Detached Public-Key Signature Verifier

Verify exact local file or UTF-8 message bytes and a detached signature against a supplied public key.

Files stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Verify detached signature controls

The exact bytes are hashed. A file is read as it is stored, so a text file with a trailing newline is hashed with that newline.

Used when the source is text. The exact characters are hashed, including spaces and line breaks.

Drop your file here

or choose one from your device

Used when the source is a file. The limit is 32 MB. The file stays on this device.

    Paste the public key you trust, as a JWK or one-key JWKS. Private and symmetric keys are refused.

    The algorithm the signature was made with. It must match the key "alg" when the key declares one.

    How the detached signature is written. The two encodings are not interchangeable, so pick the one the signature actually uses.

    The signature bytes, written in the encoding you chose. A detached signature is separate from the message.

    Processed in your browser. Your inputs stay on this device.

    Showing a generated example. Generate again for a new result.

    How to use Detached Public-Key Signature Verifier

    1. Supply the what to verify and text using the supported input described beside the controls.
    2. Review the selected options and the declared scope, then run the detached signature verifier.
    3. Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.

    Example: Detached Public-Key Signature Verifier

    Verify an exact local file/message and detached signature with a supplied public key. This example uses synthetic public data.

    You add
    What to verify: text Text: Synthetic detached verification example. Public JWK: {"kty":"EC","x":"423IsUaZ4rkzM4DqGWlqrY5kTtS2bQ6YkWGPS4Iq2hw","y":"-nrnuCEOId4KxhLZr-CilOx0k5cvNbg9_-rIdipuCNQ","crv":"P-256","alg":"ES256","kid":"synthetic-demo","use":"sig","key_ops":["verify"]} Expected algorithm: ES256 Signature encoding: base64url Detached signature: RKIY_Dt0Or7GaxVKss9tDyhix6lsd2_edhDpy4zLkeKeggNvmv_aWyOucNPsrCczshTiPpEUrMolE7xSzhdd4g
    You get
    SHA-256 of the text is 8a63fddce917d78e... The detached signature is valid for the supplied public key. Source | Entered text Message bytes | 40 SHA-256 | 8a63fddce917d78e46052411c74a5fe152da1f73ba8f34ee3cfc335729fd4eea

    Options

    Message source
    Choose the supported local-file or text workflow. Do not copy a file into text mode when its exact original bytes matter.
    Signature encoding
    Use the explicitly selected encoding. Encoding is representation; changing it must not change the decoded signature bytes.

    Supported inputs and limits

    Verification only for the supported algorithms and public keys. No private keys, signing, trusted publisher discovery or automatic newline conversion.

    Where your input is processed

    This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

    Verify the same bytes that were signed

    A file is verified as its exact bytes. Text mode encodes the entered text as UTF-8, so line endings, spaces and punctuation can change the result. A correct digest is useful for comparing the artifact, but the digest alone does not authenticate it. Establish the public key’s source separately.

    Questions about Detached Public-Key Signature Verifier

    Why can copied text fail?

    Copying can change line endings or spaces. Verify the original file when the signature was made over file bytes.

    Is the byte hash a signature?

    No. A digest does not identify its publisher. The signature check uses your separately supplied public key.

    Are files uploaded?

    No. The tool reads the selected file locally in the browser.

    Project manager: Tony Hines · Content updated 4 October 2026 · Report a problem