Signing, certificates and agent authorization in one API. Start free: account, project, CA and API key ready in 5 minutes, no sales call.
Sign tokens, issue certificates, or authorize agents — each with its own minimal payload. No infrastructure to run, no signing keys to store.
RSA and elliptic-curve signatures — the ones behind JWTs (RS256/ES256), TLS certificates and code signing — can be broken by Shor's algorithm on a large enough quantum computer. Sign replaces them with ML-DSA (NIST FIPS 204): send a subject plus your own fields — or the SHA-256 hash of a document — and get back a signed, verifiable, revocable token.
One ML-DSA-65 certificate authority per project, created from the dashboard in seconds. Issue and revoke certificates for devices, services, or agents — no PKI expertise required, no infrastructure to run yourself.
POST /ca/issue at runtime with a subject and public key. Get back a signed certificate.ca.verifyCert() or ca.verifyX509Cert(). No API call needed.POST /ca/revoke — immediate. Check status anytime via GET /ca/crl.Mandate is a PQ-Sign feature that issues signed session credentials for agents, devices, and services — with explicit scope, budget, and real-time control.
POST /mandate with agentId, scope, budget, and TTL. Get back a signed ML-DSA token.POST /mandate/verify before the action. Checks signature + live scope + budget. Granted or denied.PATCH /mandate/:id — narrow scope, suspend, resume, or revoke at any time.GET /mandate/:id — check budget consumed, current scope, status, and time remaining.Account, project, API key and — if you need it — a Private CA: about five minutes from the dashboard. Then install an SDK and make your first call.
Rolling your own post-quantum signing means servers, key storage, revocation and certificate tooling to build and maintain. FIPSign gives you those primitives, finished, as an API.
Every account gets 2,000 free tokens per month — a token is one billable API call. When you need more, buy token packs — they never expire and accumulate across purchases.
AWS KMS and Google Cloud KMS are key management services. FIPSign is signing, certificates, and agent authorization in one API. The difference shows up before your first signature: in the setup.
|
This is FIPSign
FIPSign
fipsign.dev
|
AWS KMS
+ ML-DSA
|
Google Cloud KMS
ML-DSA GA
|
|
|---|---|---|---|
|
Setup time
FIPSign: register, create a project, copy your API key — and create a CA from the dashboard if you need one. AWS/GCP: create an account, set up billing and IAM, then create a key (and a key ring on Google Cloud) before the first call.
|
✓
~5 minutes
|
✗
Account, billing, IAM and key setup first
|
✗
Account, billing, IAM and key setup first
|
|
What you're calling
/sign, /ca/issue, and /mandate are the whole product. On KMS, signing is one operation among hundreds — certificates and agent authorization aren't a concept at all.
|
✓
Sign, CA, Mandate
|
✗
A key management service
|
✗
A key management service
|
|
Cloud account required
FIPSign works standalone. AWS and GCP require an account, billing setup, and IAM configuration before any signing happens.
|
✓
No
|
✗
Yes — AWS account
|
✗
Yes — GCP account
|
|
Platform dependency
FIPSign is HTTP. Move to any stack, any cloud, any language without re-architecting.
|
✓
No cloud lock-in — pure REST
|
✗
Locked to AWS
|
✗
Locked to GCP
|
|
Persistent free tier
FIPSign's free tier doesn't expire. AWS KMS's always-free requests exclude asymmetric Sign and Verify, and new-account credits on AWS and Google Cloud are time-limited.
|
✓
2,000 tokens/month
|
✗
6-month credits (up to $200)
|
✗
New-customer credits (expire)
|
|
Dedicated JS/TS SDK
A focused signing SDK — sign, verify, revoke, CA certificates, Mandate, Zero-Exposure Signing. AWS and GCP SDKs expose the entire cloud API surface with hundreds of unrelated operations.
|
✓
fipsign-sdk on npm
|
✗
Generic AWS SDK
|
✗
Generic GCP SDK
|
|
Dedicated Python SDK
A focused SDK vs a generic cloud SDK that happens to include signing.
|
✓
fipsign-sdk on PyPI
|
✗
boto3 (generic)
|
✗
google-cloud-kms
|
|
Token revocation
KMS signs bytes. It has no concept of tokens, sessions, or revocation. FIPSign lets you revoke any token it issued, and remote verification checks the revocation list.
|
✓
Native — /revoke endpoint
|
✗
Not a concept
|
✗
Not a concept
|
|
Bounded authorization for AI agents
KMS signs bytes with a key — it has no concept of a session, a spending budget, or a scope that narrows over time. FIPSign's Mandate issues a credential with all three, controllable in real time.
|
✓
Mandate — scope, budget, TTL
|
✗
Not a concept
|
✗
Not a concept
|
|
Private Certificate Authority
FIPSign: create a CA from the dashboard in seconds, no cloud account needed. AWS Private CA and Google CAS require full cloud account setup, IAM, and per-certificate billing.
|
✓
Self-service — dashboard
|
✗
Requires AWS account + IAM
|
✗
Requires GCP account + IAM
|
|
MCP for Claude
FIPSign ships dedicated MCP servers, so Claude Desktop and Claude Code can sign tokens, issue certificates and manage revocation through natural language. AWS offers general-purpose API servers that can reach KMS; Google Cloud's MCP list has no Cloud KMS server.
|
✓
@fipsign/mcp · fipsign-mcp
|
✗
Generic AWS API server
|
✗
No Cloud KMS server listed
|
Competitor details checked on 1 October 2026: AWS KMS pricing · AWS Free Tier · AWS MCP servers · Google Cloud KMS ML-DSA · Google Cloud MCP products. Spot an error? [email protected]
Sign tokens, issue certificates, authorize agents. Free tokens every month. No credit card, no contract, no infrastructure to run. Just an API key.
Everything you need to know before integrating FIPSign into your stack.