Validate a PDF's Digital Signatures
Validate Signature reads the digital signatures in a PDF and reports what OpenSSL finds as a JSON list. It does not change the file, and without a trust anchor it cannot confirm that the signer's chain is trusted.
Drag and drop files here, or click to choose
Accepts PDF · up to 500.0 MB per file · up to 20 files at once
You can also paste a file with Ctrl/Cmd+V, or from the clipboard menu.
Validate Signature walks signature dictionaries and asks OpenSSL (`smime` / `cms` / `dgst` / `verify`) about CMS and RFC 3161 timestamps. The download is a JSON array (`resultKind: json`), not a modified PDF.
Without a `certFile` trust anchor, `chainValidationError` is `No trust anchors available`. `revocationChecked` is always false. `notExpired` is a placeholder false, not a computed expiry flag.
This is not a courtroom expert report. Chain trust needs an anchor you supply via the API; the website form has no cert upload.
Get Info's `IsSigned` is unrelated and always false.
Features
- JSON array from OpenSSL CMS/timestamp checks
- No cert upload on the website; chain then reports no anchors
- revocationChecked and notExpired are not real checks
- Anonymous API at /api/v1/security/validate-signature
When to use this tool
- See whether CMS verify liked the embedded signature bytes
- Check coversEntireDocument before you flatten
- API-pass a certFile when you have an anchor
How do I check a PDF's digital signature?
- Upload a PDF that may contain signature dictionaries.
- Click Process and download the JSON.
- Read valid, coversEntireDocument, and errorMessage per entry.
- Do not treat chainValid as true unless you called the API with certFile.
Limits and edge cases
- Website cannot supply trust anchors
- No OCSP/CRL
- notExpired is unused as a real clock check
- Upload limit on this website: 500 MB per file, sent in chunks above about 95 MB. A single direct API request body is capped at 100 MB.
Examples
- An unsigned PDF yields an empty JSON array
- A signed PDF without certFile still reports chainValidationError about anchors
Privacy for this tool
Files are uploaded over HTTPS, processed in memory or a short-lived temporary directory on our servers, and deleted when your result is ready. We do not keep copies for later browsing, training, or advertising profiles. See the Privacy Policy for retention details and AdSense cookie disclosures.
Frequently asked questions
- Why is chain validation an error?
- The website does not send certFile. The op then has no trust anchors.
- Does this alter the PDF?
- No. It only reports.
- Is revocation checked?
- No. revocationChecked is always false.
- Can I use this instead of Adobe's validator?
- No. Use it as a coarse OpenSSL dump, then verify in a tool you trust for the legal context.
Last updated:
Call this from code
Every tool on this site is a plain REST endpoint - no account or API key needed for anonymous use. Built for AI agents and developers as much as for browsers.
curl -X POST "https://pdf123.xyz/api/v1/security/validate-signature" \
-F "[email protected]"Also available as an MCP tool for agent clients that speak Model Context Protocol (JSON-RPC 2.0 over POST /mcp). Full API reference
Use it from an AI agent
SkillClaude Code, Codex, Cursor and other AI agents can run Validate PDF Signature for you with this skill: /skills/pdf123-validate-signature.md
Files are used only for this processing job and deleted automatically afterward.