Short answer. PAdES (PDF Advanced Electronic Signatures) is a standard that embeds a qualified electronic signature directly into the structure of a PDF file. The output is a single signed PDF, not a document plus a separate signature file. In DSTUcrypt, signing a PDF uses the same widget as all the other formats: embed('sign') and a call to sign(pdfBytes, { format: 'PAdES-B-T', fileName: 'contract.pdf' }). All the cryptography runs in the user's browser — the key and password never leave their device.
Why PAdES beats a separate .p7s next to the PDF
There are two ways to sign a PDF. The first is a regular CMS signature (CAdES) as a separate .p7s file sitting next to the PDF. The second is PAdES, where the signature is embedded inside the PDF itself. For documents that people read, PAdES is almost always more convenient:
- One file. You send, store, and upload a single PDF. There is no risk of the document and its signature accidentally parting ways.
- Clear to the recipient. A signed PDF opens like any ordinary PDF; readers that support PAdES show that a signature is present.
- The standard for document workflow. PAdES is the European ETSI standard series for signing PDF specifically — the counterpart of CAdES for arbitrary data.
A separate .p7s (CAdES) remains appropriate when you sign non-PDF data — for example, an arbitrary file or a structure consumed by another system. A comparison of all the formats is in the article "Electronic signature formats: CAdES, PAdES, XAdES, ASiC — which to choose".
How PAdES works
Technically, PAdES takes the same cryptographic CMS signature as CAdES but places it in a dedicated location inside the PDF defined by the format. The signature therefore lives in the same file as the document and travels with it. As in CAdES, the signature has "maturity" levels — from basic to long-term.
PAdES levels: which one to choose
| Level | What it adds | When you need it |
|---|---|---|
| PAdES-B-B | a basic signature (the mere fact of signing with a key) | internal documents, drafts, when time is not critical |
| PAdES-B-T | a TSP timestamp — proves the moment of signing | most contracts and applications: the recommended starting point |
| PAdES-B-LT | certificate status data (OCSP/CRL) for long-term verification | documents stored for years |
| PAdES-B-LTA | an archival timestamp on top of everything — the most durable level | archives, legally critical documents, tenders |
A practical rule: for everyday documents take PAdES-B-T; for documents that must remain verifiable many years later — PAdES-B-LTA. Durability is covered in detail in the article "Long-term electronic signatures: CAdES-XL and PAdES-LTA".
Step by step: signing a PDF in DSTUcrypt
The entire integration is a single SDK import and a signing call. The user picks their key and enters the password inside an isolated window on our domain — your page never sees them.
signing a PDF with the PAdES standard
import { embed } from 'https://dstucrypt.io/embed/dstucrypt-embed.mjs';
const signer = await embed('sign', { mount: 'modal' });
// pdfBytes — File | Blob | ArrayBuffer | Uint8Array of your PDF
const { signature } = await signer.sign(pdfBytes, {
format: 'PAdES-B-T', // signature inside the PDF + timestamp
fileName: 'contract.pdf', // name for the PDF container
// digest: 'kupyna-256', // optional: Kupyna hash instead of GOST 34.311
});
signature.download('contract-signed.pdf'); // the finished signed PDF
// or signature.bytes / signature.base64 — to pass to your backend
The result is a finished PDF with the signature embedded. The fileName option sets the name inside the container, and you can either hand the file straight to the user via signature.download() or send it to your backend as signature.bytes/signature.base64.
One widget — all formats. The same embed('sign') signs not only PDF (PAdES) but also CAdES (.p7s), XAdES (XML), and ASiC containers — 16 formats in total. The crypto core is a proven native C/C++ library compiled to WebAssembly that has served Ukrainian PKI for years. The key and password never reach your server or ours; TSP timestamps and OCSP data are embedded into the container through our proxy — you configure nothing.
Kupyna or GOST 34.311 hash for PDF
As with the other formats, a PDF is signed by default with the DSTU GOST 34.311-95 hash — exactly the pair (DSTU 4145 signature + GOST) that government validators Diia/CZO accept today. The modern Kupyna (DSTU 7564:2014) is enabled explicitly with the digest:'kupyna-256' option. What this standard is and when to choose it — read the article "Kupyna (DSTU 7564:2014): what this hash function is and why it replaces GOST 34.311-95".
How to verify a signed PDF
You can verify a signature in a PDF with the same SDK — the verify widget detects the format from the file contents (PAdES for PDF) and returns the status, the signer, and a flag telling whether it is indeed a QES (an accredited provider). For one-off checks without an integration there is a free online tool at dstucrypt.com.ua/verify.
Frequently asked questions
Will the signature be visible when the PDF is opened in Adobe Acrobat?
A PAdES signature is embedded directly into the structure of the PDF file — it is one document, not a separate .p7s alongside it. Readers that support PAdES recognize the signature inside the file. For a cryptographically complete verification (trust chain, certificate status, timestamp), use the verification widget or the free tool at dstucrypt.com.ua/verify.
Why is PAdES better than a separate .p7s signature file next to the PDF?
PAdES keeps the signature inside the PDF itself, so you send and store one file that cannot accidentally be separated from its signature. A separate .p7s (CAdES) means two files that are easy to split apart; it makes sense when you are signing non-PDF data.
Which PAdES level should I choose?
PAdES-B-B is the basic signature. PAdES-B-T adds a TSP timestamp (proves the moment of signing). PAdES-B-LT and PAdES-B-LTA add data for long-term verification, when the document must remain verifiable for years. For most documents B-T is enough; for archives and legally critical documents — B-LTA.
Can I sign a PDF with the Kupyna hash?
Yes. The default hash is DSTU GOST 34.311-95 (the one government validators accept), and Kupyna (DSTU 7564:2014) can be enabled with the digest:'kupyna-256' option — the same way as for the other formats.
Read also
- Electronic signature formats: CAdES, PAdES, XAdES, ASiC — which to choose
- Long-term electronic signatures: CAdES-XL and PAdES-LTA
- How to add QES to your website in 10 minutes: an iframe widget with no backend
DSTU PDF signing — on your website
A ready-made widget for PAdES and every other signature format. The key and password never leave the browser. Sign a one-off file with the free /sign tool; every new domain gets 7 days free.
Sign a fileHow to connect