Tools

Digitally Sign PDF

Adds a digital signature to a PDF with your own certificate file (.p12 or .pfx) or with one you create here. The signature is a PAdES signature any PDF reader can check: it shows who signed and proves the document hasn't changed since. It is added to the end of the file, so signatures already in the document stay valid. Visible on a page with your name, the date and a handwritten signature, or invisible. The certificate, its password and the document stay on your device.

Drop PDF files here

Drag them straight from your desktop

or
  • PDF files only
  • Up to 15 MB each
  • 2 files a run - unlimited with Pro

Frequently asked questions

What kind of signature does this make?

A PAdES digital signature (the European standard for PDF signatures, baseline B-B): the document's content is hashed and signed with the private key of your certificate, and the certificate travels inside the file. Any PDF reader can check it: it shows who signed and whether the document changed since. The signature is added to the end of the file, so the original bytes and any signatures already in it stay as they were. No timestamp is fetched from a timestamping service: the signing time is your device's clock.

Sign or digitally sign: which do I need?

Sign PDF puts an image of your handwritten signature on the page: it looks like a signed and scanned printout, and it is enough where a signature only has to be seen - an internal form, a delivery note, a letter. Anyone could copy that image, so it proves neither who signed nor that the document hasn't changed since. Digitally Sign PDF signs the file with a certificate: a PDF reader shows who signed and warns if anything changed afterwards. Use it where it matters who signed and that nothing changed since - a contract, an invoice, an official submission - and you have a certificate (.p12 / .pfx). The two go together too: the digital signature can carry your handwritten signature as its visible appearance.

Which certificate can I use?

A certificate file with its private key: .p12 or .pfx, as Windows, macOS, Firefox or a certificate provider exports it, both the current (AES) and the older (3DES) kind, with an RSA or ECDSA key. A qualified certificate kept on a smart card or in a provider's cloud can't be used here, because its key never leaves the card, so this tool doesn't make qualified electronic signatures. Without a certificate you can create one in the browser: it proves the document is unchanged, but no authority vouches for the name.

Does my certificate or its password leave my device?

No. The certificate file is opened in your browser, the key is kept in the tab's memory in a form that can only sign and can't be read back, and it is forgotten when you close the tab. Neither the certificate, nor the password, nor the document is uploaded or stored: the whole signing runs on your device.

What if the PDF is already signed?

The new signature is added after the existing ones, so they stay valid, and a reader shows for each signature what it covers. A document certified with "no changes" can't take another signature, and only a document's first signature can certify it. Edit the document before signing: any change afterwards shows as a change against your signature.

Missing something, or did the result surprise you?