DSTUcrypt provides ready-made QES iframe widgets for your website: signing, verification,
encryption, certificates and sign-in with a qualified electronic signature (QES). The widgets load
only from dstucrypt.io — you install and host nothing.
Getting connected — a single import
import { embed } from 'https://dstucrypt.io/embed/dstucrypt-embed.mjs';
const signer = await embed('sign', { mount: 'modal' });
const { signature } = await signer.sign(file, { format: 'CAdES-T', digest: 'gost-34311' });
signature.download('document.p7s');
Widgets
| Type | Widget page | What it does | Key/password |
|---|---|---|---|
sign |
/embed/sign.html |
Document signing | inside the iframe |
verify |
/embed/verify.html |
Signature verification | not required |
auth |
/embed/auth.html |
Sign-in with QES | inside the iframe |
encrypt |
/embed/encrypt.html |
Encryption | not required |
decrypt |
/embed/decrypt.html |
Decryption | inside the iframe |
cert |
/embed/cert.html |
Certificates | not required |
Parameters of embed(type, opts)
You do not pass any file URLs — the SDK builds the widget address itself, from dstucrypt.io.
All you need is the action (first argument) and options:
| Option | Value | Description |
|---|---|---|
mount |
'modal' | CSS selector | Element |
modal window (default) or embed into your own block ('#box') |
session |
true | { ttlMinutes, noPin } |
automatic mode — a stored key without a password prompt every time (sign/decrypt/auth) |
branding |
false |
remove the “Protected by DSTUcrypt” badge (paid option) |
theme / styles / css / brand |
objects / string | Custom design — theme, CSS and your own brand (paid option) |
allowOrigin |
origin | restrict postMessage acceptance to a specific origin (usually not needed) |
Each widget is a separate iframe dedicated to a single task. In the modal, the iframe automatically
grows to fit its content. When a widget is no longer needed — widget.destroy().
There is also a service option
src(widget URL override) — for local development only; it is not used in a normal integration.
The result is Bytes — no base64
Widget methods return bytes wrapped in Bytes:
signature.bytes // Uint8Array
signature.size // number of bytes
signature.text() // as a string (if it is text)
signature.download('document.p7s') // download the file
signature.base64 // base64 string (for sending to the backend as JSON)
As input, the methods accept File, Uint8Array, ArrayBuffer or a string —
no conversions needed.
License and trial period
- 7 days free on every new domain — automatic, no registration: just embed the widget. The widget shows a banner with the days remaining.
localhostis always free (developer mode, with a banner).- After that — the base subscription of UAH 4,500/month or UAH 38,880/year per domain. Domain management and payment are handled in your account (LiqPay).
- When the period ends, the widget on that domain stops automatically.
Questions and onboarding: sale@dstucrypt.com.ua.