Custom Scrive integration development
Appfront builds custom Scrive integrations that embed eIDAS-compliant signing and digital identification into your own applications — from core banking, policy administration, CRM or a custom customer portal. Using the Scrive REST API, Scrive Flow and Scrive eID, we set up document templates, route multi-step signing, connect BankID, MitID or iDIN for KYC, and synchronise every signed status back in real time. The result: legally sound deals in minutes instead of days.
What is a Scrive integration?
Scrive is a Swedish e-signature and eID platform that stands out for its deep integration with BankID (Sweden, Norway), MitID (Denmark), the Finnish Trust Network and iDIN (Netherlands). The platform was designed from the ground up for legal certainty: every signature results in an Evidence Package with a cryptographic seal, an extensive audit trail and evidence that stands up in legal proceedings. Where generic e-signature tools stop at a digital scribble, Scrive also offers high-assurance identification (AES and QES level).
A custom integration means, in practice: generating documents programmatically from a template and data in your CRM, core banking or policy administration system, setting the right eIDAS level per contract type, starting identification flows via Scrive eID for KYC or age verification, orchestrating multi-step signing via Scrive Flow, and using webhooks to feed the signed status and Evidence Package back to your source systems, including automatic archiving and a link to your document management system.
Appfront builds according to the official Scrive API documentation and the OWASP ASVS security standard. We align templates, identification levels and error handling with your actual customer processes, so the integration keeps pace with regulation (GDPR, eIDAS, DORA) and contracts continue to flow through legally correct and reliable, even at peak volumes.
eIDAS-compliant signing
SES, AES or QES, depending on what the use case requires. For internal documents a simple electronic signature is enough; for consumer contracts and policies you need a qualified signature with identification via BankID, MitID or iDIN. Configurable per template.
Evidence Package per document
Every signed document comes with a cryptographically sealed Evidence Package: timestamps, IP addresses, the identification method used, device fingerprints and a complete change history. Legally sound evidence for compliance auditors and courts alike.
Scrive eID for KYC
Identification separate from signing: verify customer identity at onboarding, check age at purchase or verify a counterparty before a transaction. Supports BankID, MitID, FTN, iDIN, Freja eID+ and Smart-ID, ideal for regulated sectors such as banking, insurance and healthcare.
Our development process for Scrive integrations
We work with a proven method that removes uncertainty early and delivers a stable integration. From an initial analysis of your contract and identification processes, eIDAS requirements and integration with core systems through to go-live and ongoing maintenance, every step is aimed at an integration that your team can understand and trust, with compliance documentation for audits.
We map out which document types you want to automate, which eIDAS level each type requires, which identification methods (BankID, MitID, iDIN) are needed and how the Evidence Package fits into your compliance flow.
We design the integration architecture, choose the right authentication and draw up an error-handling strategy.
Implementation with automated tests, structured logging and monitoring. You see working builds along the way.
A controlled go-live with data validation and a safety net, followed by ongoing maintenance and further development.
What a Scrive integration delivers in practice
Every Scrive integration is set up specifically for your document types, compliance requirements and adjacent core systems. Below are the features we deliver most often for organisations that use Scrive as the legal backbone for signing and identification.
Document templates with placeholders
Integration with your CRM, policy administration or customer portal: customer data, policy or loan terms and contract data flow automatically into the right Scrive template. Field placeholders for amounts, terms and attachments are populated programmatically and locked, leaving no room for manual errors.
BankID, MitID & iDIN
Deep integration with the official eID methods of Sweden, Norway, Denmark, Finland and the Netherlands. For each document type you set which level is required: SMS OTP, BankID, MitID or a full QES. Often mandatory for consumer transactions in regulated sectors.
Scrive Flow for multi-step signing
For documents that several parties must sign in a fixed order (customer, intermediary, internal approver, compliance officer), Scrive Flow orchestrates the process automatically. With parallel or sequential signing, reminders and escalation when the turnaround time is exceeded.
KYC flows with Scrive eID
Standalone identification flows for onboarding, age verification or risk checks, even without a contract. The KYC result (name, date of birth, address, ID type) comes back via webhook and links directly to your customer record or application file, ready for UBO or sanctions checks.
