Environments
Pre-production
The pre-production environment is available to all customers to facilitate integration, demonstrations, and regression testing.
Accounts and data created in the pre-production environment are persistent, mirroring the behavior of our production environment. However, in rare cases, data may be purged or reverted to a previous state.
While we do not provide a formal SLA for the pre-production environment, our teams strive to ensure its reliability and availability to support your needs.
There are no usage fees for the pre-production environment, as the provided certificates are for testing purposes and cannot be used in production.
REST API Base URL
https://mtl.sandbox.pre.swissid.ch/rss/admin
Security
Like our production environment, API in the pre-production environment are secured using the following mechanisms:
- IP address whitelisting
- mTLS client certificate authentication
- Basic Authentication
You must provide your system’s IP address(es) during registration. After your account is set up, we will provide the mTLS client certificate and Basic Authentication credentials.
By default, the mTLS certificate requires renewal every two years.
Mobile application
A dedicated SwissSign Wallet Preview app is available for testing the Qualified Electronic Signature use case in the pre-production environment.
The end-user will be guided into the installation of the app at signing time.
Signing Service Profiles
| Signature type | Signing Room & Web Client | Hash signing | Document Certification |
|---|---|---|---|
| Qualified Electronic Signature | swisssign-qes-zertes | scs-swisssign-qes-zertes | N/A |
| SwissSign QES ZertES - Per user billing | swisssign-qes-zertes-ppu | scs-swisssign-qes-zertes-ppu | N/A |
| SwissSign QES eIDAS | swisssign-qes-eidas | scs-swisssign-qes-eidas | N/A |
| SwissSign AES | swisssign-aes | scs-swisssign-aes | N/A |
| SwissSign SES | swisssign-ses | N/A | N/A |
| SwissSign SES with SMS auth | swisssign-ses-with-sms | N/A | N/A |
| Swisscom Fasttrack | swisscom-fasttrack | scs-swisscom-fasttrack | N/A |
| Identification LoT1 | identification-lot1 | N/A | N/A |
| Identification LoT2 | identification-lot2 | N/A | N/A |
| Simple Electronic Signature | swisssign-seal | N/A | N/A |
| SwissSign document seal | demo-seal | scs-demo-seal | Note(1) |
| SwissSign document seal (alternate) | demo-seal-alt | scs-demo-seal-alt | Note(1) |
| SCS SwissSign SES | N/A | scs-demo-ses | Note(2) |
| SCS SwissSign SES with SMS | N/A | scs-demo-ses-with-sms | Note(2) |
Note(1): Document certification can be configured directly in the API request (see pdfDocMDP). Sealing a doc is synchronous, otherwise use SES.
Note(2): Hash signing with SES requires a customer seal for production
Deprecated signature profiles
Starting in 2025, new signing profile identifiers have been introduced to replace the legacy ones.
Please update your integration to use the new profile names as listed in the table below.
| Legacy Signature Profile | New Signature Profile | Purpose |
|---|---|---|
generic | swisssign-qes-zertes | Qualified Electronic Signature |
entrust-seal | swisssign-ses | Simple Electronic Signature |
swisssign-seal | swisssign-ses | Simple Electronic Signature |
scs-qes-zertes | scs-swisssign-qes-zertes | SCS - QES ZertES |
scs-qes-zertes-ppu | scs-swisssign-qes-zertes-ppu | SCS - QES ZertES (Per User) |
qes-zertes-swisssign-ppu | swisssign-qes-zertes-ppu | QES ZertES (Per User) |
swisssign-aes-eidas | swisssign-aes | SwissSign AES eIDAS |
scs-swisssign-aes-eidas | scs-swisssign-aes | SCS - SwissSign AES eIDAS |
swisscom-ades | swisscom-fasttrack | Swisscom Fasttrack |
scs-swisscom-ades | scs-swisscom-fasttrack | SCS - Swisscom Fasttrack |
demo-seal-certification | demo-seal | Demo seal |
scs-demo-seal-with-sms | Note(1) | SCS - Demo Seal with SMS authentication |
scs-ses-swisssign | Note(1) | SCS - Advanced Seal |
entrust-seal-certification | Note(1) | Advanced Seal |
Note(1): Contact our support team to get your identifier
Please contact our support team if one of the profiles listed above is not available for your account.
