Documentation · Widgets

Signature verification

The verify widget performs full validation of a signature: cryptography, the certificate chain, OCSP/CRL statuses, timestamps. No key or password is needed — this is a secret-free widget (it physically contains no key-handling code).

Minimal example

import { embed } from 'https://dstucrypt.io/embed/dstucrypt-embed.mjs';

const verifier = await embed('verify', {
    mount: '#verify-box',          //  handy to embed as a panel rather than a modal
});

const report = await verifier.verify(p7sFile);
if (report.valid) console.log('The signature is valid', report.signers);

API

const report = await verifier.verify(signature, data?);
  • signature — the signature file/bytes (.p7s, .pdf, .xml, .asics, .asice). The format is detected automatically — CMS, PDF, XML or ASiC.
  • data — the original data; needed only for a detached signature.

Result

{
  valid: true,                //  overall verdict
  signers: [{                 //  one per signer
    status: 'TOTAL-VALID',    //  TOTAL-VALID | TOTAL-FAILED | INDETERMINATE
    valid: true,
    statusSignature: 'VALID',        //  cryptographic check of the signature
    statusMessageDigest: 'VALID',    //  data integrity
    accredited: true,         //  true — from an accredited CA (this is a QES); false — not; null — not checked
    format: 'CAdES-T',
    signingTime: '2026-07-30 12:00:00',
    timestampTime: '2026-07-30 12:00:02',  //  timestamp, if present
    ocspStatus: 'GOOD',       //  certificate status via OCSP (if checked)
    crlStatus: undefined,     //  or via CRL
    signerCertId: '…',
    signerName: 'Ivanenko Ivan Ivanovych',  //  full name from the certificate (CN)
    signerOrg: 'Pryklad LLC',              //  organization (O), if different
    signerCode: '1234567890',              //  RNOKPP/EDRPOU (serialNumber)
  }],
  content: Bytes | null,      //  embedded data (for an attached signature)
}

content is a Bytes wrapper (.bytes, .text(), .download()); it lets you immediately display or save the document embedded in the signature.

accredited tells you whether this is a QES: the signer's certificate has been traced up to the official central CA (CZO) root (an accredited CA). false — the signature is valid but without QES status; null — accreditation was not checked.

Recommendation for critical decisions

The widget honestly verifies the signature in the browser — that is enough for UX (showing the user the verdict). But if, based on the verification, you make decisions on the backend (credit a payment, accept a document) — do not trust a verdict that came from the client's browser: the user controls the browser. Send the signature itself to your backend and verify it there — we provide a ready-made server API for that (below). For login with QES there is a separate ready-made flow — see Login with QES.

Server-side verification (for the backend)

Authoritative verification on our server with a native crypto core: cryptography + the chain up to an accredited CA + OCSP/CRL + timestamp. Use it for critical decisions (crediting a payment, accepting a document) — unlike the browser check, here the result is not controlled by the client.

curl -X POST https://dstucrypt.com.ua/api/verify \
  -H "Content-Type: application/json" \
  -d '{ "signature": "<base64 .p7s/.pdf/.xml/.asice>" }'
  • { "signature": "<base64>" } — the signature (format detected automatically);
  • { "signature": "<base64>", "content": "<base64>" } — for a detached signature (the original data supplied separately);
  • { "cert": "<base64>" } — verify a single certificate (accreditation + OCSP).

Response:

{
  "ok": true,                       // all signatures are cryptographically valid
  "signers": [{
    "status": "TOTAL-VALID",
    "signatureValid": true,         // signature cryptography
    "digestValid": true,            // data integrity
    "accredited": true,             // certificate from an accredited CA
    "qualified": true,              // this is a QES (accredited + valid)
    "revocation": "GOOD",           // OCSP/CRL: GOOD | REVOKED | UNKNOWN
    "signatureFormat": "CAdES-T",
    "signingTime": "2026-07-30 12:00:00",
    "timestampTime": "2026-07-30 12:00:02",
    "subject": {
      "fullName": "Ivanenko Ivan Ivanovych",
      "taxId": "1234567890",        // RNOKPP (personal tax number)
      "orgCode": "12345678",        // EDRPOU (company code)
      "issuer": "ACSK …",
      "certSerial": "…", "validFrom": "…", "validTo": "…"
    }
  }],
  "content": "<base64 of the embedded content, if attached>"
}

For the { "cert": … } mode the response is: { ok, accredited, qualified, revocation, subject }.