What Is a Digital Signature?
A digital signature uses a private key to produce a value that anyone can verify with the matching public key, proving that the holder of the key signed this exact content and that it has not changed since. It gives three things at once: authenticity, integrity, and non-repudiation — the signer cannot later deny it. It is how a verifiable credential, a signed agent action, or a sealed record proves who stands behind it.
Sign the hash, not the document
In practice a signature is computed over a hash of the content, not the content itself: the signer hashes the document and signs the hash, and a verifier re-hashes and checks. That is why a single changed byte breaks the signature — the hash no longer matches — and why signatures and hash functions are always paired.
For agents, the signature is what turns an action into an accountable one: who authorised it is not a claim in a log but a value anyone can verify against a public key held at the actor’s own domain.
Related standards
Questions
Is a digital signature the same as an electronic signature?
No. An e-signature can be a typed name or an image; a digital signature is a cryptographic proof tied to a key.
What is non-repudiation?
Because only the private-key holder could have produced the signature, they cannot credibly deny having signed — the property that makes signatures accountable.
Keep reading
By Michael Gord · published 2026-10-09 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.