E-signature iDIN & eHerkenning Signhost API

Custom Evidos integration development

Appfront builds custom Evidos integrations that make documents legally binding to sign, from your CRM, HR system, contract management or own application. Via the Signhost REST API and webhooks we send documents for signature, choose the right verification level per signatory (iDIN, eHerkenning, iDEAL verification, SMS or ID scan) and feed the signing status back in real time. Including eIDAS-compliant signatures and a complete evidence file for your archive.

What is an Evidos integration?

Evidos is a Dutch platform for e-signature and identity verification, part of Entrust since 2021. Its signing product is called Signhost. Where an ordinary PDF signature is little more than an image, Signhost adds legal certainty: you choose a verification method for each signer, and the platform records every step in an evidence file. A document is therefore not only signed, but afterwards it can also be demonstrated who signed it, when, and how.

In practice, a custom integration means: creating a signing transaction from your own software via the Signhost API, passing on the document to be signed and the signatories, setting the verification level per signatory (iDIN, eHerkenning, iDEAL verification, SMS or ID scan), defining the signing order when multiple parties are involved, and sending the status back to your CRM or application via webhooks. Once complete, you archive the signed document together with the evidence file.

Appfront builds according to the official Signhost developer documentation and the OWASP ASVS security standard. We align signing flows, verification levels and error handling with your actual processes, so the integration grows with your organisation and signing remains reliable and legally binding even at peak volumes.

Legally Binding Signatures

eIDAS-compliant signatures, whether simple, advanced (AdES) or qualified (QES), matched to the risk of the document. Each signature receives the level that fits legally and practically.

Strong identity verification

The right method for each signer: iDIN via your bank, eHerkenning for business, iDEAL verification, SMS code or ID scan. This way you are certain who has signed, not just that something was signed.

Evidence file and audit trail

For every transaction, Signhost records each step (verification method, timestamps and the signing process) in an evidence file that serves as legal proof. You archive the document and file together in your own system.

Our development process for Evidos integrations

We work to a proven methodology that removes uncertainty early and delivers a stable, legally binding integration. From an initial analysis of your signing flows, required verification levels and the systems Signhost must connect to, through to go-live and ongoing management, every step is aimed at an integration your team can understand and trust.

1
Analysis & scope

We map out which documents you need signed, which signatories are involved and in what order, which signature level and verification method each document requires, and where the evidence file should be archived.

2
Architecture

We design the integration architecture, choose the right authentication and draw up an error-handling strategy.

3
Development

Implementation with automated tests, structured logging and monitoring. You see working builds along the way.

4
Go-live & management

Controlled go-live with data validation and a safety net, followed by ongoing management and further development.

What an Evidos integration concretely delivers

Every Evidos integration is tailored to your document types, signing flows and connected systems. Below are the capabilities we most often deliver for organisations using Signhost as part of their signing process.

Documents for signature via API

Create a signing transaction from your own software via the Signhost API: pass the document and signatories, generate the signing link and send the invitation. No more manual uploads; signing starts directly from the process where the document is created.

Identity verification per signatory

For each signatory, the verification level that suits the document: iDIN, eHerkenning, iDEAL verification, an SMS code or an ID scan. The integration automatically selects the right method based on your rules, so more sensitive documents receive stronger verification.

Signing order and multiple signatories

Documents with multiple parties: set a fixed order or allow parallel signing. The integration tracks whose turn it is, sends reminders at the right moment and only closes the transaction once all signatories have signed.

Webhook status updates to your CRM

Signhost postbacks feed the status back in real time: invited, opened, signed or declined. No polling, but direct updates in your CRM or application, so files and pipelines are always accurate and follow-up actions are triggered automatically.

Evidence file and archiving

Once completed, we retrieve the signed document and the full evidence file via the API and store them in a structured way in your DMS, contract management system or archive. Everything in one easily searchable place, ready for audits and legal evidence.

Choosing eIDAS levels

Logic that determines the correct eIDAS level per document type: simple, advanced (AdES) or qualified (QES). Your rules are defined once and then applied consistently, so every document is signed with legal validity without a manual choice.

Typical use cases in practice

An Evidos integration plays out very differently from one organisation to the next. We see a number of recurring patterns, and for each of them we have a proven setup that gets the verification levels, signing order and archiving of the evidence file right.

HR onboarding and contracts

Employment contracts, amendments and onboarding documents that new employees sign legally with strong verification via iDIN. The status flows automatically back to your HR system, so files are complete from day one. See also our API integrations.

Sales agreements

Quotes, mandates and agreements that customers sign directly from your CRM. Appropriate verification per deal, a clean signing order for multiple parties, and a webhook that updates the deal status as soon as it is signed, including the evidence file attached to the record.

Legal and contract management

Legal teams that manage contracts, NDAs and processing agreements centrally. Per document type the correct eIDAS level, a fixed signing order for internal and external parties, and automatic archiving of the signed document and evidence file in your contract management system. We also build comparable signing integrations with ValidSign and DocuSign.

Government and healthcare with strong verification

Organisations in government, healthcare and real estate where the identity of the signatory must be demonstrably verified. eHerkenning for business signatories, iDIN for citizens, qualified electronic signatures where required, and an evidence file that stands up to audits and disputes.

Technology we use

We build Evidos integrations using the official Signhost REST API and postbacks (webhooks), combined with the backend stack that suits you. The exact choice depends on your systems and the verification methods you need, so your own team can manage or further develop the implementation.

Signhost REST API Signhost postbacks (webhooks) API key authentication iDIN verification eHerkenning iDEAL verification SMS verification & ID scan eIDAS / AdES / QES Node.js / Python / PHP / .NET CRM & HR system integrations Contract management & DMS archiving Signing order & multiple signatories Evidence file & audit trail Webhook validation Retry & dead-letter queues GitHub Actions

Why choose Appfront for your Evidos integration?

