# Verify a signature in the SecurySign web app

The [Verify page](https://securysign.com/#/verify) checks a saved signature against its original document. The browser compares the file hash and verifies the signature with the passkey's public key. For certificate-chain and revocation checks in a backend integration, see the [Verification API](#/docs/api-certificates).

## What you need

The check requires:

- a signature available in your current account from [Hash signing](#/docs/hash-signing);
- the exact file you signed.

## Verify a signature

Select a signature under **Available Signatures**, then add the original file under **Original Document**. The browser computes the file's SHA-256 hash. **Run Verification** compares it with the signed hash and checks the ECDSA signature.

## Read the result

**Signature Valid** means both checks passed. **Signature Invalid** includes details of the failed check.

| Result field | How you read it |
|---|---|
| Document hash | `MATCH` identifies the signed file; `MISMATCH` identifies different bytes. |
| ECDSA signature | `VALID` means the signature verifies with your passkey's public key. |
| Authenticator | You see the passkey name, Authenticator Attestation Globally Unique Identifier (AAGUID) and hardware status. |
| Certificate SN | You see the signing certificate's serial number. |
| Identity | You see the account and sign-in provider associated with the signature. |

For `MISMATCH`, select the exact original file and choose **Re-verify**. A change of even one byte changes the hash.
