what am i signing?

paste a wallet signature request, get it in plain english with risk flags.

what your wallet asks you to signtyped data json, calldata 0x…, or a message
read it as
try

paste the request from your wallet (or the dapp's console) to get a plain-english reading: who gets access to what, for how long, and what looks off.

about this tool

Paste a signature request from your wallet, whether EIP-712 typed data, transaction calldata or a personal_sign message, and get a plain-English summary of who gets access to what and for how long, with a low / medium / high risk verdict. It recognises ERC-20 approvals and permits, Uniswap Permit2, setApprovalForAll, Seaport orders, Safe transactions (including delegatecall) and blind 32-byte hashes, and flags unlimited amounts, far-off deadlines and orders where you receive nothing.

good to know

can signing a message lose me money?

yes. a permit, permit2 or seaport order signature needs no transaction from you: whoever holds it can submit it later and move your tokens or nfts. plain text messages and sign-in requests can’t move funds on their own.

why is an unlimited approval flagged as high risk?

it lets the spender take every token of that kind you hold, now and later, until you revoke it. if that contract is ever hacked, or was a scam from the start, the whole balance is exposed. approve only the amount you need.

what is blind signing?

signing a bare 32-byte hash (eth_sign style). you can’t see what it stands for, and it can be the hash of a transaction or permit that empties your wallet. honest apps almost never need it: reject it unless you know exactly why.