Compliance-ready archiving
Every signed document with its Evidence Package is archived automatically in line with your retention obligations (GDPR, DNB, SOx, MiFID II). Integration with M-Files, SharePoint, iManage or your own DMS. Searchable by customer, policy number, document type and date, with a retention policy per type.
Branded signing portals
Customers sign in your own branding (logo, colours, domain) without Scrive being visually prominent. White-labelled signing pages increase trust for regulated products and reduce drop-off during onboarding, which matters for high-stakes financial sign-ups.
Typical use cases in practice
A Scrive integration looks very different from sector to sector. We see a few patterns recur across regulated industries, and for each of them we have a proven setup that covers templates, eIDAS level, integration with core systems and compliance documentation.
Banks & lenders
Digital closing of consumer loans, business credit, mortgages and account openings. Scrive eID verifies the applicant via BankID or iDIN (KYC), the contract is signed with QES and the Evidence Package is automatically linked to the customer file. See also our API integrations.
Insurers & pension funds
Digital conclusion of policies, amendments to existing agreements, claim forms and pension applications. Identification during onboarding via iDIN or BankID, signing of the policy at the appropriate eIDAS level, and integration with policy administration systems such as CCS, AQS or custom solutions.
Healthcare & welfare
Treatment agreements, patient consent, DBC declarations and research participation. Digitally signed with an audit trail for the Wgbo (Dutch Medical Treatment Contracts Act) and GDPR, including integration with EHR systems such as HiX, Epic or Nedap ONS. Evidence and a retention policy of 15–20 years in line with legal requirements.
Real estate, notaries & government
Rental and purchase agreements, estate agent mandates, private deeds, government decisions and permits. Qualified signature via BankID or an appropriate level, with integration to your DMS, CRM or case management system. The Evidence Package replaces old-fashioned paperwork without any legal compromises.
Technology we use
We build Scrive integrations with the official REST API v2 and webhooks, combined with the backend stack that suits you. The exact choice depends on your core systems and the eID methods you want to support, so that your own team can manage or further develop the implementation.
Why choose Appfront for your Scrive integration?
Appfront has extensive experience building API integrations for a wide range of organisations in the Netherlands. We always start with a thorough analysis of your existing systems and processes, because an integration must not only be technically sound but also add practical value to the way you work.
For every integration we write clear documentation and make sure your own team, or a future supplier, can understand and manage the integration. No black box, but transparent code and clear agreements on monitoring, alerting and maintenance.
You work with a dedicated point of contact who understands both the technical and the functional side. That keeps communication lines short, prevents miscommunication and speeds up decisions when choices have to be made during the build.
Also take a look at our broader services around API integrations, middleware, custom software and web app development.
- Experience with the Scrive REST API, Scrive Flow and Scrive eID
- Specialist in eIDAS-compliant signing (SES, AES, QES)
- Familiar with BankID, MitID, FTN, iDIN, Freja eID+ and Smart-ID
- Secure by default — API key rotation, webhook signature validation, scoped permissions
- Structured error handling and retry mechanisms
- Extensive logging and monitoring from day one
- Clear documentation that your team can read and maintain
- A single point of contact, no passing you between account managers
- Ongoing maintenance and proactive further development
- An approach tailored to your existing IT landscape
Security and privacy in Scrive integrations
Regulated signing directly involves personal data, BSN (Dutch citizen service number) or financial transaction data, and therefore falls under GDPR, eIDAS, the Wwft (Dutch Anti-Money Laundering Act), DNB (the Dutch central bank) requirements and, in many cases, DORA. Appfront builds in line with Scrive's security best practices and the OWASP ASVS. Among other things, that means API tokens in secure vaults, HMAC webhook signature validation, scoped permissions and regular audits of document and identification flows.
Scrive itself is ISO 27001 and GDPR compliant, hosts data in EU data centres and, as a Qualified Trust Service Provider (via partners), can deliver QES in accordance with eIDAS. We document the data flows, eID integrations and Evidence Package flows so that your record of processing activities is complete and you can demonstrably comply with the GDPR. The Evidence Package for each document serves as legal proof of every signature.
