Signatures and identity for your application
Enroll people, issue their signing certificates and ask them to sign, through one API. Start in a sandbox that needs no approval.
curl $BASE_URL/v1/signature-requests \
--cert app.pem --key app-key.pem \
-H "Authorization: Bearer $TOKEN" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{
"subscriber_id": "sub_sbxScenarioApprovalSand0001",
"certificate_profile_id": "prf_4Hq8NcLx5Qw9Bj4M",
"document_hash": {
"algorithm": "sha-256",
"value": "9f86d081884c7d65…"
},
"signature_format": "pades",
"validity_window_seconds": 900
}'import { Agent } from 'undici';
// Your workload certificate, for mutual TLS.
const dispatcher = new Agent({ connect: { cert, key } });
const res = await fetch(`${BASE_URL}/v1/signature-requests`, {
method: 'POST',
dispatcher,
headers: {
Authorization: `Bearer ${token}`,
'Idempotency-Key': crypto.randomUUID(),
'Content-Type': 'application/json',
},
body: JSON.stringify({
subscriber_id: 'sub_sbxScenarioApprovalSand0001',
certificate_profile_id: profileId,
document_hash: { algorithm: 'sha-256', value: sha256(pdf) },
signature_format: 'pades',
validity_window_seconds: 900,
}),
});import requests, uuid
res = requests.post(
f"{BASE_URL}/v1/signature-requests",
cert=("app.pem", "app-key.pem"), # mutual TLS
headers={
"Authorization": f"Bearer {token}",
"Idempotency-Key": str(uuid.uuid4()),
},
json={
"subscriber_id": "sub_sbxScenarioApprovalSand0001",
"certificate_profile_id": profile_id,
"document_hash": {"algorithm": "sha-256", "value": sha256(pdf)},
"signature_format": "pades",
"validity_window_seconds": 900,
},
)POST /v1/signature-requests 201 Created
{
"id": "sig_7GQ2nXv8LpRk4Tb1",
"status": "push_notification_sent",
"signature_format": "pades",
"expires_at": "2026-09-25T10:15:00Z"
}The person approves on their phone.
GET /v1/signature-requests/sig_7GQ2nXv8LpRk4Tb1 200 OK
{
"id": "sig_7GQ2nXv8LpRk4Tb1",
"status": "completed",
"signed_at": "2026-09-25T10:02:41Z",
"signature_value": "MEUCIQDkq1vX0…"
}What your integration does
Find the person
Resolve your customer to one ePahichan subscriber from identifiers you have verified. The same person is one record however many organizations know them.
POST /v1/subscribers/resolutionEnroll them for a certificate
Open an enrollment with the application details, submit it and follow the decision. The certificate is delivered to the person's own device.
POST /v1/enrollmentsAsk them to sign
Send the hash of your document. They approve on their phone and you receive the signature. The document itself never leaves your systems.
POST /v1/signature-requestsHear what happened
Receive signed events as enrollments are decided, certificates issued and signatures completed, instead of polling for them.
POST /v1/applications/{id}/webhook-endpoints