SM2 Sign
Sign a message with an SM2 private key.
Sign a message with an SM2 private key (Chinese national standard). Free, offline, runs entirely client-side. Read more Show less
What is SM2 Sign?
SM2 Sign produces a digital signature using an SM2 private key. The signature proves that the holder of the private key approved the message, and can be verified by anyone with the matching public key.
The SM2 signature scheme is similar to ECDSA but includes the signer's identity (a "user ID") in the hash computation. This is called the Z value and provides domain separation - the same message signed by two different identities produces different signatures.
How to sign
Enter the message, enter the SM2 private key (64 hex characters), and press Sign. The signature is produced as a hex string.
By default, SM2 signs the SM3 hash of the message, which is the standard behavior. The optional user ID defaults to 1234567812345678, the value recommended by the GB/T 32918 standard.
Signature format
SM2 signatures are two 256-bit integers, called r and s. They can be output in two forms:
Raw (r || s) - 128 hex characters, r followed by s, no wrapping.
DER-encoded - an ASN.1 SEQUENCE of two INTEGERs. Used by OpenSSL and most enterprise tools.
This tool outputs the raw form by default. Enable DER encoding in the settings if you need to interoperate with OpenSSL.
FAQ
Is SM2 signing deterministic?
No. Like ECDSA, SM2 uses a random nonce k for each signature. Signing the same message twice produces two different signatures. Both verify correctly.
Can I recover the private key from a signature?
No. SM2 is designed so that recovering the private key from valid signatures is as hard as solving the elliptic curve discrete logarithm problem, which is infeasible on the sm2p256v1 curve.
What is the user ID for?
It is included in the SM3 hash as part of the Z value. A signer's identity, together with their public key and the curve parameters, produces a unique prefix that binds the signature to that signer. The default value 1234567812345678 is used when no specific identity is needed.
Can I verify an SM2 signature with OpenSSL?
Yes, with the right conversion. OpenSSL 1.1.1+ supports SM2. Convert the raw signature to DER (or enable DER output here) and use openssl pkeyutl -verify with the SM2 algorithm.
Is it safe to paste my private key here?
This tool runs entirely client-side. Nothing is uploaded. Verify by opening your browser's Network tab - no requests are sent after page load. For production keys, always audit any tool before pasting secrets.
Command line equivalent
# Node with sm-crypto
npm i sm-crypto
node -e '
const sm2 = require("sm-crypto").sm2;
const msg = "hello";
const privateKey = "your-64-hex-private-key";
const sig = sm2.doSignature(msg, privateKey, { hash: true });
console.log(sig);
'
# Python with gmssl
pip install gmssl
python3 -c '
from gmssl import sm2, func
private_key = "your-64-hex-private-key"
msg = b"hello"
signer = sm2.CryptSM2(private_key=private_key, public_key="")
sig = signer.sign(msg)
print(sig.hex())
'