# SecurySign developer documentation

SecurySign provides APIs for identity verification, digital signatures, single sign-on and document encryption.

Identity verification reads the submitted document’s details and portrait, checks the face capture for liveness, and compares the captured face with that portrait. API signing starts with a document hash or a PDF and asks the signer to approve with a passkey. Once that approval has been verified, SecurySign signs with a key held in a hardware security module (HSM) and returns the signer’s X.509 certificate for verification.

## What you can build

| Your task | How you integrate it | Guide |
|---|---|---|
| Sign users in | Redirect through OpenID Connect (OIDC), then exchange the authorization code for tokens. | [Single sign-on](#/docs/sso) |
| Verify a customer's identity | Submit document images and the transaction ID from a live face capture; read the verdict and extracted fields. | [KYC](#/docs/kyc) |
| Enrol a signer | Open the hosted enrolment link and exchange the code returned to your callback. | [Enrolment](#/docs/enrolment) |
| Collect a signature on your page | Request a signing token on your backend and pass it to the signing iframe. | [Iframe](#/docs/iframe) |
| Sign from your backend | Create a hash-signing request, or prepare a PDF; collect the customer's passkey approval in the signing frame. | [Hash signing API](#/docs/api-hash-signing), [PAdES signing API](#/docs/api-pades-signing) |
| Verify a signature | Check the signed bytes, the signer's certificate and its revocation status. | [Verification API](#/docs/api-certificates) |
| Encrypt a document | Encrypt on the device, encrypt the file key with the user's public key and store the encrypted result. | [Encryption API](#/docs/api-encryption) |

Start by [registering your application](#/docs/rp-integration-guide) as a relying party (RP) to obtain its credentials and approved configuration. The [Quick start](#/docs/quickstart) then walks through embedding the signing iframe, from requesting a token to receiving a signature.

## Get the OpenAPI spec

The [OpenAPI specification](/docs/openapi.json) contains the authentication requirements, request schemas and responses for each operation. It can be imported into Postman or used to generate a client.
