Skip to content
QUALIFIED TRUST SERVICES

Legally compliant digital signatures (eIDAS) to drive forward the digitalization of your business processes.

CORPORATE TRUST SERVICES

Cryptography-based trust services
to protect your digital identities,
data and business secrets.

Qualified electronic signature products based on eIDAS - legally binding and secure.

API GUIDE

Upgrade your application with electronic signatures by primesign.





DOCUMENT SIGNING API

Signing of PDF documents. primesign handles document processing and adds a visual signature stamp.

HASH SIGNING API

Signing of hash values. Your application handles document processing and provides the document viewer.

CASH BOX API

RKSV-compliant JWS- or raw signatures for cash box receipts.





primesign TRUST CENTER

All documents for our qualified trust services, certificate revocation list, root-/CA- certificates, etc.

RESOURCES

Fact sheets, product documentation and more.



BLOG

Insights on digital signatures, eIDAS and trust services.

BG_ICON_ARROW_3-1
Back to all questions

Document Signing API or Hash Signing API — which do I need?

The difference is who processes the document. With the Document Signing API you hand the PDF to primesign; the service prepares it, applies the visible signature stamp and returns the signed document.

With the Hash Signing API your application calculates the hash value itself and transmits only that value — the document never leaves your system boundary. The choice of API does not change the signature level achieved: hash signing also produces a full qualified electronic signature with identical evidential weight.

Here's how the two interfaces differ:

  • Document preparation: Document Signing API: handled by the service. Hash Signing API: handled in your application, including PDF generation and signature rendering.
  • Data transmitted: Document Signing API: the complete PDF. Hash Signing API: only the hash value — a fingerprint carrying no content.
  • Document viewer: Document Signing API: provided by the service. Hash Signing API: your application displays the document itself.
  • Implementation effort: Document Signing API: lower, since formatting and PAdES generation happen centrally. Hash Signing API: higher, in exchange for maximum control.
  • Data protection profile: Hash signing is the most data-minimal option and the right choice for particularly sensitive content.
  • Legal effect: Identical. Both routes produce the same qualified electronic signature under eIDAS.

When each API is the right choice:

  • Document Signing API: Applications without their own PDF viewer, with no special confidentiality constraints, and where consistent signature rendering is preferred.
  • Hash Signing API: Personnel files, health data and other highly sensitive content; very large files; architectures built on strict GDPR data minimisation.
  • Cash Box API: For signing cash register receipts under the Austrian cash register security regulation (RKSV), a dedicated interface is available.

primesign provides both interfaces backed by the same qualified trust service. That allows the decision to be made per use case without changing provider — for example Document Signing for sales documents and Hash Signing for personnel files within the same organisation.

Benefits

  • Data protection requirements met precisely per use case
  • Fast initial integration, later switch without changing provider
  • No transfer of large files at high volumes
  • Full control over signature rendering where required
  • Identical legal effect regardless of the route chosen

Still have questions?

Unsure which API fits? Our developer team can advise.

Talk to an expert