Native electronic signature.
No Java, no waiting.
Desktop application in Rust and React that replaces AutoFirma's Swing interface and local servers, with the Administration's official cryptography.
- Open source, EUPL 1.2
- The private key never leaves your computer
- CAdES, PAdES, XAdES and FacturaE
- In five languages
How a document gets signed
Document loaded
rFirma opens the PDF and shows what it contains: pages, size and the signatures it already carries. If there's an earlier one, yours will be a co-signature.
Choose certificate
The list is built from the system stores, the browser profiles and the PKCS#11 modules. Expired and revoked ones are shown, but can't be used.
Enter the PIN
The PIN is requested in a native dialogue, not a web window, and is wiped from memory as soon as the signature is done.
Signature complete
The signed PDF is saved next to the original, and the summary shows its format.




Four design decisions
It replaces AutoFirma's Swing interface and local servers; the cryptographic engine is the same one, from clienteafirma.
Native performance
Desktop app in Tauri v2, Rust and React. No JVM and no local servers listening.
The private key never leaves the system
Signing happens on your computer, through the system stores and the PKCS#11 modules. Java never sees it.
Official cryptography
CAdES, PAdES, XAdES and FacturaE come from the clienteafirma code, compiled to a native binary with GraalVM.
Draggable visible signature
Place and size the rubric on the page, with a faithful preview. No blind coordinates.
AutoFirma versus rFirma
| Aspect | AutoFirma (official) | rFirma |
|---|---|---|
| Architecture | Java Swing on the JVM | Tauri v2 (Rust + React) with the clienteafirma engine on GraalVM Native Image |
| Where the private key is processed | In the Java process | In the system store or the PKCS#11 module; it never leaves it |
| PIN protection in memory | Only partly wiped, and it can end up on disk | Protected in memory, never written to disk and wiped after use |
| Signing with a Spanish DNIe | Yes, via jMulticard | In development |
Certificates in a file (.p12) | The file's path is registered in a store dialogue with six options | Its own encrypted store, unlocked with your session |
| Certificate lookup | Only searches the store you pick | All in one searchable list, one certificate per row |
| Visible signature placement | Coordinates or a box with no context | Drag it onto the page, with text templates and a faithful preview |
| Browser trust in the local server | The installer registers the CA on the system, with privileges | The application registers its CA in the person's NSS stores, without root |
| Languages | Spanish only, with the Swing dialogue strings | Spanish, Catalan, Basque, Galician and English, with its own catalogue and switching from Preferences |
| Document manager | — | Remembers recent documents and the last certificate used |
| Operating systems | Windows, macOS, Linux, Android and iOS | Linux and Windows; macOS, in development |
| Update channel | Manual download of a .deb or .rpm | Native repositories: APT, DNF and Flatpak; on Windows, from the app itself |
| Desktop integration | Swing's own look | Follows the desktop's style, with light and dark themes |
One repository for your operating system
rFirma's channels are native repositories. Once your system's is added, security patches install through the package manager.
For Debian, Ubuntu and derived distributions. Sets up the repository using the modern deb822 format with the GPG key verified in /usr/share/keyrings/.
curl -fsSL https://rfirma.sgomez.me/rfirma.asc | sudo tee /usr/share/keyrings/rfirma.asc >/dev/null sudo tee /etc/apt/sources.list.d/rfirma.sources <<'EOF' Types: deb URIs: https://rfirma.sgomez.me/apt/ Suites: stable Components: main Signed-By: /usr/share/keyrings/rfirma.asc EOF sudo apt update && sudo apt install rfirma
For Fedora and RPM-based derivatives. Sets up the repository with strict cryptographic checking of metadata and packages (gpgcheck=1 and repo_gpgcheck=1).
sudo tee /etc/yum.repos.d/rfirma.repo <<'EOF' [rfirma] name=rfirma baseurl=https://rfirma.sgomez.me/rpm/ enabled=1 gpgcheck=1 repo_gpgcheck=1 gpgkey=https://rfirma.sgomez.me/rfirma.asc EOF sudo dnf install rfirma
Recommended for Linux distributions that use neither APT nor DNF. It resolves from rFirma's own ostree remote, and the org.gnome.Platform runtime is downloaded from Flathub with no setup. You only need flatpak and xdg-desktop-portal installed.
flatpak install https://rfirma.sgomez.me/rfirma.flatpakref
You can also download and double-click install the rfirma.flatpakref file if your desktop supports it.
Per-user installer, no administrator rights needed. It uses the Windows certificate store (MS-CAPI / CNG) directly and, once installed, updates from within the app: every new version arrives with its minisign signature, which is checked before installing it.
Verify what you download: get SHA256SUMS from the Release and check that the installer's hash matches its line. The installer is not Authenticode-signed, so SmartScreen will warn you when you open it.
Get-FileHash .\rFirma_*_x64-setup.exe -Algorithm SHA256 Select-String rFirma_ .\SHA256SUMS
The native version for macOS is in active development. It will integrate with Apple's Keychain and CryptoTokenKit for smooth, secure access to the system's digital identities.
It will be distributed as a .dmg disk image and through a Homebrew formula. You can follow the project's progress on GitHub.
All the code, in the open
rFirma is free, auditable software under the EUPL 1.2 licence. The code and the cryptographic engine live in two public repositories.
Application and FFI bridge
sgomez/rfirma holds the Tauri interface (Rust + React), the FFI bridge (rfirma-native-bridge) and the packaging.
Original cryptographic engine
The signing logic consumes the artefacts from ctt-gob-es/clienteafirma, compiled into a native library with GraalVM Native Image.
Package signing key
Public key at rfirma.asc. Check its fingerprint after downloading it with gpg --show-keys rfirma.asc:
C8D6 A81C 1ED4 3A28 D426 8112 A6E0 EE02 2344 6A16