An independent, offline verifier for RFC 3161 timestamped and digitally signed PDFs — as an npm package you embed in your own app. Zero dependencies.
import { readFileSync } from "node:fs";
import { verify } from "verifiedby";
const bytes = new Uint8Array(readFileSync("contract.pdf"));
const result = await verify(bytes);
console.log(result.status);
// "verified" | "verified-untrusted-root" | "signed-untimed" |
// "unverified" | "mismatch" | "unsupported" | "no-signature"
Runs entirely on the bytes you pass in and crypto.subtle — no network access, no filesystem access beyond what you give it. Node 20+, any modern browser, Deno, or Bun.
| Status | Read as |
|---|---|
verified | pass |
verified-untrusted-root | pass — confirm the authority yourself |
signed-untimed | pass, weaker claim |
no-signature | informational |
unsupported | limit of the tool, not a finding |
unverified | fail |
mismatch | fail |
Only mismatch and unverified are failures of the document. Full rubric — what's checked, in what order, and what would have to be true for each verdict to be wrong — is in METHODOLOGY.md.
verify(pdfBytes, trustAnchors?)The main entry point. Returns a promise resolving to a result object — see the full field-by-field reference in the README and TypeScript declarations.
extractSignatures(pdfBytes)The raw signature dictionaries in a PDF — byte ranges, /Contents, /SubFilter — without running verification.
KNOWN_ROOTSThe short, human-checkable list of pinned trust anchors, by public key rather than certificate fingerprint.
registerResolver(resolver) / resolveIdentity(result, pdfBytes)Attach your own app's identity claims as clearly separate, display-only information — never merged into the cryptographic result, since proof and "a party's records say" are different kinds of evidence.
Who made this. Built and operated by SPRK10 B.V., the company behind SignedBy. Stated plainly rather than left to be discovered — the reason to run this yourself, from published source, is that you don't have to take our word for what it does.
Apache-2.0. Found a file that should fail and instead verifies? Report it privately: security@signedby.ai.