WDK logoWDK documentation
TONStandard TONGuides

Sign and Verify Messages

Sign messages and verify signatures with TON accounts.

This guide explains how to sign messages with an owned account and verify signatures using a read-only account.

Starting with beta.15, message signing and verification use a domain-separated digest. Signatures from beta.14 and earlier do not verify with this scheme, and raw-message external verifiers cannot verify beta.15 signatures. Keep an existing signature with its original verification scheme; use the matching beta.15 verifier for new signatures.

Sign a Message

The wallet signs the SHA-256 digest of the bytes 0xffff, the UTF-8 string ton-safe-sign-magic, and the UTF-8 message, concatenated in that order. The returned Ed25519 signature is hex encoded. External verifiers must reproduce this digest.

You can sign a message using account.sign():

Sign a Message
const message = 'Hello, TON!'
const signature = await account.sign(message)
console.log('Signature:', signature)

Verify a Signature

You can verify that a signature was produced by the corresponding private key using readOnlyAccount.verify():

Verify a Signature
const readOnlyAccount = await account.toReadOnlyAccount()
const isValid = await readOnlyAccount.verify(message, signature)
console.log('Signature valid:', isValid)

You can also create a WalletAccountReadOnlyTon from any public key to verify signatures without access to the private key.

Next Steps

For best practices on handling errors, managing fees, and cleaning up memory, see Handle Errors.

On this page