Providers - Options d'authentification

Créé par Lise LI, Modifié le  Mer, 27 Mai à 2:33 H par  Lise LI

This article is the technical reference for e-signature in DiliTrust. It covers two things:

  • Authentication options per provider — what methods are available to verify the signer's identity, and what eIDAS level they give
  • Technical capabilities per provider — what features are available beyond the basic signing flow

For a simpler overview of which providers are available and on which modules, see: Providers & their capabilities →


Part 1 - Authentication options by provider

⚠️ The eIDAS level of a signature depends entirely on the authentication option chosen, not just the provider. A provider that supports QES will only deliver QES if the corresponding authentication method is selected when sending the document.

DocuSign

Authentication optioneIDAS levelNotes
Standard Electronic SignatureSESEmail only, no ID proofing
Standard + SMS / Phone⚠️ Not eIDASDespite the name "Advanced", this option is not eIDAS-compliant
EU Advanced — Phone AuthenticationAESSMS or call verification code. Per-use fee applies
EU Advanced — Knowledge-Based Authentication (KBA)AESIdentity questions from public records (LexisNexis). US only, billed per use
EU Advanced — ID document checkAESSigner's government ID analyzed and matched against envelope data
EU Qualified — remote ID verificationQESSigners can store verified identity in their Identity Wallet
EU Qualified — in-person ID checkQESQualified signature with prior in-person ID verification
IDnow EU QualifiedQESQualified signature with remote ID verification via IDnow
Signer Held EU QualifiedQESCertificate stored on computer, smart card or USB

Adobe Sign

Authentication optioneIDAS levelNotes
Standard Electronic SignatureSESNo verification
Acrobat Sign AuthenticationSESRequires sign-in with Adobe account
OTP emailSESOne-time code sent to the same email as the signature link. Single-factor, no account creation required
PasswordSESSender defines a password (entered twice); signer must input it before signing
Phone authentication (2FA)AES6-digit code sent to recipient's phone
Knowledge-Based AuthenticationAESPersonal info + questions from public databases. Used in financial institutions
Government ID⚠️ UnconfirmedSigner provides government-issued photo ID + selfie
Cloud-based digital signatures⚠️ UnconfirmedSigner authenticates to a third-party identity provider to apply a digital signature

Universign

Note: Universign exists in two versions in DiliSign (V1 and V2). V2 is the active version with full feature support. V1 is legacy and has limited capabilities. The options below apply to V2.

Authentication optioneIDAS levelNotes
Standard Signature (OTP SMS)SESRequires OTP SMS authentication (unlike other providers where SES may be email-only)
Advanced SignatureAESSigner must provide a valid ID document
Advanced Signature with Qualified CertificateQESIn-person identity verification by an authorized person required
Qualified SignatureQESRequires a qualified IT system with qualified certificate

⚠️ QES availability for Universign: Universign offers QES options at the provider level, but native support within DiliSign may vary. Contact your administrator or support team to confirm QES availability for your tenant.

DropBox Sign (active on CLM) / HelloSign (active on Board/LEM)

Authentication optioneIDAS levelNotes
Standard Electronic SignatureSESNo identification required
SMS authenticationSES
eID verificationAES / QESIdentity verified via eID document. Supports both AES and QES
NOM 151 certificateQESFor documents under Mexican regulations — digital certificate for document integrity

Note: There are two configurations for this provider:

  • HelloSign on CLM (shared account, legacy) — only supports SES. Not available on Board/LEM
  • DropBox Sign on CLM / HelloSign on Board/LEM — supports SES, AES and QES as listed above

YouSign

Authentication optioneIDAS levelNotes
Standard Electronic SignatureSESNo identification
OTP AuthenticationSESOne-time code for double identity check
ID VerificationAESSigner uploads ID, instantly verified (automated + optional manual check)
Qualified SignatureQESFacial verification + identity check

Box Sign

Authentication optioneIDAS levelNotes
Standard Electronic SignatureSES
Box loginSESRecipient must log in to Box account. Enterprise Plus / Advanced plans only
SMS authenticationSESBox sends SMS to verify recipient identity
PasswordSESRecipient enters sender-provided password before signing
CAC/PIV⚠️ UnconfirmedWindows only, requires Box Tools. Uses Common Access Card or Personal Identification Verification card

Signaturit

Authentication optioneIDAS levelNotes
Standard Electronic SignatureSES
OTP SMSAESSMS verification sent to signer
ID VerificationAESAutomated real-time identity check with liveness detection
Biometric ID verification⚠️ UnconfirmedFingerprint, facial recognition or iris scan
Proof of liveness⚠️ UnconfirmedUser performs actions (blinking, head movement) to confirm real active person

Connective (Nitro Sign)

Authentication optioneIDAS levelNotes
Standard (click or drawn signature)SESAcceptance by scanned image, drawn signature, or "I accept" click
SMS OTP + Mail Access Code (2FA)SESSMS or email verification code
ID Verification + OTPSES / AESPlans with SSO and 2FA offer enhanced security
ID Verification + OIDCAES
Remote Hash SigningQES
Smart cardsQES

"⚠️ Unconfirmed" means the eIDAS classification for this option has not been formally validated. The option exists at the provider level but its legal standing under eIDAS is not yet confirmed in our documentation. Contact support if you need clarification.


Part 2 - Technical capabilities by provider and module

✱ = Feature requires UI development for Board/LEM (DT). It may work technically but is not yet available in the interface.

? = Unconfirmed — not yet validated in DiliSign. 1/p = 1 signature area per person maximum. — = Not applicable.

FeatureDocuSign DTDocuSign CLMUniv. V1 DTUniv. V1 CLMUniv. V2 DTUniv. V2 CLMSignaturit DTSignaturit CLMAdobe DTAdobe CLMYouSign DTYouSign CLMConnective DTConnective CLMDropBox DTDropBox CLMBox Sign DTBox Sign CLMGeneric API DTGeneric API CLM
Standard signature
Advanced signature??
Qualified signature* (eIDAS)
Signature order?
Signature in parallel?
Customized message?
Block placement: Signature area1/p1/p1/p1/p
Block placement: Date
Block placement: Email
Block placement: Initials
Block placement: Text
Block placement: Mention
Block placement: Read and approved
Block placement: Stamp
Email delivery status?
Webhook + Callback
Direct link to sign envelope from DiliTrust
Cancel signature process?
Modify signatories during an existing process
Accept modification of signatories by the signatories itself?
Certificate emission
Sending signature request without placeholders (block)

Related articles


If you have questions about authentication options or feature availability for your specific use case, contact your administrator or our support team.

The right authentication method ensures your signatures hold up legally — always match the option to the sensitivity of the document. ✨

Cet article a-t-il été utile ?

C'est super !

Merci pour votre commentaire

Désolé ! Nous n'avons pas pu vous être utile

Merci pour votre commentaire

Dites-nous comment nous pouvons améliorer cet article !

Sélectionner au moins l'une des raisons
La vérification CAPTCHA est requise.

Commentaires envoyés

Nous apprécions vos efforts et nous allons corriger l'article