PDFFileElement: verify() method

Works in all major browsers
Since July 2026

WebPDF works in Chrome and Edge 125, Firefox 153 and Safari 18, on desktop and mobile, and in every later version: the oldest versions its PDF.js build supports, which already have every platform feature WebPDF needs. Since July 2026, that is every major browser.

The verify() method of the PDFFileElement interface checks the digital signatures of a <pdf-file> and returns one row per signature.

Verification runs by itself in idle time after the first pages draw (or, when every page is lazy, once one comes near the viewport), and fires verify. verify() runs it at once or returns the cached rows; changing a trust anchor makes the next run check again. Everything happens in the browser with Web Crypto: CMS, certificate paths, RFC 3161 timestamps, OCSP and CRLs.

Syntax

js
verify()
verify(options)

Parameters

options Optional

An object with one property:

force Optional

A boolean value: true checks again even though nothing changed. The default is false.

Return value

A Promise that resolves to an Array of rows, newest signature first: see Signature verification results for their fields. An unsigned file resolves to an empty array.

Exceptions

None.

Usage notes

Examples

Verifying a signed file

html
<pdf-file id=s src=//new.webpdf.pro/signed.pdf trust:src=//new.webpdf.pro/demo-root.pem></pdf-file>
js
const rows = await document.querySelector("#s").verify();
for (const { name, status, certificate } of rows) console.log(name, status, certificate?.subjectCN);

Specifications

Not part of any specification. <pdf-file> and <pdf-page> are autonomous custom elements defined by WebPDF.pro. It implements:

Specification
ISO 32000-2:2020 (PDF 2.0)
# 12.8 Digital signatures
RFC 5652: Cryptographic Message Syntax
RFC 3161: Time-Stamp Protocol
RFC 5280: X.509 certificates and CRLs
RFC 6960: OCSP

Browser compatibility

desktopmobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
verify()
1251251531111812515383182712518
  • verify() · Chrome, Edge, Firefox, Opera, Safari, Chrome Android, Firefox for Android, Opera Android, Safari on iOS, Samsung Internet, WebView Android, WebView on iOS: Secure contexts (HTTPS) only; elsewhere every signature verifies as unknown.

Legend

Full support
See implementation notes.

See also