Skip to main content

Tools for stamping and signing PDF files

Project description

pyHanko

status Codecov Language grade: Python pypi

The lack of open-source CLI tooling to handle digitally signing and stamping PDF files was bothering me, so I went ahead and rolled my own.

Note: The working title of this project (and former name of the repository on GitHub) was pdf-stamp, which might still linger in some references.

Note: This project is currently in alpha, and not yet production-ready.

Installing

PyHanko is hosted on PyPI, and can be installed using pip:

   pip install 'pyHanko[pkcs11,image-support,opentype]'

This pip invocation includes the optional dependencies required for PKCS#11, image handling and OpenType/TrueType support.

Overview

The code in this repository functions both as a library and as a command-line tool. It's nowhere near complete, but here is a short overview of the features. Note that not all of these are necessarily exposed through the CLI.

  • Stamping
    • Simple text-based stamps
    • QR stamps
    • Font can be monospaced, or embedded from a TTF/OTF font (requires [opentype] optional deps)
  • Document preparation
    • Add empty signature fields to existing PDFs
    • Add seed values to signature fields, with or without constraints
  • Signing
    • Signatures can be invisible, or with an appearance based on the stamping tools
    • LTV-enabled signatures are supported
      • PAdES baseline profiles B-B, B-T, B-LT and B-LTA are all supported.
      • Adobe-style revocation info embedding is also supported.
    • RFC 3161 timestamp server support
    • Support for multiple signatures (all modifications are executed using incremental updates to preserve cryptographic integrity)
    • Supports both RSA & ECDSA
      • RSA padding modes: PKCS#1 v1.5 and RSASSA-PSS
      • ECDSA curves: anything supported by the cryptography library, see here.
    • PKCS#11 support
      • Available both from the library and through the CLI
      • Extra convenience wrapper for Belgian eID cards
    • "Interrupted signing" mode for ease of integration with remote and/or interactive signing processes.
  • Signature validation
    • Cryptographic integrity check
    • Authentication through X.509 chain of trust validation
    • LTV validation/sanity check
    • Difference analysis on files with multiple signatures and/or incremental updates made after signing (experimental)
    • Signature seed value constraint validation
  • Encryption
    • All encryption methods in PDF 2.0 are supported.
  • CLI & configuration
    • YAML-based configuration (optional for most features)
    • CLI based on click
      • Available as pyhanko (when installed) or python -m pyhanko when running from the source directory
      • Built-in help: run pyhanko --help to get started

Some TODOs and known limitations

See the known issues page in the documentation.

Documentation

Documentation is built using Sphinx, and hosted here on ReadTheDocs.

Acknowledgement

This repository includes code from PyPDF2 (with both minor and major modifications); the original license has been included here.

License

MIT License, see LICENSE.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pyHanko-0.8.0.tar.gz (242.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

pyHanko-0.8.0-py3-none-any.whl (294.4 kB view details)

Uploaded Python 3

File details

Details for the file pyHanko-0.8.0.tar.gz.

File metadata

  • Download URL: pyHanko-0.8.0.tar.gz
  • Upload date:
  • Size: 242.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.3.0 pkginfo/1.7.0 requests/2.25.1 setuptools/53.0.0 requests-toolbelt/0.9.1 tqdm/4.56.2 CPython/3.9.6

File hashes

Hashes for pyHanko-0.8.0.tar.gz
Algorithm Hash digest
SHA256 ab5058b448fa8da1d5a41f90e0cb04c683388f79273acccc6d76f127833bab18
MD5 dc5ed100b01a58f97768c21c031e2965
BLAKE2b-256 d26349157f28bc2f950eb14c340ef424e0dee8616ff560a8401276569ff28f57

See more details on using hashes here.

File details

Details for the file pyHanko-0.8.0-py3-none-any.whl.

File metadata

  • Download URL: pyHanko-0.8.0-py3-none-any.whl
  • Upload date:
  • Size: 294.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.3.0 pkginfo/1.7.0 requests/2.25.1 setuptools/53.0.0 requests-toolbelt/0.9.1 tqdm/4.56.2 CPython/3.9.6

File hashes

Hashes for pyHanko-0.8.0-py3-none-any.whl
Algorithm Hash digest
SHA256 292422044e54f885ac41be957ac2b86e13f32c0ee29b5c3966a26495e648c444
MD5 c6653f09bbe48264a232b4545adcdff7
BLAKE2b-256 6d8e0e3f8e9799dfc65d3377cb16dccd4ef4dd0bf7563b042576035e12c5ae4f

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page