---
name: "pdf123-validate-signature"
description: "Verify digital signatures and certificates in PDF documents. Runs the PDF123 \"Validate PDF Signature\" tool (pdf123.xyz) over its REST API with curl, no account needed. Use when the user wants this done to their file. Also known as: 验证 PDF 签名, Validar firma PDF, PDF हस्ताक्षर जाँचें, التحقق من توقيع PDF, Validar assinatura do PDF, Validasi tanda tangan PDF, Vérifier la signature PDF, Проверить подпись PDF, PDF署名の検証, PDF-Signatur prüfen, PDF 서명 확인, Kiểm tra chữ ký PDF, PDF imzasını doğrula, 驗證 PDF 簽章, Verifica firma PDF, ตรวจลายเซ็น PDF, Sprawdź podpis PDF, Перевірити підпис PDF, PDF-handtekening controleren, Sahkan tandatangan PDF, Kontrollera PDF-signatur, Έλεγχος υπογραφής PDF, Проверка на PDF подпис, Valida la signatura, Thibitisha saini ya PDF."
compatibility: "Needs curl 7.76+ and outbound HTTPS to pdf123.xyz, or PDFX_API_BASE pointing at a self-hosted pdfx-server."
---

# Validate PDF Signature (PDF123)

Verify digital signatures and certificates in PDF documents.

Web version: https://pdf123.xyz/validate-signature · All tools: https://pdf123.xyz/skills/pdf123.md

## When to use

- See whether CMS verify liked the embedded signature bytes
- Check coversEntireDocument before you flatten
- API-pass a certFile when you have an anchor

## Run it

Replace the sample file names and values with the user's, then run:

```bash
API="${PDFX_API_BASE:-https://pdf123.xyz}"
curl -sS --fail-with-body -X POST "$API/api/v1/security/validate-signature" \
  -F "fileInput=@input.pdf"
```

## Inputs

Everything is `multipart/form-data`. The command above already sends each field with its default; keep them all and change only the values the user asked for, since some endpoints reject a missing optional field.

| Field | Type | Required | Default | Notes |
| --- | --- | --- | --- | --- |
| `fileInput` | file | yes | | .pdf (one file) |

## Result

The response body is JSON and is printed to stdout. Summarize it for the user.

## Limits

- Website cannot supply trust anchors
- No OCSP/CRL
- notExpired is unused as a real clock check
- Upload limit on this website: 500 MB per file, sent in chunks above about 95 MB. A single direct API request body is capped at 100 MB.

## Errors

- A non-zero curl exit means the request failed. The saved file then holds `application/problem+json`; read it and report its `detail` to the user instead of retrying blindly.
- `413`: the upload exceeds 100 MiB. `429`: wait for `Retry-After` seconds, then retry once.
- Send `X-API-KEY: $PDFX_API_KEY` only if the user has a PDF123 API key; anonymous calls work without it.

## Privacy

Files are uploaded to the API host, processed, and deleted once the response is sent. For confidential files, ask before uploading, or use a self-hosted server via `PDFX_API_BASE`.

## Authorized use only

Use this report only on files you are entitled to inspect. Do not present it as a qualified electronic-signature audit, and do not use it to impersonate a certification authority.
