eSign.AIeSign.AI

Solution Guides

Connecting National Digital Identity to eSignature Workflows

Singpass, iAM Smart, VNeID, My Number: how to integrate national eID systems into signing workflows for stronger identity proofing.

eSign.AI Solutions Team7 min read

National digital identity meets electronic signatures

Across APAC, governments are building national digital identity platforms that verify citizens against government records. These systems — Singpass in Singapore, iAM Smart in Hong Kong, VNeID in Vietnam, My Number in Japan — create a trusted identity layer that commercial e-signature platforms can integrate with. When combined with CA-backed digital signatures, national eID verification produces the strongest evidence chain available.

Major APAC national eID systems for signing

Each national eID system has different API architectures, identity assurance levels, and integration requirements.

Best forAPI available
Singpass (Singapore)QES identity proofing, MyInfo KYCOAuth2 + MyInfo API
iAM Smart (Hong Kong)Identity proofing for commercial signingGovernment API gateway
VNeID (Vietnam)Decree 337 labour contract complianceVNeID integration via LAPITeCH
My Number (Japan)Qualified signature via JPKI cardDigital Agency API expanding
PhilSys (Philippines)Identity verification expandingPSA API pilot phase
MyIdent (Malaysia)Future NDI integrationIn development

Three integration patterns

National eID systems can be integrated into signing workflows at different points, depending on the use case.

01

The signer authenticates via national eID before the document is presented for signature. The eID provides identity data (name, NRIC, date of birth) that pre-fills signing fields. The signature itself may be a simpler SES or AES, but the identity proof is government-grade.

02

The national eID verifies identity, then a CA-issued qualified certificate is applied to the document. This produces a QES with the strongest legal presumption. This is the pattern for high-value or regulated transactions.

03

Some government platforms (e.g. India's Aadhaar eSign) use the eID directly for signing. The signature is created using a certificate linked to the eID. This is efficient but limited to the eID's jurisdiction.

Case study: integrating Singpass for Singapore signing

Singpass is APAC's most mature commercial eID integration. Here is the typical implementation flow.

01

Register for Singpass API

Apply through GovTech Singapore for Singpass API access. You will need to demonstrate a legitimate business use case and meet security requirements (ISO 27001 or equivalent).

02

Implement OAuth2 login

Integrate Singpass login using OAuth2. The user authenticates with Singpass (via mobile app or web), and your platform receives a verified token containing their NRIC and verified personal data.

03

Retrieve MyInfo data (optional)

For KYC-heavy workflows, retrieve MyInfo data (name, address, employment) through the MyInfo API. This pre-fills forms and reduces manual data entry.

04

Apply CA-qualified signature

After Singpass identity verification, route the document through a Singapore-licensed CA (e.g. Netrust) to apply a qualified electronic signature. The result is a QES with government-verified identity proof.

05

Store evidence package

The evidence package should include: Singpass verification token, identity data snapshot, CA certificate details, timestamp, and complete audit trail.

Common integration challenges

API access restrictions

Most national eID APIs require government approval before commercial integration. Singpass requires registration with GovTech. iAM Smart requires OGCIO approval. Plan 4-8 weeks for API access provisioning.

Per-country configuration

Each eID system has a unique API architecture, authentication flow, and data schema. A signing platform that supports multiple eID systems needs per-country adapters, not a single universal integration.

Identity data mapping

National eID systems use different identity schemas. Singpass uses NRIC; iAM Smart uses HKID; VNeID uses CCCD. Map eID identity fields to your signing platform's identity model to ensure consistent evidence packages.

Fallback for non-residents

National eID only works for that country's residents. When a signer is not registered (e.g. a foreign employee in Singapore without Singpass), provide an alternative: eKYC document verification or CA-direct identity proofing.

How eSign.AI connects to national eID systems

eSign.AI maintains active integrations with national digital identity systems across APAC.

Connected eID systems

eSign.AI currently integrates with: Singpass (Singapore), iAM Smart (Hong Kong), CCCD/VNeID (Vietnam), MyKad/JPN (Malaysia). Additional integrations are in development: Sistem ID (Indonesia), Taiwan Natural Person Certificate, Korea PASS.

One API, multiple eIDs

The eSign.AI API abstracts the eID layer. Developers send a signing request with the signer country code; the platform handles the eID-specific authentication flow automatically. No need to integrate each eID separately.

Frequently asked questions

Yes. You must register with GovTech Singapore and demonstrate a legitimate business use case. The process typically takes 4-6 weeks. You must also meet security standards (ISO 27001 or equivalent) and comply with Singpass integration guidelines.

Team discussing the right eSignature approach for a business

Explore the right eSignature approach for your business

Talk to our team about eSignature requirements, compliance considerations, and document workflows across your target markets.