跳到正文

Realaoleep

SigDeck

Offline Ed25519 signing toolkit - sign files, verify signatures, exchange keys via QR. Pure-Python RFC 8032, scrypt passphrases, ASCII armor. Air-gapped signing playground.

README 已保存到本站,可直接阅读

Documentation snapshot

README 快照

本页保存的是公开项目资料快照,阅读过程不需要连接 GitHub。

SigDeck

图片:ci-python 图片:license 图片:python 图片:air-gapped

Offline Ed25519 signing toolkit - sign files, verify signatures, exchange keys via QR. Fully air-gapped: a pure-Python RFC 8032 implementation, scrypt passphrases, and ASCII armor. The signing playground for people who don’t trust their clipboard.

Why this exists

I wanted a signing tool I could run on a machine with no network at all - no pip downloads, no telemetry, no cloud. SigDeck is a single Python package with a from-scratch Ed25519 core, a passphrase-wrapped secret key format, and QR payloads for moving keys and signatures across an air gap.

Layout

sigdeck/    the Python engine (pure stdlib: keys, sign, verify, armor, qr)
app/        minimal Android demo: scan QR keys, sign, verify
docs/       guides (getting started, formats, qr exchange, shortcuts)
examples/   end-to-end recipes (signing releases, qr verification)

Quick start

$ pip install -e .
$ sd keygen --out alice.key
$ sd pub alice.key --output alice.pub
$ sd sign release.tar.gz --key alice.key
$ sd verify release.tar.gz --sig release.tar.gz.sig --pub alice.pub
Verified

The signing playground rules

  • Pure stdlib - the whole engine uses hashlib, hmac, base64, os, zlib. Nothing to download, ever.
  • Ed25519 from scratch - RFC 8032, test-vector verified (see tests).
  • Passphrase option - secret keys can be sealed with scrypt (hashlib.scrypt) so a stolen key file is still useless.
  • QR exchange - SGDK1: payloads carry public keys and signatures across air gaps (print, scan, done).

Requirements

  • Python 3.9+ (no third-party dependencies for the engine)
  • Android Studio for the demo app

Contributing

PRs welcome - see CONTRIBUTING.md. make test before push; CI mirrors it.

License

MIT - see LICENSE.

Official distribution

获取与安装

暂未发现可确认的官方软件包地址

当前 README 快照没有出现 npm、PyPI、Crates.io、pub.dev 等官方包页链接。本站不会根据仓库名称猜测下载地址。

本站不托管项目文件;需要安装时,请以项目维护者发布的官方文档为准。

使用前核验

本站保存公开资料用于阅读,不代表安全审计或功能背书。安装前请核对许可证、依赖来源和发布签名,不要直接运行来源不明的二进制文件或高权限脚本。