Features

Everything DSTUcrypt widgets can do — from 16 signature formats to background sessions for software cash registers (PRRO). Every feature runs right in the user's browser: the key and password never reach your server — or ours.

Signing and verification

DSTU standards — the same ones used by Diia and state registries

QES signing — 16 formats

CAdES-BES/-T/-C/-XL, PAdES-B-B/-B-T/-B-LT/-B-LTA (in PDF), XAdES-BES/-B-T/-B-LT/-B-LTA (in XML), ASiC-S/-E (-BES/-T). Attached and detached, signing a single file or a whole batch at once. TSP and OCSP responses are embedded in the container — the signature verifies offline and remains valid years later.

Hash functions

The default is DSTU GOST 34.311 — exactly the pair accepted by government validators. The modern Kupyna (DSTU 7564) is enabled with a single digest option. Legacy GOST keys and new ones work side by side — migration without disruption.

Signature verification

Full validation: cryptography, certificate chain, OCSP/CRL, timestamps. The format is detected automatically — CMS, PDF, or XML. The server-side /api/verify additionally reports whether the certificate was issued by an accredited provider (i.e. whether it is a QES).

Kalyna encryption

EnvelopedData per DSTU 7624: encrypt for a recipient using their certificate, decrypt with your own key. Separate encrypt and decrypt widgets.

Certificates

View certificate contents right in the widget. If the key file contains no certificate (typical for Key-6.dat), we fetch it from the provider's server via CMP or accept it as a file.

All key formats

PKCS#12/PFX, JKS, PKCS#8, and IIT Key-6.dat. The key is auto-selected from the container by keyUsage — users never see technical lists.

No key file

The key stays in the user's app — Diia or Privat24

Diia.Signature

The user scans a QR code and confirms the signature in the Diia app. Only the hash is sent to the provider — the document never leaves the device. Enabled with a single providers parameter.

Smart ID

Signing with a key from Privat24 — for PrivatBank customers. The same flow: QR code, confirmation on the phone, a ready signature in response.

QES login

Sign-in with any method — a key file, Diia.Signature, or Smart ID. The widget signs a one-time challenge, and your backend receives a verified identity via /api/auth/verify: full name, RNOKPP (personal tax number), EDRPOU (company code).

Modes and integration

One import — everything else works out of the box

Ready-made widgets

Signing, verification, encryption, certificates, QES login — separate iframes served from our domain. The parent page receives only the result — all cryptography runs isolated on our domain.

Automatic mode

With the user's consent, the key is stored encrypted (PIN, PBKDF2) in our origin — from then on, signatures run in a background session with no modals. This is exactly how a PRRO cash register signs every receipt without the cashier's involvement.

Branding

The "Secured by DSTUcrypt" badge can be removed (white-label). The paid "Custom design" option gives you your own theme, CSS, and your brand inside the widget.

WebAssembly security

A proven native C/C++ library compiled to WASM: constant-time execution, a correct one-time k, entropy from the browser's CSPRNG. Near-native speed even on old hardware.

Key isolation

The key and password are entered inside an iframe on a different origin. Even an XSS on your site cannot reach the key or the password — this is the foundation of the security model, not an option.

Production-grade, not an experiment

Predictable updates and ongoing maintenance — in contrast to open-source JS implementations of DSTU with no constant-time guarantees and no support.

Try it live

Every feature has a live demo — right on the site, no sign-up required. Every new domain gets 7 days free.