One SDK for QES integration in Ukraine
dstucrypt

One SDK to integrate QES, Diia.Signature, and Smart ID into your web product. You get a stable service and a ready-made signature — no need to dive into the fine points of cryptography.

DSTU4145 · 7564 · 7624

QES · Diia.Signature · Smart ID

One SDK for QES integration.
No crypto code.

One SDK import — and your web app can sign with Diia.Signature, Smart ID, or a file key. You get a stable service and a ready-made signature, with no deep dive into cryptography.

  • 7 days free on every new domain
  • Activation immediately after payment

Signing

Sign with Diia.Signature

Signing method
Diia.Signature
The signature is created in the Diia app
ID
Smart ID
You need to be a PrivatBank client
File key
The key and document never leave the device
Sign

How it works

Four steps from a script to a legally valid signature

01

One SDK import

A single line of code on your page — no installs, libraries, or self-hosting.

02

The key stays in the browser

The user selects a key and enters the password inside an isolated iframe on our origin.

03

A ready signature

Your page receives only the result: signature.base64. No private data.

04

Formats for state registers

CAdES, PAdES, XAdES, and ASiC — with timestamps and validation data, still valid years later.

Integration

How to integrate

The recommended path is the iframe widget: a “signing button in 10 minutes” with maximum key isolation. Widgets load only from dstucrypt.io — origin isolation guarantees that a key leak through XSS on your site is impossible.

1

Import dstucrypt-embed.mjs

A single line of code on your page. Nothing to install or host on your side.

2

Call embed('sign' | 'verify' | 'auth' | …)

A modal or an inline block — the user selects a key and enters the password inside the iframe.

3

Get the finished result

The parent page receives only the result — signature.base64 for your backend.

embed.mjs — on any website
import { embed } from
  'https://dstucrypt.io/embed/dstucrypt-embed.mjs';

const signer = await embed('sign', { mount: 'modal' });

const fileBytes = new TextEncoder().encode('Hello, world!');
const { signature } = await signer.sign(fileBytes, {
  format: 'CAdES-XL',
  digest: 'kupyna-256', // (or 'gost-34311')
  includeContentTS: true,
});

// signature.base64 → to your backend

Formats, hashes, keys, Diia.Signature and Smart ID, automatic mode — see the full list of features →

Ready to integrate?

7 days free on every new domain — just add the widget.

Terms and pricing →

Who it's for

One widget — any industry

The same signing methods and the same formats — no matter what your user is signing.

Illustration: a document with a digital signature and seal

Document workflow and ERP

Contracts and acts are signed right in the web interface, with no file exports.

Illustration: a bank, a payment card, and a verification shield

Banks and fintech

Confirm payments and applications with a QES — with a complete validation data package.

Illustration: scales of justice, a document, and a timestamp

Legal services

CAdES-XL and PAdES with timestamps and offline verification.

Illustration: a medical report, a stethoscope, and a signing key

Healthcare systems

The doctor's key stays with the doctor: reports are signed without handing the key over.

Illustration: signing in to a user account in a browser

Portals and accounts

Applications, declarations, and QES sign-in (Login via QES) out of the box.

Illustration: modular widget integration into a SaaS product

SaaS products and PRRO

QES as a feature of your product — no crypto code or WASM maintenance of your own. Also fits software cash registers (PRRO): silent receipt signing with no modals.

Pricing

One license per domain. No per-signature fees

UAH 4,500 / month

or UAH 38,880/year — save UAH 15,120

Every new domain gets 7 days free. Pay online via LiqPay — the widget works right away.

  • A ready-to-embed JS widget for your website
  • Creating and verifying QES under the DSTU standard
  • File keys (PKCS#12/PFX, JKS, Key-6.dat)
  • User authentication (Login via QES)
  • 1,000 free signatures (timestamps) per day
  • License for 1 domain, activated immediately after payment

Custom design

+UAH 1,200/month

Your own widget theme and CSS, your brand instead of the badge.

Multiple signers

+UAH 700/month

Multi-signature: add a signer via signer.coSign().

Encryption

+UAH 900/month

Encrypt/decrypt widgets for recipient data.

Technical support and integration

UAH 3,000/hour, when needed.

