Sign with Singpass
Singpass Developer DocsAsk a Question
  • START HERE
    • Why use us?
    • How do our Digital Signatures work?
    • Use Cases
    • Frequently Asked Questions
  • FOR USERS
    • How to sign
    • Verifying Sign with Singpass Signatures
      • Loading Singpass Root Signing Certificate
  • FOR DIGITAL SIGNING PARTNERS
    • Guiding Principles
    • Digital Signing Partners
      • Docusign
      • Tungsten Automation
      • OneSpan
      • Tessaract Technologies Pte Ltd
      • Netrust Pte Ltd
      • Modus Consulting
      • Redoc.co by Real Estate Doc Pte Ltd.
      • CrimsonLogic
      • Zoho Sign
      • Securemetric Technology Pte. Ltd.
      • Rently Pte. Ltd.
    • API Documentation
      • Document Signing
        • Document Signing API Specs
      • Transaction Signing
        • Introduction
        • Embedding Singpass JS
        • Init Transaction Signing
        • Exchange Transaction Signature
    • How to Onboard
Powered by GitBook
On this page
  • Secure Electronic Signatures (SES) with Sign with Singpass
  • Sign with Singpass signatures use Public-Key Infrastructure (PKI)

Was this helpful?

  1. START HERE

How do our Digital Signatures work?

PreviousWhy use us?NextUse Cases

Last updated 2 months ago

Was this helpful?

Secure Electronic Signatures (SES) with Sign with Singpass

Sign with Singpass uses signing certificates issued by GovTech. GovTech is a public certification authority under paragraph 3(b)(iii) of the Third Schedule to the Electronic Transactions Act 2010 (ETA).

Signatures created through Sign with Singpass are regarded as Secure Electronic Signatures under the ETA.

Sign with Singpass signatures use Public-Key Infrastructure (PKI)

Public Key Infrastructure (PKI) involves the use of a pair of cryptographic keys: a private key (kept secret by the signer, on the Singpass app) and a public key (embedded in the Singpass signing certificate). The private key is used to create a digital signature, which is a unique encrypted code tied to the document. The public key can be used by anyone to verify the authenticity of the signature. GovTech issues the Singpass signing certificate, which verifies that the identity of the signer is bound to the public key.

This process ensures that only the holder of the private key is able to sign the document, ensuring its authenticity.

Find out more here:

How are digital signatures different from physical signatures?

Digital signatures are resistant to tampering or forgery. While a wet ink signature can be scanned and tampered with or forged, digital signatures cannot be modified or forged once created, as they are cryptographically linked to the signed document through a hash.

Digital signatures are directly embedded into the document's metadata, and provide additional safeguards beyond a visual representation, unlike traditional wet-ink signatures. The authenticity of Sign with Singpass signatures can be verified via standard PDF document readers, which will check that the document has not been modified since it was signed.

Find out more about verifying digital signatures .

Verifying Sign with Singpass Signatures
here