iSigner 1.4.6
dotnet add package iSigner --version 1.4.6
NuGet\Install-Package iSigner -Version 1.4.6
<PackageReference Include="iSigner" Version="1.4.6" />
<PackageVersion Include="iSigner" Version="1.4.6" />
<PackageReference Include="iSigner" />
paket add iSigner --version 1.4.6
#r "nuget: iSigner, 1.4.6"
#:package iSigner@1.4.6
#addin nuget:?package=iSigner&version=1.4.6
#tool nuget:?package=iSigner&version=1.4.6
iSigner — official .NET SDK
Server-side digital signing for iSigner, Nepal's national digital signature platform. Sign PDFs, validate signatures, manage citizen sessions — your app never holds a private key, never wraps PAdES, never talks to OCSP/TSA/HSM.
Targets .NET Framework 4.5+, .NET Standard 2.0, and .NET 8 — one package for every Windows server box a government office, bank or insurer runs, including legacy ASP.NET MVC5 apps such as eBPS.
dotnet add package iSigner
Two ways to connect
// External integrators → the iSigner gateway (per-tenant client HMAC):
var gov = new iSignerClient("https://api.isigner.gov.np", clientId, hmacSecret);
// Internal / on-prem app next to the signing agent (ServiceAuth):
var gov = iSignerClient.ForAgent("http://127.0.0.1:9090", serviceSecret);
Sign
// One PDF, citizen confirms on their phone:
byte[] signed = await gov.Signatures.SignPdfAsync(pdf, citizenId: "12-34-56-7890",
title: "Account Opening — KYC", relyingParty: "NIBL Bank", level: "LT");
// Bulk, server-side, with a department certificate (no citizen):
List<byte[]> sealed = await gov.Signatures.SignPdfInstitutionalAsync(
pdfs, certReference: "ird-bulk-stamp-2026", level: "LT");
// Validate:
var report = await gov.Validations.ValidateAsync(signed, "doc.pdf");
Synchronous wrappers (SignPdf, SignPdfInstitutional, …) are provided for
classic ASP.NET MVC5 / .NET Framework callers — they're deadlock-safe because the
SDK uses ConfigureAwait(false) throughout.
ASP.NET Core DI (netstandard2.0+/net8)
builder.Services.AddiSigner(o => {
o.BaseUrl = "https://api.isigner.gov.np";
o.ClientId = config["iSigner:ClientId"];
o.HmacSecret = config["iSigner:Secret"];
});
Webhooks
gov.Webhooks.Verify(rawBody, Request.Headers["X-iSigner-Signature"], webhookSecret);
License: Apache-2.0 · https://isigner.gov.np/sdk
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net5.0 was computed. net5.0-windows was computed. net6.0 was computed. net6.0-android was computed. net6.0-ios was computed. net6.0-maccatalyst was computed. net6.0-macos was computed. net6.0-tvos was computed. net6.0-windows was computed. net7.0 was computed. net7.0-android was computed. net7.0-ios was computed. net7.0-maccatalyst was computed. net7.0-macos was computed. net7.0-tvos was computed. net7.0-windows was computed. net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
| .NET Core | netcoreapp2.0 was computed. netcoreapp2.1 was computed. netcoreapp2.2 was computed. netcoreapp3.0 was computed. netcoreapp3.1 was computed. |
| .NET Standard | netstandard2.0 is compatible. netstandard2.1 was computed. |
| .NET Framework | net45 is compatible. net451 was computed. net452 was computed. net46 was computed. net461 was computed. net462 is compatible. net463 was computed. net47 was computed. net471 was computed. net472 was computed. net48 was computed. net481 was computed. |
| MonoAndroid | monoandroid was computed. |
| MonoMac | monomac was computed. |
| MonoTouch | monotouch was computed. |
| Tizen | tizen40 was computed. tizen60 was computed. |
| Xamarin.iOS | xamarinios was computed. |
| Xamarin.Mac | xamarinmac was computed. |
| Xamarin.TVOS | xamarintvos was computed. |
| Xamarin.WatchOS | xamarinwatchos was computed. |
-
.NETFramework 4.5
- Newtonsoft.Json (>= 13.0.3)
-
.NETFramework 4.6.2
- Microsoft.Extensions.DependencyInjection.Abstractions (>= 6.0.0)
- Newtonsoft.Json (>= 13.0.3)
-
.NETStandard 2.0
- Microsoft.Extensions.DependencyInjection.Abstractions (>= 6.0.0)
- Newtonsoft.Json (>= 13.0.3)
-
net8.0
- Microsoft.Extensions.DependencyInjection.Abstractions (>= 6.0.0)
- Newtonsoft.Json (>= 13.0.3)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
1.4.6 — Unverified-document watermark:
* StampTemplate gains UnverifiedImageB64 — an office "not digitally verified" watermark
(e.g. a red cross) the eBPS host stamps onto UNSIGNED document copies at download/print.