FAQ

Frequently asked questions

Didn't find your answer? Email sale@dstucrypt.com.ua — we reply within one business day.

Does the key or password ever reach a server?

No. All cryptography runs in the user's browser. The key and password are entered inside a protected window loaded from dstucrypt.io — they never reach your page's code or any server.

Can I host the widgets myself?

No — and that is a fundamental part of the security model. The widgets execute on our origin, so XSS on your site physically has no access to the key. If the files lived on your servers, the origin boundary would disappear. As a bonus, you are always on the latest version with no manual updates.

Important: the widgets and SDK are copyrighted works licensed exclusively for loading from our origin. Copying these files and hosting them on your own servers is expressly prohibited by the terms of use and the public offer — such use violates the license agreement and our proprietary rights, and we enforce them as provided by law.

Can users sign without a key file — via Diia or Privat24?

Yes. Besides the file key, Diia.Signature and Smart ID from PrivatBank are supported: the user scans a QR code and confirms the action in the app — no file, no password. The document never goes anywhere: only the hash, i.e. 32 bytes, is sent to the provider. Both methods work for signing and for login, and are enabled with a single providers parameter — you don't need to build a separate integration with Diia or the bank; it's already ours.

How does QES login (user authentication) work?

Your backend requests a one-time challenge from us, the user signs it with their key in the widget, and your backend submits the signature to our API — we verify it cryptographically with a native core on the server and return the confirmed identity (full name, RNOKPP, EDRPOU). Verifying a QES with a JS library in the browser is not production-safe: a client-side verification result can be forged, and pure-JS DSTU cryptography has known vulnerabilities.

Which signature formats are supported?

CAdES-BES/-T/-C/-XL, PAdES (signatures in PDF), XAdES, ASiC-S/-E. The default hash is DSTU GOST 34.311-95 (accepted by state validators such as Diia); Kupyna (DSTU 7564:2014) is enabled explicitly with the digest:'kupyna-256' option. TSP timestamps and OCSP statuses are embedded in the container — the signature can be verified offline.

Which key files are supported?

PKCS#12/PFX, JKS, PKCS#8, and IIT Key-6.dat. The signing or decryption key is picked from the container automatically based on keyUsage — the user never sees technical lists.

Will older keys with GOST 34.311 still work?

Yes — GOST 34.311-95 is in fact the default hash: this exact pair (DSTU 4145 signature + GOST 34.311 hash) is what the Diia/central CA (CZO) state validators accept today. The modern Kupyna (DSTU 7564:2014) can be enabled explicitly (digest:'kupyna-256') for keys that support it; once state systems switch over, making it the default is an easy one-line change — no rebuild required.

Is the modern Kupyna (DSTU 7564) supported? Will new keys work?

Yes. The crypto core (a proven C/C++ library compiled to WebAssembly) supports the Kupyna (DSTU 7564:2014) hash function — enabled explicitly with the digest:'kupyna-256' option when signing. The keys themselves are DSTU 4145 (elliptic-curve); Kupyna only replaces the hash function paired with them, so new keys work. The default hash is DSTU GOST 34.311-95, because that exact pair (4145 signature + GOST hash) is what the Diia/central CA (CZO) state validators accept today; once state systems move to Kupyna, it can become the default with a one-line change — no rebuild. Separately: Kalyna (DSTU 7624) is data encryption, and it is supported too.

How do payment and activation work?

The license is tied to your domain and paid online via LiqPay — by Visa/Mastercard card, UAH 4,500/month or UAH 38,880/year. Optional add-ons: Custom design (+UAH 1,200/month or +UAH 10,368/year per domain), Multiple signers (+UAH 700/month or +UAH 6,048/year per domain), and Encryption and decryption (+UAH 900/month or +UAH 7,776/year per domain). Every new domain automatically gets 7 days free. Domains and subscriptions are managed in your account; when the paid period ends, access stops automatically.

Are the demos free? What about the license?

The demos on the site are free to explore and test, and every new domain gets a 7-day free period. After that — the base subscription of UAH 4,500/month (or UAH 38,880/year).

Try it right now

Everything runs right on the site — not a single byte of your key ever leaves the browser. Every new domain gets 7 days free, then from UAH 4,500/month.

Tools with no integration required: sign a file · verify a signature