Deprecation timeline
The removal date has not been finalized yet. Customers still using legacy profiles will be notified in advance before the phase-out.
Other endpoints
| System | Pre-Production |
|---|---|
| Signature Service End-User Webclient | https://sign.sandbox.pre.swisssign.com/console/ |
| Signature Service Administration Webclient | https://sign.sandbox.pre.swisssign.com/rss/admin |
| IdP Login / Account creation | https://login.sandbox.pre.swissid.ch |
| IdP User Self Management (USM) | https://account.sandbox.pre.swissid.ch |
Production
REST API Base URL
https://mtl.swissid.ch/rss/admin
Security
Like our pre-production environment, API in the production environment are secured using the following mechanisms:
- IP address whitelisting
- mTLS client certificate authentication
- Basic Authentication
You must provide your system’s IP address(es) during registration. After your account is set up, we will provide the mTLS client certificate and Basic Authentication credentials.
By default, the mTLS certificate requires renewal every two years.
The production environment is fully decoupled from the pre-production environment. As a result, you will have separate mTLS certificates, credentials, accounts, and organization identifiers for each environment.
Mobile application
Our SwissSign Wallet mobile app is required to use the Qualified Electronic Signature use case. You'll find more information on the following website:
https://www.swisssign.com/en/identities/wallet.html
Signing Service Profiles
| Signature type | Signing Room & Web Client | Hash signing | Document Certification |
|---|---|---|---|
| Qualified Electronic Signature | swisssign-qes-zertes | scs-swisssign-qes-zertes | N/A |
| SwissSign QES ZertES - Per user billing | swisssign-qes-zertes-ppu | scs-swisssign-qes-zertes-ppu | N/A |
| SwissSign QES eIDAS | swisssign-qes-eidas | scs-swisssign-qes-eidas | N/A |
| SwissSign AES | swisssign-aes | scs-swisssign-aes | N/A |
| SwissSign SES | swisssign-ses | N/A | N/A |
| SwissSign SES with SMS auth | swisssign-ses-with-sms | N/A | N/A |
| Swisscom Fasttrack | swisscom-fasttrack | scs-swisscom-fasttrack | N/A |
| Identification LoT1 | identification-lot1 | N/A | N/A |
| Identification LoT2 | identification-lot2 | N/A | N/A |
| Simple Electronic Signature | swisssign-seal | N/A | N/A |
| Advanced Electronic Seal | Note(1) | Note(1) | Note(1) |
Note(1): Contact our support team to get your identifier
Signing Service Profiles General configuration
The workflow configurations are defined under the key lets-sign.workflow.availableWorkflows.
The general structure of a configuration is:
lets-sign.workflow.availableWorkflows:
<name-of-the-workflow>:
workflowId:
serialSignaturesWorkflowId: by default "serialSignatures"
parallelSignaturesWorkflowId: by default "parallelSignatures"
name:
type:
webClientSupported: <boolean>
envelopeSupported: <boolean>
phoneNumberRequired: <boolean>
electronicSeal: <boolean>
requiresAuditTrailReport: <boolean>
identification: <boolean>
signingRoomSupported: <boolean>
apiSupported: <boolean>
swisscomTrustServices:
jurisdiction: <ZERTES, EIDAS>
assuranceLevel: <ADES, QES>
signatoryAttributes:
# list of
key:
displayName:
required: <boolean> by default true
swissid:
required-qor: <QOR1, QOR2>
stepUpRequired: <boolean>
stepUpWebFlow: <boolean>
step-up-purpose: <QOR1, ZERTES, SIGNING>
complies-with: <ZERTES, EIDAS>
allowedOrganizations: # list of strings
signatureLevel: <SES, AES, QES, ADVSEAL, QSEAL>
regulation: <EIDAS, ZERTES>
metaData: # map of data used to configure the service, there isn't a defined set of keys
<key>: <value>
Other endpoints
| System | Production |
|---|---|
| Signature Service End-User Webclient | https://sign.swisssign.com/console/ |
| Signature Service Administration Webclient | https://sign.swisssign.com/rss/admin |
| IdP Login / Account creation | https://login.swissid.ch/ |
| IdP User Self Management (USM) | https://account.swissid.ch |