Why transactions need signatures
Every transaction on the Hive blockchain must be cryptographically signed to prove that it’s authorized by the account(s) performing the operations. Signatures ensure:Authentication
Proves the transaction creator has access to the private keys
Authorization
Verifies the account holder approves the operations
Integrity
Ensures the transaction hasn’t been modified after signing
Non-repudiation
Creates an immutable proof of the transaction’s origin
How signing works
Signature digest
Before signing, WAX calculates a signature digest (hash) of the transaction:- TypeScript
- Python
The signature digest is deterministic - the same transaction always produces the same digest, making signatures verifiable.
Signature providers
WAX supports multiple signature providers through a pluggable interface. You choose the provider based on your application’s needs:Available providers
Beekeeper
Server-side wallet manager for automated signing
Hive Keychain
Browser extension for secure key management
PeakVault
Mobile-friendly wallet integration
MetaMask
Ethereum wallet adapter for Hive
Provider interface
All signature providers implement a common interface:- TypeScript
- Python
ts/wasm/lib/detailed/extensions/signatures/index.ts
Signing with Beekeeper
Beekeeper is the recommended signature provider for server-side applications and automation:- TypeScript
- Python
Signing with browser extensions
For web applications, browser extensions like Hive Keychain provide secure signing without exposing private keys:- Keychain
- PeakVault
Browser extension providers handle user interaction (prompts, confirmations) automatically.
Authority levels
Hive accounts have multiple authority levels, each with different permissions:Required authorities
You can check which authorities a transaction requires:- TypeScript
- Python
Multiple signatures
Some operations require signatures from multiple accounts or multiple keys from the same account:- TypeScript
- Python
Manual signature handling
For advanced use cases, you can manage signatures manually:- TypeScript
- Python
Signature verification
You can verify that a transaction’s signatures are valid:- TypeScript
- Python
Encryption and decryption
Signature providers also handle encryption for private memos:- TypeScript
- Python
Key management
WAX provides utilities for working with cryptographic keys:Generate keys
- TypeScript
- Python
Brain keys
- TypeScript
- Python
Best practices
Never expose private keys
Never expose private keys
Always use signature providers that keep private keys secure. Never log or transmit private keys.
Validate before signing
Validate before signing
Always call
tx.validate() before signing to catch errors early and avoid wasting signatures.Handle signature failures gracefully
Handle signature failures gracefully
Users may reject signing requests. Always handle errors and provide clear feedback.
Next steps
Broadcasting
Learn how to broadcast signed transactions
Signature Providers
Explore all signature provider options
Transactions
Review transaction concepts
Security
Best practices for secure signing