everyday
pgp sign
put an unfakeable stamp on a message: anyone holding your public key can later prove that you wrote it and that not one character changed. signing does not hide the text - use encrypt for that.
privacy: with javascript enabled, everything runs in your browser and your key never leaves it. without javascript this form posts to the server, where your private key is used in memory to sign - never stored, never logged, discarded when the response is sent. the javascript path is strongly preferred; note it supports modern keys (ed25519/ecc) while the no-javascript path is rsa-only.
faq
- is my private key uploaded?
- with javascript on: no. signing runs entirely inside your browser tab and nothing is sent anywhere. without javascript the form posts to our server, which signs in memory only - never stored or logged.
- does signing encrypt my message?
- no. a signature only proves authorship and integrity - the text stays readable by anyone. combine signing with encryption when confidentiality matters too.
- what do recipients need to check my signature?
- only your public key. they paste your signed message and your public key into a verify tool - if it matches, the message provably came from your key.
- clearsigned vs detached signature?
- this tool produces a clearsigned message - signature wrapped around the readable text. that is what email clients and most people expect. detached signatures (separate .sig file) are mainly for files.
- can someone lift my signature onto another message?
- no. the signature covers exactly the bytes you signed. any change invalidates it.
- which key types work here?
- rsa keys work everywhere, even with javascript fully off. modern curve25519/ed25519 keys sign in the browser with javascript on; the plain-form path rejects them instead of producing a broken signature.