Every feature, right here. This page hosts nothing itself — just a single import of dstucrypt-embed.mjs from dstucrypt.io. The key and password are entered in a secure window on our domain — your site never sees them.
The signing widget opens as a modal: choose a key and enter the password inside the iframe. The page receives only the finished signature. In this demo we sign text — CAdES, XAdES, and ASiC formats are available (all 16, including PAdES for PDF, are covered in the docs).
The signing method — Diia.Signature, Smart ID, or a key file — is chosen inside the widget itself. Diia.Signature and Smart ID sign in CAdES format; XAdES, PAdES, and ASiC require a key file.
No private key needed. Choose a signature file; for a detached signature, add the original data.
Encrypt for a recipient using their certificate (DSTU 7624 Kalyna). The result is a .p7e envelope.
Decrypt a .p7e envelope with your own key — the key and password are entered in the iframe.
Parse a certificate, check its status online (OCSP), or fetch the issuer chain.
A demo of the full flow: the page fetches a one-time challenge from our API, the widget signs it with your key, and the backend (in a real integration) verifies the signature via /api/auth/verify and receives the confirmed identity.
Identity can be confirmed via Diia.Signature, Smart ID, or a key file — the method is chosen inside the widget itself.