The verify widget performs full validation of a signature: cryptography, the certificate
chain, OCSP/CRL statuses, timestamps. No key or password is needed — this is a
secret-free widget (it physically contains no key-handling code).
Minimal example
import { embed } from 'https://dstucrypt.io/embed/dstucrypt-embed.mjs';
const verifier = await embed('verify', {
mount: '#verify-box', // handy to embed as a panel rather than a modal
});
const report = await verifier.verify(p7sFile);
if (report.valid) console.log('The signature is valid', report.signers);
API
const report = await verifier.verify(signature, data?);
signature— the signature file/bytes (.p7s,.pdf,.xml,.asics,.asice). The format is detected automatically — CMS, PDF, XML or ASiC.data— the original data; needed only for a detached signature.
Result
{
valid: true, // overall verdict
signers: [{ // one per signer
status: 'TOTAL-VALID', // TOTAL-VALID | TOTAL-FAILED | INDETERMINATE
valid: true,
statusSignature: 'VALID', // cryptographic check of the signature
statusMessageDigest: 'VALID', // data integrity
accredited: true, // true — from an accredited CA (this is a QES); false — not; null — not checked
format: 'CAdES-T',
signingTime: '2026-07-30 12:00:00',
timestampTime: '2026-07-30 12:00:02', // timestamp, if present
ocspStatus: 'GOOD', // certificate status via OCSP (if checked)
crlStatus: undefined, // or via CRL
signerCertId: '…',
signerName: 'Ivanenko Ivan Ivanovych', // full name from the certificate (CN)
signerOrg: 'Pryklad LLC', // organization (O), if different
signerCode: '1234567890', // RNOKPP/EDRPOU (serialNumber)
}],
content: Bytes | null, // embedded data (for an attached signature)
}
content is a Bytes wrapper (.bytes, .text(),
.download()); it lets you immediately display or save the document embedded in the signature.
accredited tells you whether this is a QES: the signer's certificate has been traced up to
the official central CA (CZO) root (an accredited CA). false — the signature is valid but without
QES status; null — accreditation was not checked.
Recommendation for critical decisions
The widget honestly verifies the signature in the browser — that is enough for UX (showing the user the verdict). But if, based on the verification, you make decisions on the backend (credit a payment, accept a document) — do not trust a verdict that came from the client's browser: the user controls the browser. Send the signature itself to your backend and verify it there — we provide a ready-made server API for that (below). For login with QES there is a separate ready-made flow — see Login with QES.
Server-side verification (for the backend)
Authoritative verification on our server with a native crypto core: cryptography + the chain up to an accredited CA + OCSP/CRL + timestamp. Use it for critical decisions (crediting a payment, accepting a document) — unlike the browser check, here the result is not controlled by the client.
curl -X POST https://dstucrypt.com.ua/api/verify \
-H "Content-Type: application/json" \
-d '{ "signature": "<base64 .p7s/.pdf/.xml/.asice>" }'
{ "signature": "<base64>" }— the signature (format detected automatically);{ "signature": "<base64>", "content": "<base64>" }— for a detached signature (the original data supplied separately);{ "cert": "<base64>" }— verify a single certificate (accreditation + OCSP).
Response:
{
"ok": true, // all signatures are cryptographically valid
"signers": [{
"status": "TOTAL-VALID",
"signatureValid": true, // signature cryptography
"digestValid": true, // data integrity
"accredited": true, // certificate from an accredited CA
"qualified": true, // this is a QES (accredited + valid)
"revocation": "GOOD", // OCSP/CRL: GOOD | REVOKED | UNKNOWN
"signatureFormat": "CAdES-T",
"signingTime": "2026-07-30 12:00:00",
"timestampTime": "2026-07-30 12:00:02",
"subject": {
"fullName": "Ivanenko Ivan Ivanovych",
"taxId": "1234567890", // RNOKPP (personal tax number)
"orgCode": "12345678", // EDRPOU (company code)
"issuer": "ACSK …",
"certSerial": "…", "validFrom": "…", "validTo": "…"
}
}],
"content": "<base64 of the embedded content, if attached>"
}
For the { "cert": … } mode the response is: { ok, accredited, qualified, revocation, subject }.