PAdES · CAdES · XAdES · Mobile Signature
eimzaonay adds qualified electronic signatures compliant with e-Signature Law No. 5070 to your application through a single REST API. Upload the document, let your user approve with their smart card or mobile signature, download the legally valid result.
How it works
The cryptographic burden is entirely on our side; your application makes just three REST calls. The user's private key never leaves their card or phone at any step.
Send a PDF, Office file or any document to the API; we convert it to PDF if needed and place the visual signature field. You get an operation ID in return.
POST /v1/files/uploadThe user's browser signs with their smart card through the desktop E-Signature app — or they approve the mobile-signature request on their phone with a single tap.
POST /v1/pades/signThe long-term-validatable (LTV) signed document is ready. A timestamp and a QR verification layer are added on request.
POST /v1/files/downloadArchitecture
Certificate handling, signature protocols, card drivers, mobile-operator integrations — all inside the platform. You just call the API.
Your side
Your existing application; calls three endpoints with an API key.
Our side
Authentication, quotas, records and signature orchestration in one place.
User side
Triggered from the browser; the signature is created locally.
Core principle: The private key never touches the network. The platform only delivers the digest to be signed and seals the signed result into the document. No key hand-over, storage or delegation.
Signature formats
From contracts to e-invoices, HR paperwork to enterprise XML integrations — the standard for every document type is ready.
PDF signing with visual signature fields for contracts, forms and official correspondence. Serial and parallel multi-signing, page positioning, stamp and layer support.
CMS- and XML-based signatures for e-invoice, e-ledger, registered e-mail attachments and enterprise data exchange. With every profile level the regulations require.
Signing without a card or reader over Turkcell, Vodafone and Türk Telekom mobile-signature lines. A request lands on the user's phone and is approved with a PIN.
Converting Office documents to PDF, adding signature fields and visual layers, stamping QR verification seals — all pre-signing preparation lives in the API.
Integration
No mandatory SDK, no certificate setup. Put your API key in a header and call three endpoints.
Management and licensing
A dedicated management panel per customer: live quota status, usage breakdown, key lifecycle and billing records.
Keys are stored as SHA-256 digests, created and revoked instantly from the panel. One click disables a leaked key.
Remaining signatures, period usage and consumption trend live in the panel. Threshold alerts mean no surprises.
Per-operation records: which key, which format, how long it took, what the outcome was. Audit and reconciliation ready.
For teams with predictable monthly volume
For variable volumes and those just starting out
For high-volume enterprise use
Verification
A QR verification seal is stamped onto the signed document on request. Anyone holding the document — the counterparty, an auditor, a court — confirms identity and integrity in seconds.
Desktop app
End users install it once: insert the card, enter the PIN, sign. It recognises common smart cards including AKİS and updates itself. Distribution is not your problem.
Let's begin
Request a trial API key; our engineers stay with you throughout the integration. For pricing, just share your volume.