Developers

Service endpoints and certificates to integrate Sigalion timestamping into your software, scripts and signing tools.

Timestamping API

Timestamping API

Integrate timestamping into your applications: RFC 3161 standard, Sigalion level or qualified eIDAS.

Qualified (eIDAS) access uses an API key generated from your Client Area.

Heavy usage, a custom integration, a specific project? Write to us at contact@sigalion.fr.

Service endpoints

Both endpoints follow the RFC 3161 protocol and can be used as they are in Acrobat, OpenSSL or any signing tool.

Sigalion timestamping

Free, no account. Up to ten tokens in a row, then one per minute.

  • https://api.sigalion.fr/tsa

eIDAS qualified timestamping

API key, one credit per token.

  • https://api.sigalion.fr/tsa/qualified/auto (the first available provider)
  • https://api.sigalion.fr/tsa/qualified/certigna (Certigna)

Sigalion root certificate

Tokens from the free service are signed under our own certification authority. The Sigalion applications and the Verify page already embed this root, so they need no installation. Any other tool, OpenSSL, a PDF reader or a system certificate store, does need it: the token already carries the signer's certificate and the intermediate authority.

Root in PEM format (OpenSSL, curl, libraries, the Linux certificate store) or DER (the Windows certificate store). Both files contain the same certificate, and macOS accepts either one.

SHA-256 fingerprint: A0:DF:11:28:7F:DD:6A:C8:6D:D6:E2:8F:29:28:03:7D:B8:5B:8A:E4:9E:73:9C:AF:F0:93:BE:5C:D1:1B:1F:93

This authority is not eIDAS qualified. Qualified timestamping is issued by qualified trust service providers, which are recognised in the trusted lists of the Member States, and Sigalion verifies it without requiring any installation.