Add an RFC 3161 document timestamp to your PDF using a trusted Time Stamp Authority (TSA) server. Proves your document existed at a specific point in time. No certificate required.
Internet connection required
Timestamping requires contacting the selected TSA server to obtain a trusted timestamp token.
Click to select a file or drag and drop
PDF Documents
Your files never leave your device.
Processing...
Select the PDF document you want to timestamp
Select one of the trusted TSA servers
Apply the RFC 3161 timestamp and download your timestamped PDF
The menu offers five public RFC 3161 authorities: DigiCert, Sectigo, SSL.com, FreeTSA, and MeSign. There is no field for a custom URL, so the choice is limited to those presets.
No. The tool has to contact the chosen TSA over the internet to obtain the signed timestamp token; everything else, including hashing the file and embedding the token, happens in your browser. If the request fails you can pick another server and try again.
A digital signature proves who signed the document and needs your own certificate, while a document timestamp proves only when the document existed, vouched for by the TSA. If you need both, sign first with Digital Sign PDF and then add the timestamp here.
The timestamp is appended as an incremental update rather than a rewrite of the file, so an existing signature stays intact and verifiable, and the timestamp shows as its own entry in the reader's signature panel.
No. The timestamp is invisible; it lives in the file's signature data and shows up in the signature panel of Acrobat and similar readers, not as a stamp on the page. The downloaded file keeps its original name.
Most often the TSA didn't respond or your connection dropped, so try another server from the list. On self-hosted copies of BentoPDF served over HTTPS, the servers that only offer HTTP endpoints need a CORS proxy configured at build time; FreeTSA uses HTTPS and works without one.
Readers validate the token against the TSA's certificate chain, so it verifies as long as that chain is trusted. This tool doesn't embed long-term validation (LTV) data, so verification years later depends on the reader still being able to check the TSA's certificates.
Open the signature panel in Adobe Acrobat Reader or another signature-aware viewer; the timestamp is listed there with its time and the authority that issued it. If the reader trusts the TSA's certificate chain, it reports the timestamp as valid.