# Sign a PDF in the SecurySign web app

The [PAdES page](https://securysign.com/#/pades) embeds a signature directly in a PDF. Upload the file, approve with a passkey and download the signed PDF. The PDF contains an embedded CMS/PKCS#7 signature and the signer's X.509 certificate. For a backend integration, see the [PAdES signing API](#/docs/api-pades-signing).

## What you need

Before starting, you'll need:

- your Google account for sign-in;
- a passkey and signing certificate, created through the [document signing flow](#/docs/hash-signing#sign-a-document);
- a PDF of about 15 MB or less, so its base64 representation fits within the 20 MB request limit.

## Sign a PDF

Select the file under **Upload a PDF to sign**, then choose **Sign PDF with PAdES**. The progress display follows three stages.

**Prepare PDF** adds a signature placeholder and computes the SHA-256 hash of the PDF byte range covered by the signature. **Touch Key** requests passkey approval on the device. **Build PAdES** embeds the signature and certificate in a Cryptographic Message Syntax (CMS) container inside the PDF.

When **PAdES PDF Signed** appears, select **Download Signed PDF**. A PAdES-aware reader displays the embedded signature and certificate. See [Validate against the certificate authority](#/docs/api-certificates#2-validate-against-the-certificate-authority) for certificate-chain validation.
