Understanding signatures
Every transaction must be signed with one or more private keys that correspond to the authorities required by the operations in the transaction.1
Check required authorities
Before signing, determine which authorities are needed for your transaction.
- TypeScript
- Python
Most operations require posting authority (votes, comments). Financial operations require active authority (transfers, power ups). Account recovery requires owner authority.
2
Get the signature digest
The signature digest is what you actually sign. It’s a cryptographic hash of the transaction.
- TypeScript
- Python
3
Sign with a provider
Use your preferred signing provider to sign the transaction. See the sections below for provider-specific examples.
4
Verify signatures
After signing, you can verify which public keys signed the transaction.
- TypeScript
- Python
Signing with Beekeeper
Beekeeper is the official wallet solution for Hive. It provides secure key management and signing.- TypeScript
- Python
Beekeeper runs as a separate process and manages keys securely. Never hardcode private keys in production code.
Signing with Hive Keychain
Hive Keychain is a browser extension that provides secure signing for web applications.- TypeScript
- Browser Example
Signing with MetaMask
MetaMask Snaps enables signing Hive transactions using MetaMask.- TypeScript
Signing with PeakVault
PeakVault is a mobile wallet that supports signing through deep links.- TypeScript
Manual signing
You can also sign transactions manually if you have the private key.- TypeScript
- Python
Multi-signature transactions
Some operations require multiple signatures from different authorities.- TypeScript
- Python
Best practices
Validate before signing
Validate before signing
Always validate your transaction before attempting to sign it. This catches errors early and prevents wasted signing attempts.
Handle signing errors gracefully
Handle signing errors gracefully
Signing can fail for various reasons (user rejection, wrong key, etc.). Always handle errors appropriately.
Never expose private keys
Never expose private keys
Private keys should never be:
- Hardcoded in source code (except for testing)
- Logged to console or files
- Sent over insecure connections
- Stored in plaintext
Next steps
Broadcasting transactions
Learn how to broadcast your signed transactions
Signing providers
Explore all available signing provider extensions
Beekeeper setup
Detailed guide to using Beekeeper
Keychain integration
Integrate Hive Keychain in your web app