The signer authenticates via national eID before the document is presented for signature. The eID provides identity data (name, NRIC, date of birth) that pre-fills signing fields. The signature itself may be a simpler SES or AES, but the identity proof is government-grade.
National digital identity meets electronic signatures
Across APAC, governments are building national digital identity platforms that verify citizens against government records. These systems — Singpass in Singapore, iAM Smart in Hong Kong, VNeID in Vietnam, My Number in Japan — create a trusted identity layer that commercial e-signature platforms can integrate with. When combined with CA-backed digital signatures, national eID verification produces the strongest evidence chain available.
Major APAC national eID systems for signing
Each national eID system has different API architectures, identity assurance levels, and integration requirements.
| Best for | API available | |
|---|---|---|
| Singpass (Singapore) | QES identity proofing, MyInfo KYC | OAuth2 + MyInfo API |
| iAM Smart (Hong Kong) | Identity proofing for commercial signing | Government API gateway |
| VNeID (Vietnam) | Decree 337 labour contract compliance | VNeID integration via LAPITeCH |
| My Number (Japan) | Qualified signature via JPKI card | Digital Agency API expanding |
| PhilSys (Philippines) | Identity verification expanding | PSA API pilot phase |
| MyIdent (Malaysia) | Future NDI integration | In development |
Three integration patterns
National eID systems can be integrated into signing workflows at different points, depending on the use case.
The national eID verifies identity, then a CA-issued qualified certificate is applied to the document. This produces a QES with the strongest legal presumption. This is the pattern for high-value or regulated transactions.
Some government platforms (e.g. India's Aadhaar eSign) use the eID directly for signing. The signature is created using a certificate linked to the eID. This is efficient but limited to the eID's jurisdiction.
Case study: integrating Singpass for Singapore signing
Singpass is APAC's most mature commercial eID integration. Here is the typical implementation flow.
Register for Singpass API
Apply through GovTech Singapore for Singpass API access. You will need to demonstrate a legitimate business use case and meet security requirements (ISO 27001 or equivalent).
Implement OAuth2 login
Integrate Singpass login using OAuth2. The user authenticates with Singpass (via mobile app or web), and your platform receives a verified token containing their NRIC and verified personal data.
Retrieve MyInfo data (optional)
For KYC-heavy workflows, retrieve MyInfo data (name, address, employment) through the MyInfo API. This pre-fills forms and reduces manual data entry.
Apply CA-qualified signature
After Singpass identity verification, route the document through a Singapore-licensed CA (e.g. Netrust) to apply a qualified electronic signature. The result is a QES with government-verified identity proof.
Store evidence package
The evidence package should include: Singpass verification token, identity data snapshot, CA certificate details, timestamp, and complete audit trail.
Common integration challenges
API access restrictions
Most national eID APIs require government approval before commercial integration. Singpass requires registration with GovTech. iAM Smart requires OGCIO approval. Plan 4-8 weeks for API access provisioning.
Per-country configuration
Each eID system has a unique API architecture, authentication flow, and data schema. A signing platform that supports multiple eID systems needs per-country adapters, not a single universal integration.
Identity data mapping
National eID systems use different identity schemas. Singpass uses NRIC; iAM Smart uses HKID; VNeID uses CCCD. Map eID identity fields to your signing platform's identity model to ensure consistent evidence packages.
Fallback for non-residents
National eID only works for that country's residents. When a signer is not registered (e.g. a foreign employee in Singapore without Singpass), provide an alternative: eKYC document verification or CA-direct identity proofing.
How eSign.AI connects to national eID systems
eSign.AI maintains active integrations with national digital identity systems across APAC.
Connected eID systems
eSign.AI currently integrates with: Singpass (Singapore), iAM Smart (Hong Kong), CCCD/VNeID (Vietnam), MyKad/JPN (Malaysia). Additional integrations are in development: Sistem ID (Indonesia), Taiwan Natural Person Certificate, Korea PASS.
One API, multiple eIDs
The eSign.AI API abstracts the eID layer. Developers send a signing request with the signer country code; the platform handles the eID-specific authentication flow automatically. No need to integrate each eID separately.
Frequently asked questions
Yes. You must register with GovTech Singapore and demonstrate a legitimate business use case. The process typically takes 4-6 weeks. You must also meet security standards (ISO 27001 or equivalent) and comply with Singpass integration guidelines.







