Broken digital journeys
Manual signing breaks digital onboarding journeys and adds days to time-to-close.
Aadhaar eSign API
Let your users sign contracts, loan agreements, and KYC forms with nothing but their Aadhaar number and an OTP. Full legal standing under the IT Act, 2000, delivered through a single API into your existing onboarding flow.
Trusted by
Verifications processed
Transactions per year
Clients served
Platform uptime
What is the Aadhaar eSign API
The Aadhaar eSign API is a government-enabled electronic signature service, built on India's Aadhaar identity infrastructure, that you integrate directly into your own product.
Instead of a printed page or a USB-based Digital Signature Certificate (DSC) token, the signer authenticates with their Aadhaar number and a one-time password, or biometrics. Once UIDAI confirms their identity, a licensed Certifying Authority issues a one-time Electronic Signature Certificate, uses it to cryptographically sign the document, and destroys it.
| Aadhaar eSign | DSC (USB token) | Simple e-signature | |
|---|---|---|---|
| Legal standing | Second Schedule, IT Act — equal to a handwritten signature | Section 3, IT Act — equal to a handwritten signature | Not in the Second Schedule; evidence of agreement, without the IT Act presumption |
| Hardware | None | USB cryptographic token | None |
| Signer setup | None — Aadhaar number + OTP | Days: KYC, issuance, shipping | None |
| Certificate | One-time, issued at signing | Valid 1–3 years | N/A |
| Cost model | Per signature | Per token, per year | Usually bundled |
| Best fit | High-volume customer signing | Directors, statutory filings | Low-risk internal approvals |
The problem
Printing, courier, notarisation, and the days it takes to execute one agreement.
Manual signing breaks digital onboarding journeys and adds days to time-to-close.
Paper trails make compliance audits and dispute resolution slow and expensive.
Self-attested identity checks are easy to spoof, increasing fraud exposure.
Physical processes don't scale as loan books, policy volumes, or hiring pipelines grow.
Why regulated lenders can't defer this
The RBI (Digital Lending) Directions, 2025, effective 8 May 2025, consolidated India's digital lending rules and extended them to All-India Financial Institutions alongside banks, co-operative banks, and NBFCs. Regulated entities must issue a Key Fact Statement (KFS) — per RBI's circular of 15 April 2024 — before the loan contract is executed, and furnish digitally signed documents to the borrower on execution.
Every digitally originated loan now generates several documents that must be delivered, acknowledged, and executed inside a compressed window, with a demonstrable record of each step. Aadhaar eSign is how most lenders close that loop without breaking the digital journey.
The solution
Gridlines' Aadhaar eSign API embeds compliant, government-backed signing directly into your onboarding, lending, or HR workflow. Signing runs through an authorised, CCA-licensed eSign Service Provider, so every signature is compliant by default — while you keep a single integration, a single dashboard, and your own brand in front of the customer.
Anyone with an Aadhaar number can sign in under a minute using an OTP sent to their registered mobile, and the signature carries full legal weight in an Indian court.
Features & benefits
Agreements that took days to circulate, print, sign, and return complete in minutes — decisive wherever deal velocity affects revenue.
No printing, courier, physical storage, or manual verification. Per-document execution cost drops sharply at scale.
Every signature carries a verifiable audit trail — signer identity, timestamp, IP address, device fingerprint — captured at the moment of consent rather than reconstructed later.
Customers complete onboarding, loan applications, or policy purchases entirely on their phone. No branch visit, no printing.
Identity is verified against UIDAI's infrastructure directly, not a document upload or self-attestation.
The signing private key is generated inside a Hardware Security Module and destroyed immediately after use, leaving no reusable credential to steal.
Industries
Loan agreements, sanction letters, KFS execution.
Policy issuance, proposal forms, claim consent.
Account opening, KYC, mandate forms.
Offer letters, employment contracts, policy acknowledgments.
Partner agreements and onboarding contracts.
Seller and merchant agreements.