Appfront has extensive experience building API integrations for a wide range of organisations in the Netherlands. We always start with a thorough analysis of your existing systems and processes. An integration should not only work technically, but also add practical value to the way you work.

For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand and manage it. No black box, just transparent code and clear agreements on monitoring, alerting and maintenance.

You work with a dedicated point of contact who understands both the technical and the functional side. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during development.

See also our wider services around API integrations, middleware, custom software development and web app development.

  • Experience with the Signhost REST API, verification levels and postbacks
  • Familiar with iDIN, eHerkenning, iDEAL verification, SMS and ID scan
  • Knowledge of eIDAS levels: simple, advanced (AdES) and qualified (QES)
  • Specialists in integrations with CRM, HR and contract management systems
  • Secure by default: API key rotation, webhook validation, scoped permissions
  • Structured error handling and retry mechanisms
  • Comprehensive logging and monitoring from day one
  • Clear documentation your team can read and manage
  • A fixed point of contact, no account managers passed around
  • Ongoing maintenance and proactive further development

Undecided between signing platforms? We also build integrations with SignRequest and Scrive, and we are happy to advise you on the best choice. Feel free to get in touch.

Security and privacy in Evidos integrations

Documents signed digitally almost always contain personal data or commercially sensitive information, and identity verification adds sensitive data such as BSN-derived or bank identity details. Appfront builds in line with the Signhost security best practices and the OWASP ASVS. This means, among other things: the API key kept in a secure vault, validation of webhook postbacks, encryption in transit and at rest, and regular audits of the signing flows.

Signhost records an extensive evidence file for each transaction, including the verification method used, timestamps and the steps in the signing process, which serves as legal proof. We document the data flows and personal data processed so that your record of processing activities is complete and you can demonstrably comply with the GDPR. By setting up verification and archiving properly, you collect no more data than necessary.

More on our security approach: information security policy and CVD policy.

  • GDPR-compliant data processing and data minimisation
  • Encryption in transit (TLS 1.2+) and at rest
  • Strong identity verification for each signatory
  • Evidence file and audit trail as legal proof
  • Role-based access and least-privilege principles
  • Automatic retries and dead-letter queues
  • Monitoring and alerting for anomalies
  • Documentation for your record of processing activities

Frequently asked questions about Evidos integrations

Answers to the questions we are asked most often about Evidos and Signhost implementations.

An Evidos integration is a technical link between Evidos's signing platform, which is called Signhost, and another system, such as your CRM, HR application, contract management software or in-house software. Through the Signhost REST API, signing transactions are created programmatically: you send a document for signature, add signatories, choose the verification level for each signatory and receive real-time status updates via webhooks. Once signing is complete, the signed document and the evidence file are passed back to your system for archiving.

Evidos/Signhost suits organisations that want documents legally signed under eIDAS, with strong identity verification using Dutch and European methods such as iDIN, eHerkenning, iDEAL verification, SMS or an ID scan. It is a strong fit for HR, legal, finance, government and healthcare, where the signatory's identity must be demonstrably verified. For very simple signing without heavy verification, a lighter platform may suffice; in an intake conversation we can work out together which approach fits best.

Evidos/Signhost is eIDAS-compliant and supports the simple electronic signature, the advanced electronic signature (AdES) and the qualified electronic signature (QES). The right level depends on the risk and the legal requirements of the document. For each signatory you choose a verification method, for example iDIN, eHerkenning, iDEAL verification, SMS or an ID scan, that suits the desired signature level. In the integration we set this up so that the document automatically receives the correct level.

We work with the official Signhost REST API and postbacks (webhooks), combined with the backend stack that suits you: Node.js, Python, PHP or .NET. Authentication runs through an API key. For identity verification, we link the methods you need, such as iDIN, eHerkenning and iDEAL verification, to the right signatories, and we process the signed documents and evidence file into your archive. Status updates arrive in real time via webhooks in your CRM or application.

Costs are driven by the complexity of the signing flows, the number of systems to integrate, the verification methods and signature levels you need, and the amount of custom business logic around signing order and archiving. Ongoing management, monitoring and support also affect the total investment. We always provide a clear quote following a no-obligation analysis of your situation.

Yes. Evidos/Signhost records a comprehensive audit trail for each transaction, including timestamps, the verification method used and the steps in the signing process, which serves as legal evidence. Appfront builds to OWASP ASVS: the API key is held in a secure vault, webhook postbacks are validated, data is encrypted in transit and at rest, and access follows least-privilege rights per integration. We document the data flows and the personal data processed so that your record of processing activities remains complete and you can demonstrate GDPR compliance.

Yes. Appfront regularly takes over existing Evidos or Signhost integrations, even when they were originally set up by another party. We review the API integration, verification levels, webhook configuration and error handling, document the current setup and propose improvements. From that point on we handle adjustments, extensions and monitoring, including timely rotation of the API key.

Evidos/Signhost suits organisations that need documents signed with legal validity and strong identity verification. Think of HR teams (employment contracts and onboarding), sales (agreements and mandates), legal and contract management, finance, and sectors such as government, healthcare and real estate where the signatory's identity must be demonstrably verified. For very simple signing without heavy verification, a lighter platform may be more suitable, and we will look with you at whether another platform would fit better.

Ready to build your Evidos integration?

Tell us which documents you want to have legally signed and which CRM, HR system or contract management software Signhost needs to connect to. We're happy to help you think through verification levels, signing order, webhooks and archiving of the evidence file. A no-obligation first conversation will give you a clear picture of the possibilities within half an hour.

Edit content