Custom Zynyo integration development
Appfront builds custom integrations with Zynyo (formerly ValidSign), the Dutch platform for digital signatures and e-signing. Through the Zynyo REST API and callbacks, you can send contracts and documents for signing automatically, with the correct eIDAS levels, iDIN identification and real-time status fed back into your own systems. You save hours of manual work per file and keep a watertight audit trail.
What is a Zynyo integration?
Zynyo, formerly known as ValidSign, is a Dutch platform for digital signatures and e-signing. Documents are sent through a signing workflow to one or more signatories, who sign with legal validity at the eIDAS level that suits the document: simple (SES), advanced (AES) or qualified (QES). For each signature, the platform records a signing certificate with a timestamp and identity details.
In practice, a custom integration means creating signing flows programmatically based on a template and data from your CRM, HR or property system, adding signatories in the right order, enforcing identification with iDIN or a qualified certificate, and automatically writing the status back to your own file via callbacks. This way the entire signing process runs without manual copying or emailing.
Appfront builds in line with the official Zynyo (ValidSign) developer documentation and the OWASP ASVS security standard. We align templates, signing flows and error handling with your actual processes, so the integration grows with your organisation and remains reliable even at peak volumes.
Legally Binding Signatures
Documents are signed digitally and with legal validity at the eIDAS level that suits the risk: SES, AES or QES. No printing, scanning or wet ink signatures, just a watertight, legally usable signing certificate.
eIDAS-compliant & evidentiary value
Zynyo operates in line with the European eIDAS Regulation and ETSI standards. Every signature receives a timestamp and identity details, recorded in an audit trail that serves as legal evidence in the event of a dispute.
Identification with iDIN
For a higher level of assurance, the signatory identifies themselves through their own bank using iDIN, or with a qualified certificate. This provides verifiable evidence of who signed, in line with AES and QES signatures.
Our development process for Zynyo integrations
We work with a proven methodology that removes uncertainty early and delivers a stable integration. From an initial analysis of your documents, signing flows and source system through to go-live and ongoing management, every step is aimed at an integration your team can understand and trust.
We map out which documents you want to automate, which data from your source system needs to go into the templates, how many signatories are involved and in what order, and which eIDAS level and identification method each document type requires.
We design the integration architecture around the Zynyo REST API, choose the right authentication and callback handling, and define an error-handling strategy.
Implementation with automated tests, structured logging and monitoring. You see working builds along the way.
Controlled go-live with data validation and a safety net, followed by ongoing management and further development.
What a Zynyo integration delivers in practice
Every Zynyo integration is tailored to your documents, signing flows and adjacent systems. Below are the features we most often deliver for organisations that use Zynyo (formerly ValidSign) as part of their signing process.
Zynyo REST API integration
We connect directly to the Zynyo REST API (and the SOAP API where needed) from your CRM, HR or property system. Signing flows are created programmatically, documents uploaded and signatories added, without anyone having to work manually in the Zynyo portal.
Signing flows and sequencing
Multiple signatories in a fixed order or in parallel, with automatic email or SMS reminders when signing is outstanding. For example, a contract that is first approved internally and then sent to the customer, fully automated through the integration.
Templates and pre-filled fields
Document templates with fields that are populated automatically from your system, or that the signatory completes before signing. With Fast Track templates, you send standard documents in a single API call, consistently and without copy-paste errors.
eIDAS levels per document type
For each document type we set the correct eIDAS level: SES for low-risk documents, AES with strong identification for contracts, or QES with a qualified certificate for the highest legal certainty. The integration enforces the right level automatically.
Identification and authentication
The right identification method for each signatory: iDIN through their own bank, SMS verification, or a qualified certificate from a recognised trust service provider. The chosen method is enforced in the flow and recorded in the signing evidence.
Webhooks & status processing
Callbacks from Zynyo report in real time when a document has been opened, signed, declined or expired. We set up a webhook endpoint that validates and processes these events, so the case or deal status in your own system updates automatically, without manual checks.
Typical use cases in practice
A Zynyo integration works differently depending on the sector. We see a number of patterns come up again and again, and for each of them we have a working setup that covers templates, signing flows and the right eIDAS and identification level.
HR and employment contracts
HR teams that have employment agreements, addenda and onboarding documents signed digitally from their HR system. New employees identify themselves with iDIN and sign with legal validity, while the signed version lands automatically in the personnel file. See also our API integrations.
Legal and law firms
Law firms, civil-law notaries and legal departments that need contracts, powers of attorney and settlement agreements signed with legal validity. For documents with a high evidential requirement, the integration enforces AES or QES, with a complete audit trail for every signature.
Financial services & insurance
Banks, insurers, intermediaries and financial advisers who have credit agreements, policies and applications signed digitally. iDIN identification verifies the customer through their own bank, while the signed documents are retained with an audit trail for supervision and compliance.
Real estate & estate agents
Estate agents, landlords and property managers who have purchase and rental agreements, service contracts and valuation reports signed remotely. Multiple parties sign in sequence, and the signed documents flow back into the file.
Technology we use
We build Zynyo integrations using the official Zynyo REST API and callbacks, combined with the backend stack that suits you. The exact choice depends on your source system and the identification levels you need, so that your own team can manage or further develop the integration.
