Tooleux

Ed25519 Verify

EdDSA (3)

Verify an Ed25519 signature against a message and public key.

Runs in your browser. Nothing leaves your device.
Verify an Ed25519 signature (RFC 8032). Free, offline, runs in your browser. Read more Show less

What is Ed25519 Verify?

This tool verifies an Ed25519 signature against a message and a public key. It answers one question: was this message signed by the holder of the private key that corresponds to this public key?

Verification uses only public information - the public key, the message, and the signature. No secret is involved. Anyone can run it.

How to verify

Enter the message, paste the 64-byte signature, paste the 32-byte public key, press Verify. The tool returns valid or invalid.

If invalid, three things to check: the message must match byte for byte (including whitespace and line endings), the signature encoding must match (hex vs Base64), and the public key must be the one belonging to the signer.

Common reasons a signature looks invalid

Wrong message encoding. If the signature was produced over raw bytes but you paste them as UTF-8 text, the bytes differ and verification fails.

Line ending mismatch. A trailing newline changes the bytes. If the signer hashed hello, do not verify hello .

Wrong public key. A public key is a single 32-byte value; a small typo changes it entirely.

Signature from a different algorithm. Ed25519 signatures are 64 bytes. If yours is 70-72 bytes, it might be DER-encoded ECDSA - use ECDSA Verify instead.

FAQ

Can this tool tell me who signed a message?

No. It only confirms that a signature matches a given public key. Binding a public key to an identity is a separate problem solved by certificates, DNS, or another trust layer.

Does verification reveal the public key?

You already provided it. Verification does not extract the public key from the signature - that is not possible with Ed25519.

Is Ed25519 verification fast?

Yes - on the order of 50 microseconds per verification in JavaScript. RSA-2048 verification is roughly 10-30x slower.

What if the message is a file?

Hash the file first with SHA-256 or BLAKE3, then verify the signature of the hash. This is the standard "sign the digest" pattern and avoids loading a large file into memory.

Command line equivalent
# OpenSSL 3.x
echo -n "hello" | openssl pkeyutl -verify -pubin -inkey public.pem -rawin -sigfile sig.bin

# Node with @noble/ed25519
node --input-type=module -e '
import * as ed from "@noble/ed25519";
const pub = Buffer.from("...hex public key...", "hex");
const sig = Buffer.from("...hex signature...", "hex");
const msg = new TextEncoder().encode("hello");
console.log(await ed.verifyAsync(sig, msg, pub) ? "valid" : "invalid");
'
Loads a test value into the form
Message
Result