More about our approach to security: information security policy and CVD policy.
- GDPR-compliant data processing and minimisation
- Encryption in transit (TLS 1.2+) and at rest
- Role-based access and least-privilege principles
- Audit logs with traceable data flows
- Automatic retry and dead-letter queues
- Monitoring and alerting for anomalies
- Secrets management following best practices
- Documentation for your record of processing activities
Frequently asked questions about Scrive integrations
Answers to the questions we get asked most often about Scrive implementations.
A Scrive integration is a technical integration between Scrive and another system, such as your CRM, core banking, policy administration, HR system or in-house application. Via the Scrive REST API and webhooks, documents are prepared programmatically for signing, populated with data from your source systems, signed at the appropriate eIDAS level (SES, AES or QES) and reported back in real time once completed. The Scrive eID module can also facilitate standalone identification flows, without a document having to be attached. An integration ranges from a single document template to a fully automated onboarding process including KYC.
Scrive is a particularly good fit for organisations in regulated sectors: banks, insurers, healthcare providers, pension funds, real estate and government. It originated in Sweden, with strong BankID integration (Swedish BankID, Norwegian BankID, Danish MitID, Finnish FTN) plus AES and QES levels via eIDAS. Besides e-signing, Scrive also offers a dedicated eID product for identification during onboarding and KYC. For pure proposals and CPQ, PandaDoc is a better fit; for CLM we look at Oneflow; for broad global e-signing, DocuSign. We advise on what suits your use case.
A simple integration — sending one document template via the API and a webhook for the signed status — can go live within a few weeks. More complex scenarios take longer: multiple eIDAS levels per document type, combined eSign + eID flows (KYC plus contract), integration with core banking or policy administration, and multiple regions with different BankID schemes. After an intake meeting, we'll give you a realistic estimate.
We work with the official Scrive REST API v2 and webhooks, combined with the backend stack that suits you — Node.js, Python, PHP, .NET, Java, Ruby or Go. Authentication runs via OAuth 1.0a (token-based). For automation we use templates, field placeholders and Scrive Flow for multi-step signing. For identification we integrate Swedish/Norwegian BankID, Danish MitID, Finnish FTN, iDIN (Netherlands), Freja eID+, Smart-ID and SMS OTP — depending on the level of legal certainty required.
The cost is determined by the number of document templates, the eIDAS levels required per flow, the number of eID methods to integrate (BankID, MitID, iDIN etc.), the integrations with core systems (CRM, core banking, policy administration) and the amount of custom business logic. Compliance documentation, monitoring and maintenance also affect the total investment. We always provide a clear quote after a no-obligation analysis of your situation.
Yes — Scrive has always been designed for legally binding signing in regulated sectors. It is ISO 27001 and GDPR compliant, hosted in EU data centres, and provides extensive evidence for every signed document (the Evidence Package), including a cryptographic seal, timestamps, IP addresses and the identification method used. Appfront builds according to OWASP ASVS: API tokens in secure vaults, HMAC webhook signature validation, scoped permissions and strictly separated rights per integration. We document the data flows so your record of processing activities stays complete.
Yes. Appfront regularly takes over the maintenance of existing Scrive integrations, even if they were originally set up by another party. We review the API integrations, templates, eID configuration, webhook flows and error handling, document the current setup and draft improvement proposals. From that point on, we can handle changes, extensions and monitoring — including timely token rotation.
Scrive is a good fit for organisations in regulated sectors where legal certainty and identification are essential: banks and insurers (applications, quotes, policies, loans), healthcare providers (treatment agreements, DBC, research consent), pension funds, real estate and estate agents (rental and purchase agreements), notaries and legal service providers, and government. Typical use cases: digital onboarding of new customers with KYC and contract signing in a single flow, digitally concluding policies and loans with BankID or iDIN, patient consent in healthcare, and employment contracts in the public sector.
Ready to build your Scrive integration?
Tell us which document types you want to automate, which eIDAS levels each flow needs and which core systems Scrive has to integrate with — we're happy to advise on templates, eID methods, Scrive Flow and Evidence Package archiving. A no-obligation first conversation will give you a clear picture of the possibilities within half an hour.