LogoSignature Service

Environments

Pre-production

The pre-production environment is available to all customers to facilitate integration, demonstrations, and regression testing.

Accounts and data created in the pre-production environment are persistent, mirroring the behavior of our production environment. However, in rare cases, data may be purged or reverted to a previous state.

While we do not provide a formal SLA for the pre-production environment, our teams strive to ensure its reliability and availability to support your needs.

There are no usage fees for the pre-production environment, as the provided certificates are for testing purposes and cannot be used in production.

REST API Base URL

https://mtl.sandbox.pre.swissid.ch/rss/admin

Security

Like our production environment, API in the pre-production environment are secured using the following mechanisms:

  • IP address whitelisting
  • mTLS client certificate authentication
  • Basic Authentication

You must provide your system’s IP address(es) during registration. After your account is set up, we will provide the mTLS client certificate and Basic Authentication credentials.

By default, the mTLS certificate requires renewal every two years.

Mobile application

A dedicated SwissSign Wallet Preview app is available for testing the Qualified Electronic Signature use case in the pre-production environment.

The end-user will be guided into the installation of the app at signing time.

Signing Service Profiles

Signature typeSigning Room & Web ClientHash signingDocument Certification
Qualified Electronic Signatureswisssign-qes-zertesscs-swisssign-qes-zertesN/A
SwissSign QES ZertES - Per user billingswisssign-qes-zertes-ppuscs-swisssign-qes-zertes-ppuN/A
SwissSign QES eIDASswisssign-qes-eidasscs-swisssign-qes-eidasN/A
SwissSign AESswisssign-aesscs-swisssign-aesN/A
SwissSign SESswisssign-sesN/AN/A
SwissSign SES with SMS authswisssign-ses-with-smsN/AN/A
Swisscom Fasttrackswisscom-fasttrackscs-swisscom-fasttrackN/A
Identification LoT1identification-lot1N/AN/A
Identification LoT2identification-lot2N/AN/A
Simple Electronic Signatureswisssign-sealN/AN/A
SwissSign document sealdemo-sealscs-demo-sealNote(1)
SwissSign document seal (alternate)demo-seal-altscs-demo-seal-altNote(1)
SCS SwissSign SESN/Ascs-demo-sesNote(2)
SCS SwissSign SES with SMSN/Ascs-demo-ses-with-smsNote(2)

Note(1): Document certification can be configured directly in the API request (see pdfDocMDP). Sealing a doc is synchronous, otherwise use SES.
Note(2): Hash signing with SES requires a customer seal for production

Deprecated signature profiles

Starting in 2025, new signing profile identifiers have been introduced to replace the legacy ones.

Please update your integration to use the new profile names as listed in the table below.

Legacy Signature ProfileNew Signature ProfilePurpose
genericswisssign-qes-zertesQualified Electronic Signature
entrust-sealswisssign-sesSimple Electronic Signature
swisssign-sealswisssign-sesSimple Electronic Signature
scs-qes-zertesscs-swisssign-qes-zertesSCS - QES ZertES
scs-qes-zertes-ppuscs-swisssign-qes-zertes-ppuSCS - QES ZertES (Per User)
qes-zertes-swisssign-ppuswisssign-qes-zertes-ppuQES ZertES (Per User)
swisssign-aes-eidasswisssign-aesSwissSign AES eIDAS
scs-swisssign-aes-eidasscs-swisssign-aesSCS - SwissSign AES eIDAS
swisscom-adesswisscom-fasttrackSwisscom Fasttrack
scs-swisscom-adesscs-swisscom-fasttrackSCS - Swisscom Fasttrack
demo-seal-certificationdemo-sealDemo seal
scs-demo-seal-with-smsNote(1)SCS - Demo Seal with SMS authentication
scs-ses-swisssignNote(1)SCS - Advanced Seal
entrust-seal-certificationNote(1)Advanced Seal

Note(1): Contact our support team to get your identifier

Please contact our support team if one of the profiles listed above is not available for your account.

