizerGeoJSON Map EditorPolygon Overlay LabCartographic Label PlacerSpatial Table JoinGeoJSON Topology AuditorGPX Track AnalyzerTrack Privacy RedactorCSV Table JoinCSV Pivot WorkbenchScientific Data ProfilerTabular Cleaning WorkbenchRecord ReconciliationData Dictionary BuilderCanonical Graph AuditorRedirect Plan TesterHTTP response and ping reference testBrowser and System InformationJSON ↔ YAML ConverterXML ↔ JSON ConverterHTML FormatterJavaScript MinifierMock Data Generator.gitignore GeneratorLicense GeneratorUser-Agent ParserPassword Strength CheckerCode to ImageXML FormatterHTTP Status Code LookupMIME Type LookupJS & SQL String EscapeCSS Box Shadow GeneratorCSS Gradient GeneratorIndent ConverterNumber Base ConverterUnicode Escape ConverterUnicode InspectorJSON Structure DiffMarkdown Table GeneratorBase64 EncoderJSON FormatterURL EncoderSQL FormatterCron Expression GeneratorRegex TesterUUID GeneratorTimestamp ConverterJWT DecoderHTML Entity ConverterMarkdown PreviewCSS MinifierMeta Tag GeneratorJSON ↔ CSVCase ConverterImage to Base64
Explore all Dev Tools tools →Image/Media →Text/Convert →Life/Fun →