Host-only: deliberately NOT sent to the signing agent (excluded from the agent payload),
just persisted in the saved template. No agent version requirement.
No breaking changes: fully backward compatible with 1.4.5 call sites.
1.4.5 — Stamp image opacity + robustness:
* StampTemplate gains ImageOpacity (0.05–1.0 fraction or 5–100 percent; null = layout
default — watermark ~14%, seal fully opaque). Requires signing-agent >= 1.4.30.
* StampTemplate.UserSignatureMode is now serialized to the agent's stored template
(it previously lived only in the eBPS DB copy).
* Agent 1.4.30 also fixes HTTP 400 on the four image stamp layouts when the uploaded
logo isn't a PNG/JPEG the renderer can embed (WebP/SVG/BMP…): images are now sniffed
and re-encoded, or dropped gracefully to the text fallback.
No breaking changes: fully backward compatible with 1.4.4 call sites.
1.4.4 — Per-officer signature image:
* PreparePdf/PreparePdfAsync: new optional userSignatureB64 (base64 PNG) + userSignatureMode
("watermark" default, or "visible"). Each officer's own uploaded signature is applied to
their stamps — faint behind the text (watermark) or as a seal beside it (visible). It takes
precedence over the office logo/seal. Requires signing-agent >= 1.4.29 to render.
* StampTemplate gains UserSignatureMode (office-wide policy for the above).
No breaking changes: fully backward compatible with 1.4.3 call sites.
1.4.3 — Stamp-template colours:
* StampTemplate gains BackgroundColor ("#RRGGBB" fill, "transparent" for none, or null =
the layout's default tint), BorderColor ("#RRGGBB"), and BorderWidth (outline thickness
in points). Additive + nullable — omitting them keeps the prior look. Requires
signing-agent >= 1.4.28 to render (older agents ignore the fields).
No breaking changes: fully backward compatible with 1.4.2 call sites.
1.4.2 — Stamp-template variables:
* PreparePdf/PreparePdfAsync: new optional stampVars dictionary. Each {key} in the office
stamp template's custom text is replaced with its value at signing — pass per-officer DB
values the agent can't resolve itself ({nameNepali}, {nameEnglish}, {designation}, ...).
Same contract as the existing desk parameter. Requires signing-agent >= 1.4.11 to take
effect (older agents ignore the field; the {key} tokens then print literally).
* The agent (1.4.11) also renders inline **bold** spans in template custom text.
No breaking changes: fully backward compatible with 1.4.1 call sites.
1.4.1 — Security/hardening (patch, but note the transport change below):
* ForAgent(url, secret) now REFUSES a plain-http URL to a non-loopback host and throws
ArgumentException. Point iSigner.AgentUrl at http://127.0.0.1:9090/ (co-located agent) or use
https:// for a remote agent. A LAN http URL (e.g. http://192.168.x.x:9090/) will now throw —
this is intentional (the ServiceAuth HMAC does not protect the document in transit over
cleartext). Loopback http is still allowed.
* Requires Newtonsoft.Json >= 13.0.3 (add a binding redirect on .NET Framework if an older
Newtonsoft is already present).
No wire-contract changes: works with signing-agent 1.4.x (incl. the 1.4.7 one-shot
prepare-session behaviour — CompletePdf sends Idempotency-Key=sessionId, so retries are safe).