Matchboxmatchbox
← Back to match

pdf-sign

Free CLI tool to sign and verify PDFs using GPG or Sigstore keyless OIDC identities (Google/GitHub).

Desktopfreeglobal

A Rust command-line tool that signs and verifies PDFs with OpenPGP (GPG) or Sigstore keyless OIDC (Google/GitHub), appending signatures after the PDF's %%EOF so the original content remains unchanged. It removes the need for a full X.509/PKI or CMS stack, supports hardware keys, multi-signer and air-gapped challenge-response workflows, and is aimed at developers, CI/CD pipelines, and security‑conscious users; usable via CLI, Docker, Nix, or Cargo.

Categories
pdf signingdigital signaturedocument security

Full match profile

Behind the summary, Matchbox keeps a richer profile of pdf-sign - the signals our matcher actually reads to decide when to surface it. It stays private; claim the listing to see and control it.

  • Problem & pain-point mapping
  • Who we surface it to (audience fit)
  • What it's a strong alternative to
  • Trust & credibility signals

Try Matchbox with your own problem

Describe what is not working - we’ll show you whether pdf-sign (or something else) actually fits.