Document workflow and ERP
Contracts and acts are signed right in the web interface, with no file exports.
One SDK to integrate QES, Diia.Signature, and Smart ID into your web product. You get a stable service and a ready-made signature — no need to dive into the fine points of cryptography.
QES · Diia.Signature · Smart ID
One SDK import — and your web app can sign with Diia.Signature, Smart ID, or a file key. You get a stable service and a ready-made signature, with no deep dive into cryptography.
Sign with Diia.Signature
How it works
A single line of code on your page — no installs, libraries, or self-hosting.
The user selects a key and enters the password inside an isolated iframe on our origin.
Your page receives only the result: signature.base64. No private data.
CAdES, PAdES, XAdES, and ASiC — with timestamps and validation data, still valid years later.
Integration
The recommended path is the iframe widget: a “signing button in 10 minutes” with maximum key isolation. Widgets load only from dstucrypt.io — origin isolation guarantees that a key leak through XSS on your site is impossible.
A single line of code on your page. Nothing to install or host on your side.
A modal or an inline block — the user selects a key and enters the password inside the iframe.
The parent page receives only the result — signature.base64 for your backend.
import { embed } from 'https://dstucrypt.io/embed/dstucrypt-embed.mjs'; const signer = await embed('sign', { mount: 'modal' }); const fileBytes = new TextEncoder().encode('Hello, world!'); const { signature } = await signer.sign(fileBytes, { format: 'CAdES-XL', digest: 'kupyna-256', // (or 'gost-34311') includeContentTS: true, }); // signature.base64 → to your backend
Formats, hashes, keys, Diia.Signature and Smart ID, automatic mode — see the full list of features →
7 days free on every new domain — just add the widget.
Who it's for
The same signing methods and the same formats — no matter what your user is signing.
Contracts and acts are signed right in the web interface, with no file exports.
Confirm payments and applications with a QES — with a complete validation data package.
CAdES-XL and PAdES with timestamps and offline verification.
The doctor's key stays with the doctor: reports are signed without handing the key over.
Applications, declarations, and QES sign-in (Login via QES) out of the box.
QES as a feature of your product — no crypto code or WASM maintenance of your own. Also fits software cash registers (PRRO): silent receipt signing with no modals.
Pricing
UAH 4,500 / month
or UAH 38,880/year — save UAH 15,120Every new domain gets 7 days free. Pay online via LiqPay — the widget works right away.
Your own widget theme and CSS, your brand instead of the badge.
Multi-signature: add a signer via signer.coSign().
Encrypt/decrypt widgets for recipient data.
UAH 3,000/hour, when needed.
FAQ
Didn't find your answer? Email sale@dstucrypt.com.ua — we reply within one business day.
No. All cryptography runs in the user's browser. The key and password are entered inside a protected window loaded from dstucrypt.io — they never reach your page's code or any server.
No — and that is a fundamental part of the security model. The widgets execute on our origin, so XSS on your site physically has no access to the key. If the files lived on your servers, the origin boundary would disappear. As a bonus, you are always on the latest version with no manual updates.
Important: the widgets and SDK are copyrighted works licensed exclusively for loading from our origin. Copying these files and hosting them on your own servers is expressly prohibited by the terms of use and the public offer — such use violates the license agreement and our proprietary rights, and we enforce them as provided by law.
Yes. Besides the file key, Diia.Signature and Smart ID from PrivatBank are supported: the user scans a QR code and confirms the action in the app — no file, no password. The document never goes anywhere: only the hash, i.e. 32 bytes, is sent to the provider. Both methods work for signing and for login, and are enabled with a single providers parameter — you don't need to build a separate integration with Diia or the bank; it's already ours.
Your backend requests a one-time challenge from us, the user signs it with their key in the widget, and your backend submits the signature to our API — we verify it cryptographically with a native core on the server and return the confirmed identity (full name, RNOKPP, EDRPOU). Verifying a QES with a JS library in the browser is not production-safe: a client-side verification result can be forged, and pure-JS DSTU cryptography has known vulnerabilities.
CAdES-BES/-T/-C/-XL, PAdES (signatures in PDF), XAdES, ASiC-S/-E. The default hash is DSTU GOST 34.311-95 (accepted by state validators such as Diia); Kupyna (DSTU 7564:2014) is enabled explicitly with the digest:'kupyna-256' option. TSP timestamps and OCSP statuses are embedded in the container — the signature can be verified offline.
PKCS#12/PFX, JKS, PKCS#8, and IIT Key-6.dat. The signing or decryption key is picked from the container automatically based on keyUsage — the user never sees technical lists.
Yes — GOST 34.311-95 is in fact the default hash: this exact pair (DSTU 4145 signature + GOST 34.311 hash) is what the Diia/central CA (CZO) state validators accept today. The modern Kupyna (DSTU 7564:2014) can be enabled explicitly (digest:'kupyna-256') for keys that support it; once state systems switch over, making it the default is an easy one-line change — no rebuild required.
Yes. The crypto core (a proven C/C++ library compiled to WebAssembly) supports the Kupyna (DSTU 7564:2014) hash function — enabled explicitly with the digest:'kupyna-256' option when signing. The keys themselves are DSTU 4145 (elliptic-curve); Kupyna only replaces the hash function paired with them, so new keys work. The default hash is DSTU GOST 34.311-95, because that exact pair (4145 signature + GOST hash) is what the Diia/central CA (CZO) state validators accept today; once state systems move to Kupyna, it can become the default with a one-line change — no rebuild. Separately: Kalyna (DSTU 7624) is data encryption, and it is supported too.
The license is tied to your domain and paid online via LiqPay — by Visa/Mastercard card, UAH 4,500/month or UAH 38,880/year. Optional add-ons: Custom design (+UAH 1,200/month or +UAH 10,368/year per domain), Multiple signers (+UAH 700/month or +UAH 6,048/year per domain), and Encryption and decryption (+UAH 900/month or +UAH 7,776/year per domain). Every new domain automatically gets 7 days free. Domains and subscriptions are managed in your account; when the paid period ends, access stops automatically.
The demos on the site are free to explore and test, and every new domain gets a 7-day free period. After that — the base subscription of UAH 4,500/month (or UAH 38,880/year).
Everything runs right on the site — not a single byte of your key ever leaves the browser. Every new domain gets 7 days free, then from UAH 4,500/month.
Tools with no integration required: sign a file · verify a signature