✍️ Electronic Signature
Legally valid electronic signatures on any document of the mesh — through the provider you choose.
| Level | What it proves | Use it for |
|---|---|---|
| SES simple | intent to sign | internal sign-offs |
| AES advanced | who signed | most contracts (the default) |
| QES qualified | as a handwritten signature | anything needing written form |
QES is the only level equivalent to signing by hand — eIDAS Art. 25 in the EU, OR Art. 14 Abs. 2bis in Switzerland. The US has no tiers: any level satisfies the ESIGN Act / UETA. 🚨 EU and Swiss qualified signatures are not mutually recognised, so pick the law the document is governed by — eIDAS for EU law, ZertES for Swiss law — and sign a cross-border QES once under each.
Providers — connect one or several
| Skribble | DeepSign | Swisscom Sign | Swisscom AIS | |
|---|---|---|---|---|
| Sign in with | API user + key | Partner-Service credentials | Integration API client id + secret | your organisation's AIS contract — client certificate, customer name, key entities |
| Getting them | self-service | ask DeepCloud | your Swisscom Sign account | your contract with Swisscom Trust Services; usually set once for the whole mesh |
| Levels | SES · AES · QES | SES · AES · QES | SES · AES · QES | AES · QES (no SES in AIS) |
| Who signs | anyone on the request | the invitation mail | the invitation mail, or each signer's own link | each signer in turn, confirming on their phone (Mobile ID or password + SMS) |
Skribble (Skribble AG) issues a demo key on sign-up and production keys from your own account
(Settings → API); a mesh can also carry a Skribble API user of its own, used by everyone who has
none. DeepSign (DeepCloud AG) is not self-service — e-mail development@deepcloud.swiss.
Both issue SES, AES and QES under eIDAS and ZertES.
Swisscom Sign — Swisscom's own hosted signing platform, reached through its Integration API with an OAuth client id and secret (per person, or once for the whole mesh): Swisscom Sign mails every signer, runs the signing, and memex files the signed PDF back. A different product from AIS.
Swisscom AIS — the All-in Signing Service of Swisscom Trust Services, a Swiss qualified trust service provider — is for organisations that already hold an AIS contract:
- an operator enters the contract once (
Swisscom:Ais:*) and everyone signs with it; - memex prepares the PDF, each signer confirms on their phone, and memex embeds every signature itself as PAdES-B-LT — timestamp and CRL/OCSP data in the document, so a qualified electronic signature (QES) stays verifiable for years;
- transactions are billed by Swisscom under your contract.
Signing authority — a tab of your own settings once you hold the package — offers one chooser: pick the provider, sign in, and only that provider's fields are on screen. With one connected the request form opens on it; with several you choose per request; with none it says so and refuses to send.
What ships
Signature/SignatureRequest— one request, stored as a_Signaturerecord beside the document: provider, signers, level, jurisdiction, status, signing link and the signed PDF.Signature/Desk+Signature/Workspace— the request form, a document's signature list, the embeddable Signature block, and the provider sign-in. Get copies a desk of your own to{you}/MySignatures.Signature/SkribbleCredential,Signature/DeepSignCredential,Signature/SwisscomCredentialandSignature/SwisscomSignCredential— your sign-ins, stored encrypted at{you}/_Signature/…and never shown again (or the mesh's own configuration, for Skribble, Swisscom AIS and Swisscom Sign).- A PAdES signer of its own — incremental updates that keep every earlier signature valid, so several people can sign one PDF one after another.
- The
/signatureskill, and twoUiContributionnodes — Request Signature and Signatures on every node's menu.
Where to start
- Get the package — from your own Settings → Extensions. It installs MySignatures (your requests) and the skill.
- In Settings → Signing authority, choose a provider — Swisscom AIS, Swisscom Sign, Skribble or DeepSign — and sign in. Test connection proves it.
- Request Signature — the ✍️ action on any document you may edit.
- Sign — the button on every request awaiting signatures.
Full manual: Guide.