Use cases
Banking & NBFC
Borrower eSigns the sanction letter and KFS the moment the loan is approved, keeping the digital journey unbroken.
Insurance
Policyholder eSigns proposal and consent forms without a branch visit.
Fintech
Account opening and mandate forms signed and stored with a compliant audit trail.
HRTech
Offer letters and policy acknowledgments signed remotely at scale.
Marketplaces
MSAs and NDAs executed without printing, courier, or a meeting.
How it works
01
Your application calls the Aadhaar eSign API to upload the document and start a signing request. The Application Service Provider computes the document hash that will be signed.
02
The signer enters their Aadhaar number and verifies via OTP or biometric. Authentication is performed by UIDAI — credentials are encrypted at the point of capture, and neither Gridlines nor your platform stores biometric data.
03
On successful authentication, the eSign Service Provider — itself a CCA-licensed Certifying Authority — generates a key pair inside a Hardware Security Module and issues a one-time Electronic Signature Certificate. The document is signed, and the API returns the signed file with a complete audit log.
Because the private key is created inside the HSM and destroyed immediately after signing, there is no reusable credential that could later be stolen or misused.
Integration
REST APIs and a full sandbox — integrate at your own pace before going live.
Compliance
Aadhaar eSign was formally notified into the Second Schedule of the Information Technology Act, 2000 by Gazette Notification GSR 61(E), dated 28 January 2015, under the Central Government's powers in Section 3A. The technical procedure is governed by the Information Technology (Electronic Signature or Electronic Authentication Technique and Procedure) Rules, 2015. Because it sits in the Second Schedule, an Aadhaar eSign carries the same legal standing as a handwritten signature under Section 5 of the IT Act for most commercial and consumer transactions.
This comes from the Bharatiya Sakshya Adhiniyam, 2023, which replaced the Indian Evidence Act on 1 July 2024. Section 63 governs the admissibility of electronic records, Section 73 allows a court to verify a digital signature against the signer's Electronic Signature Certificate, and Section 87 creates a presumption as to the correctness of that certificate.
The First Schedule of the IT Act excludes negotiable instruments, powers-of-attorney, trusts, wills and other testamentary dispositions, and contracts for the sale or conveyance of immovable property.An important carve-back applies for regulated lenders: cheques, demand promissory notes, and bills of exchange issued in favour of — or endorsed by — an entity regulated by the RBI, NHB, SEBI, IRDAI, or PFRDA can be eSigned, as can powers-of-attorney empowering such an entity to act on the signer's behalf.
Under the Digital Personal Data Protection Act, 2023, consent must be free, specific, informed, and unambiguous, and the data fiduciary carries the burden of proving it was obtained. An eSign audit trail is that proof, captured automatically at the moment of consent.
Last reviewed: 10 August 2026
Why Gridlines
Signing is one step, not a separate vendor.
Aadhaar eSign runs on the same platform as Aadhaar OVSE verification, DigiLocker workflows, Video KYC, and fraud-risk signals — so a borrower can be verified, screened, and signed inside one configurable journey.
Signing routes through an authorised, CCA-licensed eSign Service Provider, and Gridlines handles the orchestration around it — document handling, signer routing, status callbacks, and audit logging — so your team maintains one contract and one integration rather than stitching signing to the rest of your onboarding stack.
Book a Demo1B+
Across the full Gridlines identity platform.
600Mn+
Run through Gridlines' infrastructure.
99.9%
Built for high-volume, mission-critical signing.
4,000+
Across banking, lending, insurance, and fintech.
FAQs
It lets businesses build legally valid, Aadhaar-based signing into their own product — for contracts, loan agreements, KYC forms, and consent documents — without building and maintaining the signing workflow themselves.
Related products
Offline, consent-based Aadhaar verification.
Verified documents, direct from the issuer.
Drop-in identity checks for your app.
Remote, agent-assisted identity verification.
Catch synthetic media and manipulated identity.
One branded, step-by-step onboarding flow.
Get started
Get sandbox access and run your first eSign today, or talk to us about volume and compliance requirements.