# Sign a document hash in the SecurySign web app

The [SecurySign home page](https://securysign.com/) signs a document hash using a passkey. Add the file, review the SHA-256 hash computed by the browser, then approve the signature and download its verification package. For an integration in your own application, see the [Hash signing API](#/docs/api-hash-signing).

## What you need

To sign a document, you'll need:

- your Google account for sign-in;
- the document you want to sign;
- a device that can use or create a passkey.

## Sign a document

Add a file on the home page to open its document page, which displays the name, hash and activity. Select **Sign Document**. For a first signature, the app prompts for passkey creation and issues an X.509 signing certificate.

Select **Confirm Signature** to open the device's passkey prompt. Approval uses the verification method available on the device, such as a fingerprint, face scan or PIN.

After signing, the **Signature Inspector** displays the hash, certificate, signature and algorithm: `ES256`, ECDSA with the P-256 curve. **Download Package** saves a JSON file in `signa-pades-v1` format containing the hash, timestamp, algorithm, certificate serial number, signature and PEM certificate.

## Check the signature

To check the result against the original file, open [Verify](https://securysign.com/#/verify). The [Verification guide](#/docs/verification) explains the inputs and results.
