Skip to content Glossary
- Certifying authority A certifying authority (CA) is the licensed body that checks a person’s identity and issues their digital signature certificate. Verifiers trust a signature because they trust the authority that vouched for the signer.
- Digital signature A digital signature is a value calculated from a document and a private key. Anyone with the matching public key can check that the document is the one that was signed and has not changed.
- Digital signature certificate A digital signature certificate is a record, issued by a certifying authority, that ties a public key to a named person. It is what lets someone checking a signature know whose signature it is.
- Electronic signature An electronic signature is any electronic mark that shows intent to sign, such as a typed name, a drawn squiggle or a ticked box. It is a broader idea than a digital signature and does not by itself prove who signed or that the file is unchanged.
- Hash A hash is a short fingerprint calculated from a file. The same file always gives the same hash, and changing even one character gives a completely different one.
- Idempotency An operation is idempotent when doing it twice has the same effect as doing it once. An idempotent signing request can be retried after a network failure without creating a second signature.
- KYC · Know your customer KYC is the identity information a bank or other regulated business collects and verifies about a customer. A certificate application can reuse KYC the institution already holds.
- NIN · National Identity Number The NIN is the ten-digit number on a Nepali National ID. A verification service can confirm whether the NIN, name, gender and date of birth someone gave match the National ID system.
- OTP · One-time password An OTP is a short code sent to a phone to confirm that whoever is using a service has that phone. It proves possession of the phone at that moment, not that a person agreed to a particular document.
- PKI · Public key infrastructure PKI is the set of rules, software and authorities that let people trust public keys: certifying authorities issue certificates, and verifiers check them.
- Private key A private key is the secret half of a key pair. It creates your digital signatures and must stay under your control, because anyone who holds it can sign as you.
- Public key A public key is the shareable half of a key pair. It cannot create signatures, but anyone can use it to check a signature made by the matching private key.
- Tamper evident A signed document is tamper evident when any change made after signing is detectable. A digital signature gives this property: alter one byte and verification fails.
- Trusted timestamp A trusted timestamp is a time attached to a signature by an independent time authority. A signature alone proves who signed what, not when.
- Webhook A webhook is a message one system sends to another when something happens, instead of the other system asking repeatedly. In signing, it tells your server that a request has been signed.