Sign and Verify Messages
Sign messages and verify signatures with gasless TON accounts.
This guide explains how to sign messages with an owned account and verify signatures.
Beta.13 changes message signing through its TON beta.15 dependency. Update external verifiers and any stored-signature compatibility checks before upgrading: signatures created by earlier gasless releases do not verify with the new domain-separated scheme.
Sign a Message
You can produce a cryptographic signature for any string message using account.sign():
The account signs SHA-256(0xffff || UTF-8("ton-safe-sign-magic") || UTF-8(message)) with Ed25519. An external verifier must reconstruct that digest. verify() uses the same scheme and does not accept a raw-message fallback.
const message = 'Hello, TON!'
const signature = await account.sign(message)
console.log('Signature:', signature)Verify a Signature
You can verify that a signature is valid using account.verify():
const isValid = await account.verify(message, signature)
console.log('Signature valid:', isValid)You can also create a WalletAccountReadOnlyTonGasless from any public key to verify signatures without access to the private key:
import { WalletAccountReadOnlyTonGasless } from '@tetherto/wdk-wallet-ton-gasless'
const readOnlyAccount = new WalletAccountReadOnlyTonGasless(publicKey, {
tonClient: {
url: 'https://toncenter.com/api/v2/jsonRPC',
secretKey: 'your-api-key'
},
tonApiClient: {
url: 'https://tonapi.io',
secretKey: 'your-ton-api-key'
},
paymasterToken: {
address: 'EQ...'
}
})
const isValid = await readOnlyAccount.verify(message, signature)
console.log('Signature valid:', isValid)Next Steps
For best practices on handling errors, managing fees, and cleaning up memory, see Handle Errors.