iSigner 1.4.6

dotnet add package iSigner --version 1.4.6
                    
NuGet\Install-Package iSigner -Version 1.4.6
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="iSigner" Version="1.4.6" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="iSigner" Version="1.4.6" />
                    
Directory.Packages.props
<PackageReference Include="iSigner" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add iSigner --version 1.4.6
                    
#r "nuget: iSigner, 1.4.6"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package iSigner@1.4.6
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=iSigner&version=1.4.6
                    
Install as a Cake Addin
#tool nuget:?package=iSigner&version=1.4.6
                    
Install as a Cake Tool

iSigner — official .NET SDK

Server-side digital signing for iSigner, Nepal's national digital signature platform. Sign PDFs, validate signatures, manage citizen sessions — your app never holds a private key, never wraps PAdES, never talks to OCSP/TSA/HSM.

Targets .NET Framework 4.5+, .NET Standard 2.0, and .NET 8 — one package for every Windows server box a government office, bank or insurer runs, including legacy ASP.NET MVC5 apps such as eBPS.

dotnet add package iSigner

Two ways to connect

// External integrators → the iSigner gateway (per-tenant client HMAC):
var gov = new iSignerClient("https://api.isigner.gov.np", clientId, hmacSecret);

// Internal / on-prem app next to the signing agent (ServiceAuth):
var gov = iSignerClient.ForAgent("http://127.0.0.1:9090", serviceSecret);

Sign

// One PDF, citizen confirms on their phone:
byte[] signed = await gov.Signatures.SignPdfAsync(pdf, citizenId: "12-34-56-7890",
    title: "Account Opening — KYC", relyingParty: "NIBL Bank", level: "LT");

// Bulk, server-side, with a department certificate (no citizen):
List<byte[]> sealed = await gov.Signatures.SignPdfInstitutionalAsync(
    pdfs, certReference: "ird-bulk-stamp-2026", level: "LT");

// Validate:
var report = await gov.Validations.ValidateAsync(signed, "doc.pdf");

Synchronous wrappers (SignPdf, SignPdfInstitutional, …) are provided for classic ASP.NET MVC5 / .NET Framework callers — they're deadlock-safe because the SDK uses ConfigureAwait(false) throughout.

ASP.NET Core DI (netstandard2.0+/net8)

builder.Services.AddiSigner(o => {
    o.BaseUrl    = "https://api.isigner.gov.np";
    o.ClientId   = config["iSigner:ClientId"];
    o.HmacSecret = config["iSigner:Secret"];
});

Webhooks

gov.Webhooks.Verify(rawBody, Request.Headers["X-iSigner-Signature"], webhookSecret);

License: Apache-2.0 · https://isigner.gov.np/sdk

Product Compatible and additional computed target framework versions.
.NET net5.0 was computed.  net5.0-windows was computed.  net6.0 was computed.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
.NET Core netcoreapp2.0 was computed.  netcoreapp2.1 was computed.  netcoreapp2.2 was computed.  netcoreapp3.0 was computed.  netcoreapp3.1 was computed. 
.NET Standard netstandard2.0 is compatible.  netstandard2.1 was computed. 
.NET Framework net45 is compatible.  net451 was computed.  net452 was computed.  net46 was computed.  net461 was computed.  net462 is compatible.  net463 was computed.  net47 was computed.  net471 was computed.  net472 was computed.  net48 was computed.  net481 was computed. 
MonoAndroid monoandroid was computed. 
MonoMac monomac was computed. 
MonoTouch monotouch was computed. 
Tizen tizen40 was computed.  tizen60 was computed. 
Xamarin.iOS xamarinios was computed. 
Xamarin.Mac xamarinmac was computed. 
Xamarin.TVOS xamarintvos was computed. 
Xamarin.WatchOS xamarinwatchos was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.4.6 106 7/6/2026
1.4.5 107 7/6/2026
1.4.4 102 7/3/2026
1.4.3 106 7/3/2026
1.4.2 97 7/2/2026
1.4.1 101 7/2/2026
1.4.0 99 7/1/2026

1.4.6 — Unverified-document watermark:
     * StampTemplate gains UnverifiedImageB64 — an office "not digitally verified" watermark
       (e.g. a red cross) the eBPS host stamps onto UNSIGNED document copies at download/print.
       Host-only: deliberately NOT sent to the signing agent (excluded from the agent payload),
       just persisted in the saved template. No agent version requirement.
     No breaking changes: fully backward compatible with 1.4.5 call sites.

     1.4.5 — Stamp image opacity + robustness:
     * StampTemplate gains ImageOpacity (0.05–1.0 fraction or 5–100 percent; null = layout
       default — watermark ~14%, seal fully opaque). Requires signing-agent >= 1.4.30.
     * StampTemplate.UserSignatureMode is now serialized to the agent's stored template
       (it previously lived only in the eBPS DB copy).
     * Agent 1.4.30 also fixes HTTP 400 on the four image stamp layouts when the uploaded
       logo isn't a PNG/JPEG the renderer can embed (WebP/SVG/BMP…): images are now sniffed
       and re-encoded, or dropped gracefully to the text fallback.
     No breaking changes: fully backward compatible with 1.4.4 call sites.

     1.4.4 — Per-officer signature image:
     * PreparePdf/PreparePdfAsync: new optional userSignatureB64 (base64 PNG) + userSignatureMode
       ("watermark" default, or "visible"). Each officer's own uploaded signature is applied to
       their stamps — faint behind the text (watermark) or as a seal beside it (visible). It takes
       precedence over the office logo/seal. Requires signing-agent >= 1.4.29 to render.
     * StampTemplate gains UserSignatureMode (office-wide policy for the above).
     No breaking changes: fully backward compatible with 1.4.3 call sites.

     1.4.3 — Stamp-template colours:
     * StampTemplate gains BackgroundColor ("#RRGGBB" fill, "transparent" for none, or null =
       the layout's default tint), BorderColor ("#RRGGBB"), and BorderWidth (outline thickness
       in points). Additive + nullable — omitting them keeps the prior look. Requires
       signing-agent >= 1.4.28 to render (older agents ignore the fields).
     No breaking changes: fully backward compatible with 1.4.2 call sites.

     1.4.2 — Stamp-template variables:
     * PreparePdf/PreparePdfAsync: new optional stampVars dictionary. Each {key} in the office
       stamp template's custom text is replaced with its value at signing — pass per-officer DB
       values the agent can't resolve itself ({nameNepali}, {nameEnglish}, {designation}, ...).
       Same contract as the existing desk parameter. Requires signing-agent >= 1.4.11 to take
       effect (older agents ignore the field; the {key} tokens then print literally).
     * The agent (1.4.11) also renders inline **bold** spans in template custom text.
     No breaking changes: fully backward compatible with 1.4.1 call sites.

     1.4.1 — Security/hardening (patch, but note the transport change below):
     * ForAgent(url, secret) now REFUSES a plain-http URL to a non-loopback host and throws
       ArgumentException. Point iSigner.AgentUrl at http://127.0.0.1:9090/ (co-located agent) or use
       https:// for a remote agent. A LAN http URL (e.g. http://192.168.x.x:9090/) will now throw —
       this is intentional (the ServiceAuth HMAC does not protect the document in transit over
       cleartext). Loopback http is still allowed.
     * Requires Newtonsoft.Json >= 13.0.3 (add a binding redirect on .NET Framework if an older
       Newtonsoft is already present).
     No wire-contract changes: works with signing-agent 1.4.x (incl. the 1.4.7 one-shot
     prepare-session behaviour — CompletePdf sends Idempotency-Key=sessionId, so retries are safe).