Add a cryptographic digital signature to your PDF using X.509 certificates. Supports PKCS#12 (.pfx, .p12) and PEM formats. Your private key never leaves your browser.
Internet connection required
Signing may need to fetch certificate chain information from your certificate issuer's server to validate the signature.
Click to select a file or drag and drop
PDF Documents
Your files never leave your device.
Upload certificate (.pfx, .p12, .pem)
Subject: -
Issuer: -
Valid: -
When enabled, a visible signature box appears on the PDF. You can upload an image/logo or add text. If neither is provided, the signer's name from the certificate will be shown automatically.
Upload image (PNG, JPG, WebP)
Processing...
Select the PDF document you want to sign
Provide your .pfx or .p12 certificate file and password
Apply the digital signature and download your signed PDF
Sign PDF places a drawn, typed, or uploaded picture of your signature on the page; it's visual only. This tool applies a cryptographic PKCS#7 signature using your X.509 certificate, so a PDF reader can verify who signed and detect any change made afterward. You can also show a visible signature block at the same time.
Yes. Upload a single .pem file that contains both the certificate and the private key. Encrypted private keys work too; enter the key password in the Certificate Password field. If your certificate and key are in separate PEM files, paste them into one file first.
Often, yes. The signing library fetches the issuer certificate chain from the URLs in your certificate's Authority Information Access extension, and if those servers can't be reached, signing fails for certificates that need chain validation. Your PDF and private key are never part of those requests; only the certificate URLs are fetched.
The reader can't trace the certificate back to a root it trusts. That's expected for self-signed certificates, which are fine for testing but always show a warning. For documents other people need to rely on, use a certificate issued by a Certificate Authority that PDF readers trust.
No. The cryptographic signature is embedded whether or not the visible block is enabled. Turn on Visible Signature if you want a stamp on the page: pick the first, last, all, or a specific page, set the position and size in points, and add a PNG, JPG, or WebP image or a line of text; with neither, the tool writes the certificate's common name and the current date.
They're optional metadata stored inside the signature itself. Reason records why you signed, such as "Approved" or "Reviewed", Location where it happened, and Contact Info how to reach you. PDF readers display them in the signature panel.
The file can still be opened and edited, but any change made after signing breaks the integrity check and readers will report the document as modified. If the PDF has form fields or annotations that should be fixed in place, run it through Flatten PDF before signing, not after.
Open the signed file in Validate Signature. It lists every signature, shows the signer and issuer, checks the certificate dates, and confirms whether the bytes have changed since signing. You can also load your CA certificate there to verify the trust chain.