Tooleux

Verify an SM2 signature against a message and public key.

Runs in your browser. Nothing leaves your device.
Verify an SM2 signature against a message and public key (Chinese national standard). Free, offline, runs entirely client-side. Read more Show less

What is SM2 Verify?

SM2 Verify checks whether an SM2 signature is valid for a given message and public key. It answers one question: was this message signed by the holder of the private key that corresponds to this public key?

Verification uses only public information. Anyone with the message, signature, and public key can run it.

How to verify

Enter the message, paste the SM2 signature (hex), paste the SM2 public key, and press Verify. The result is a simple valid or invalid.

By default the tool assumes the message is SM3-hashed before signing, matching the sign tool. The optional user ID defaults to 1234567812345678, matching the GB/T 32918 standard.

Why does verification fail?

Five common causes:

Wrong message. A single different byte changes the SM3 hash and produces a different verification result. Whitespace and line endings matter.

Wrong public key. The public key must be the pair of the private key that produced the signature.

Wrong user ID. If the signature was created with a non-default user ID, verification will fail unless you supply the same one.

Wrong hash flag. If the signature was created over a raw hash (hash: false), verification must also use hash: false.

Wrong signature format. Raw r||s and DER-encoded signatures are different byte sequences. Set the DER flag to match how the signature was produced.

FAQ

Can I tell who signed a message?

No. Verification only confirms a signature matches a given public key. Binding a public key to an identity is a separate problem solved by certificates or a trust directory.

Is verification fast?

Yes, on the order of a few milliseconds per signature in JavaScript.

What if the message is a file?

Hash the file first with SM3, then sign or verify the hash with hash: false. That is the standard pattern for signing large files.

Does this tool reveal the public key?

No. The public key is what you provided. SM2 signatures do not embed the public key.

Can I verify a signature created by OpenSSL?

Yes if OpenSSL produced a DER-encoded signature. Set the DER flag and use the same user ID that the signer used.

Command line equivalent
# Node with sm-crypto
npm i sm-crypto
node -e '
const sm2 = require("sm-crypto").sm2;
const msg = "hello";
const sigHex = "your-signature-hex";
const publicKey = "your-public-key-hex";
const ok = sm2.doVerifySignature(msg, sigHex, publicKey, { hash: true });
console.log(ok ? "valid" : "invalid");
'

# Python with gmssl
pip install gmssl
python3 -c '
from gmssl import sm2, func
public_key = "your-public-key-hex"
sig = bytes.fromhex("your-signature-hex")
verifier = sm2.CryptSM2(private_key="", public_key=public_key)
print(verifier.verify(sig, b"hello"))
'
Loads a test value into the form
Message
Result