---
title: sign-a-message
product: vercel
url: /docs/rest-api/sdk/kms/sign-a-message
canonical_url: "https://vercel.com/docs/rest-api/sdk/kms/sign-a-message"
last_updated: 2026-09-30
type: reference
prerequisites:
  []
related:
  - /docs/rest-api
summary: Learn about sign-a-message on Vercel.
install_vercel_plugin: npx plugins add vercel/vercel-plugin
---

# Sign a message

```http
POST /v1/kms/issuers/{issuerId}/sign/message
```

Sign a raw message with a KMS issuer's active signing key. Authenticate the request with a Vercel OIDC token in the `Authorization: Bearer` header; the issuer's policies decide which workloads are allowed to sign. The response `signature` is standard-base64 of the raw signature over the decoded message bytes. `keyId`, `algorithm`, and `fingerprint` identify the signing key in the issuer's JWKS.

## Authentication

**bearerToken**: HTTP bearer

## Path parameters

| Name | Type | Required | Description |
|---|---|---|---|
| `issuerId` | string | Yes | The ID of the issuer. |


## Request body

Required: No

Content-Type: `application/json`

```json
{
  "type": "object",
  "required": [
    "message"
  ],
  "properties": {
    "message": {
      "type": "string",
      "description": "Base64-encoded message to be signed.",
      "pattern": "^[A-Za-z0-9+/]*={0,2}$",
      "maxLength": 44000
    }
  }
}
```

## Example request

```typescript
import { Vercel } from "@vercel/sdk";

const vercel = new Vercel({
  bearerToken: "<YOUR_BEARER_TOKEN_HERE>",
});

async function run() {
  const result = await vercel.kms.signKmsMessage({
    issuerId: "<id>",
  });

  console.log(result);
}

run();
```

## Example response

```json
{
  "algorithm": "string",
  "fingerprint": "string",
  "keyId": "example_id",
  "signature": "string"
}
```

## Responses

### 200: No description

Content-Type: `application/json`

```json
{
  "type": "object",
  "required": [
    "algorithm",
    "fingerprint",
    "keyId",
    "signature"
  ],
  "properties": {
    "algorithm": {
      "type": "string",
      "description": "Algorithm of the signing key."
    },
    "fingerprint": {
      "type": "string",
      "description": "SHA-256 fingerprint of the signing key's public key (`SHA256:<base64>`)."
    },
    "keyId": {
      "type": "string",
      "description": "Key id of the signing key. Matches the JWKS `kid` so verifiers can select the key after rotation without trial-verifying every published key."
    },
    "signature": {
      "type": "string",
      "description": "Standard-base64 encoding of the raw signature over the decoded message bytes."
    }
  }
}
```

### 400: One of the provided values in the request body is invalid.
One of the provided values in the request query is invalid.

### 401: No description

### 403: No description

### 404: No description

### 429: No description

---

## Related

- [kms endpoints](/docs/rest-api#kms)

- [REST API overview](/docs/rest-api)

- [OpenAPI spec](https://vercel.com/openapi.json) (machine-readable, all endpoints)

---

[View full sitemap](/docs/sitemap)