Why choose Appfront for your Zynyo integration?
Appfront has extensive experience building API integrations for a wide range of organisations in the Netherlands. We always start with a thorough analysis of your existing systems and processes. An integration should not only work technically, but also add practical value to the way you work.
For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand and manage it. No black box, just transparent code and clear agreements on monitoring, alerting and maintenance.
You work with a dedicated point of contact who understands both the technical and the functional side. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during development.
Also see our broader services around API integrations, middleware, custom software and web app development. You can find an overview of all integrations on our integrations page.
- Experience with the Zynyo (ValidSign) REST API, transactions and templates
- Familiar with eIDAS levels, iDIN identification and signing flows
- Specialists in integrations with CRM, HR and property management systems
- Secure by default: API key rotation, callback validation, scoped permissions
- Structured error handling and retry mechanisms
- Comprehensive logging and monitoring from day one
- Clear documentation your team can read and manage
- A fixed point of contact, no account managers passed around
- Ongoing maintenance and proactive further development
- A way of working aligned with your existing IT landscape
Security and privacy in Zynyo integrations
Documents that are signed digitally almost always contain personal data or commercially sensitive information. Appfront builds to the OWASP ASVS security standard. This means, among other things: API keys stored in secure vaults, validation of incoming callbacks, scoped permissions per integration, separate test and production environments, and regular audits of the signing flows.
Zynyo is a Dutch platform that operates in line with the European eIDAS Regulation and ETSI standards, and is ISO 27001 certified. For each signature, the platform records a signing certificate with a timestamp and identity details: the audit trail that secures the evidence and serves as legal proof in the event of a dispute. We document the data flows, templates and identification methods so that your record of processing activities is complete and you can demonstrate compliance with the GDPR.
More on our security approach: information security policy and CVD policy.
- GDPR-compliant data processing and data minimisation
- Encryption in transit (TLS 1.2+) and at rest
- Role-based access and least-privilege principles
- Audit logs with traceable data flows
- Automatic retries and dead-letter queues
- Monitoring and alerting for anomalies
- Secrets management in line with best practice
- Documentation for your record of processing activities
Frequently asked questions about Zynyo integrations
Answers to the questions we are asked most often about Zynyo (formerly ValidSign) integrations.
A Zynyo integration is a technical link between Zynyo (formerly ValidSign) and another system, such as your CRM, HR platform, property management software or your own application. Through the Zynyo REST API, signing flows are created programmatically from templates, populated with data from your system and sent to one or more signatories. Callbacks (webhooks) report the status in real time once a document has been signed, declined or expired. An integration can be simple (sending a single contract template) or extensive (multiple signatories in sequence, iDIN identification and archiving with an audit trail).
Zynyo is the current brand name of the Dutch e-signing platform that previously operated as ValidSign. The underlying SigningService, the REST API and the developer documentation are the same technology. If you previously had a ValidSign integration built, you are in effect working with the same platform, now under the name Zynyo. Appfront builds both new Zynyo integrations and integrations that originated under the ValidSign name.
Zynyo supports all three eIDAS levels: the simple electronic signature (SES), the advanced electronic signature (AES) and the qualified electronic signature (QES). Which level is appropriate depends on the legal risk of the document and the evidential requirement you have. In the integration, we define for each document type which level and which identification method, for example iDIN for AES or a qualified certificate for QES, is enforced.
With iDIN, a signatory identifies themselves through their own bank's login, which confirms who they are. In the integration, we configure per signing flow that iDIN identification is required before anyone may sign. Zynyo also supports other identification methods such as SMS verification and qualified certificates. Together with you, we choose the right method per document type, so that identity is demonstrably recorded in the audit trail.
Zynyo sends callbacks (webhooks) as soon as the status of a signing flow changes, for example when a document has been opened, signed, declined or expired. Appfront sets up a webhook endpoint that receives these events, validates them and processes them in your own system. For example, the case status in your CRM or HR system is updated automatically, so nobody has to track the status by hand.
We work with the official Zynyo REST API (and the SOAP API where needed), combined with the backend stack that suits you: Node.js, Python, PHP, .NET, Java, Ruby or Go. For the signing flows we use transactions, packages and templates; for status handling we use the callback mechanisms. Authentication runs via an API key. We handle identification with iDIN or a qualified certificate, depending on the eIDAS level you need.
Costs are determined by the complexity of the signing flows, the number of signatories and their order, the number of systems to integrate, the required identification levels, and the amount of custom business logic. Ongoing management, monitoring and support also play a part. We always provide a clear quote following a no-obligation analysis of your situation.
Yes. Appfront regularly takes over existing Zynyo or ValidSign integrations, even if they were originally set up by another party. We review the API integration, templates, signing flows, callback configuration and error handling, document the current setup and draw up improvement proposals. From that point on, we handle adjustments, extensions and monitoring, including timely API key rotation.
Ready to build your Zynyo integration?
Tell us which documents you want signed and which system Zynyo (formerly ValidSign) needs to connect to. We are happy to think along about signing flows, eIDAS levels, iDIN identification and status handling via callbacks. A no-obligation first conversation will give you a clear picture of the possibilities within half an hour.