Deprecation timeline

The removal date has not been finalized yet. Customers still using legacy profiles will be notified in advance before the phase-out.

Other endpoints

SystemPre-Production
Signature Service End-User Webclienthttps://sign.sandbox.pre.swisssign.com/console/
Signature Service Administration Webclienthttps://sign.sandbox.pre.swisssign.com/rss/admin
IdP Login / Account creationhttps://login.sandbox.pre.swissid.ch
IdP User Self Management (USM)https://account.sandbox.pre.swissid.ch

Production

REST API Base URL

https://mtl.swissid.ch/rss/admin

Security

Like our pre-production environment, API in the production environment are secured using the following mechanisms:

  • IP address whitelisting
  • mTLS client certificate authentication
  • Basic Authentication

You must provide your system’s IP address(es) during registration. After your account is set up, we will provide the mTLS client certificate and Basic Authentication credentials.

By default, the mTLS certificate requires renewal every two years.

The production environment is fully decoupled from the pre-production environment. As a result, you will have separate mTLS certificates, credentials, accounts, and organization identifiers for each environment.

Mobile application

Our SwissSign Wallet mobile app is required to use the Qualified Electronic Signature use case. You'll find more information on the following website:

https://www.swisssign.com/en/identities/wallet.html

Signing Service Profiles

Signature typeSigning Room & Web ClientHash signingDocument Certification
Qualified Electronic Signatureswisssign-qes-zertesscs-swisssign-qes-zertesN/A
SwissSign QES ZertES - Per user billingswisssign-qes-zertes-ppuscs-swisssign-qes-zertes-ppuN/A
SwissSign QES eIDASswisssign-qes-eidasscs-swisssign-qes-eidasN/A
SwissSign AESswisssign-aesscs-swisssign-aesN/A
SwissSign SESswisssign-sesN/AN/A
SwissSign SES with SMS authswisssign-ses-with-smsN/AN/A
Swisscom Fasttrackswisscom-fasttrackscs-swisscom-fasttrackN/A
Identification LoT1identification-lot1N/AN/A
Identification LoT2identification-lot2N/AN/A
Simple Electronic Signatureswisssign-sealN/AN/A
Advanced Electronic SealNote(1)Note(1)Note(1)

Note(1): Contact our support team to get your identifier

Signing Service Profiles General configuration

The workflow configurations are defined under the key lets-sign.workflow.availableWorkflows.

The general structure of a configuration is:

lets-sign.workflow.availableWorkflows:
  <name-of-the-workflow>:
    workflowId:
    serialSignaturesWorkflowId:  by default "serialSignatures"
    parallelSignaturesWorkflowId: by default "parallelSignatures"
    name:
    type:
    webClientSupported: <boolean>
    envelopeSupported: <boolean>
    phoneNumberRequired: <boolean>
    electronicSeal: <boolean>
    requiresAuditTrailReport: <boolean>
    identification: <boolean>
    signingRoomSupported: <boolean>
    apiSupported: <boolean>

    swisscomTrustServices:
      jurisdiction: <ZERTES, EIDAS>
      assuranceLevel: <ADES, QES>

    signatoryAttributes:
      # list of
      key:
      displayName:
      required: <boolean> by default true

    swissid:
      required-qor: <QOR1, QOR2>
      stepUpRequired: <boolean>
      stepUpWebFlow: <boolean>
      step-up-purpose: <QOR1, ZERTES, SIGNING>
      complies-with: <ZERTES, EIDAS>

    allowedOrganizations: # list of strings

    signatureLevel: <SES, AES, QES, ADVSEAL, QSEAL>
    regulation: <EIDAS, ZERTES>

    metaData: # map of data used to configure the service, there isn't a defined set of keys
      <key>: <value>

Other endpoints

SystemProduction
Signature Service End-User Webclienthttps://sign.swisssign.com/console/
Signature Service Administration Webclienthttps://sign.swisssign.com/rss/admin
IdP Login / Account creationhttps://login.swissid.ch/
IdP User Self Management (USM)https://account.swissid.ch

On this page