Gridlines by OnGrid

Aadhaar eSign API

Aadhaar eSign API — Legally Binding Signatures in Under a Minute

Let your users sign contracts, loan agreements, and KYC forms with nothing but their Aadhaar number and an OTP. Full legal standing under the IT Act, 2000, delivered through a single API into your existing onboarding flow.

1B+ verifications processed4,000+ clientsISO 27001:2022SOC 2 Type II
Loan_Sanction_Letter.pdfSigned
Authenticated viaAadhaar OTP
CertificateOne-time ESC issued
Signing keyGenerated in HSM, destroyed
Time to sign42 seconds
Audit trailTimestamp, IP, device
Download signed document →
Equal to a handwritten signature
No USB token, no hardware
Under a minute, end to end
Full audit trail, every signature

Trusted by

Trusted by India's leading lenders, insurers, and fintechs

1B+

Verifications processed

600Mn+

Transactions per year

4,000+

Clients served

99.9%

Platform uptime

What is the Aadhaar eSign API

A government-enabled electronic signature, built into your own product

The Aadhaar eSign API is a government-enabled electronic signature service, built on India's Aadhaar identity infrastructure, that you integrate directly into your own product.

Instead of a printed page or a USB-based Digital Signature Certificate (DSC) token, the signer authenticates with their Aadhaar number and a one-time password, or biometrics. Once UIDAI confirms their identity, a licensed Certifying Authority issues a one-time Electronic Signature Certificate, uses it to cryptographically sign the document, and destroys it.

Tamper-evident — any change after signing invalidates it
Traceable — timestamp, IP address, device details
Fast — authenticate-to-signed in under a minute

Aadhaar eSign vs. DSC vs. simple electronic signature

Aadhaar eSignDSC (USB token)Simple e-signature
Legal standingSecond Schedule, IT Act — equal to a handwritten signatureSection 3, IT Act — equal to a handwritten signatureNot in the Second Schedule; evidence of agreement, without the IT Act presumption
HardwareNoneUSB cryptographic tokenNone
Signer setupNone — Aadhaar number + OTPDays: KYC, issuance, shippingNone
CertificateOne-time, issued at signingValid 1–3 yearsN/A
Cost modelPer signaturePer token, per yearUsually bundled
Best fitHigh-volume customer signingDirectors, statutory filingsLow-risk internal approvals

The problem

Every business that collects signatures hits the same bottleneck

Printing, courier, notarisation, and the days it takes to execute one agreement.

Broken digital journeys

Manual signing breaks digital onboarding journeys and adds days to time-to-close.

Slow audits & disputes

Paper trails make compliance audits and dispute resolution slow and expensive.

Fraud exposure

Self-attested identity checks are easy to spoof, increasing fraud exposure.

Doesn't scale

Physical processes don't scale as loan books, policy volumes, or hiring pipelines grow.

Why regulated lenders can't defer this

The RBI (Digital Lending) Directions, 2025, effective 8 May 2025, consolidated India's digital lending rules and extended them to All-India Financial Institutions alongside banks, co-operative banks, and NBFCs. Regulated entities must issue a Key Fact Statement (KFS) — per RBI's circular of 15 April 2024 — before the loan contract is executed, and furnish digitally signed documents to the borrower on execution.

Every digitally originated loan now generates several documents that must be delivered, acknowledged, and executed inside a compressed window, with a demonstrable record of each step. Aadhaar eSign is how most lenders close that loop without breaking the digital journey.

IntegrationSingle API, single dashboard
Signing providerCCA-licensed eSign Service Provider
Signer requirementAadhaar number + OTP
Legal weightFull standing in an Indian court

The solution

Compliant signing, embedded in your own workflow

Gridlines' Aadhaar eSign API embeds compliant, government-backed signing directly into your onboarding, lending, or HR workflow. Signing runs through an authorised, CCA-licensed eSign Service Provider, so every signature is compliant by default — while you keep a single integration, a single dashboard, and your own brand in front of the customer.

Anyone with an Aadhaar number can sign in under a minute using an OTP sent to their registered mobile, and the signature carries full legal weight in an Indian court.

Features & benefits

What changes when signing takes minutes, not days

Speed

Agreements that took days to circulate, print, sign, and return complete in minutes — decisive wherever deal velocity affects revenue.

Lower operational cost

No printing, courier, physical storage, or manual verification. Per-document execution cost drops sharply at scale.

Stronger compliance posture

Every signature carries a verifiable audit trail — signer identity, timestamp, IP address, device fingerprint — captured at the moment of consent rather than reconstructed later.

Better customer experience

Customers complete onboarding, loan applications, or policy purchases entirely on their phone. No branch visit, no printing.

Reduced fraud risk

Identity is verified against UIDAI's infrastructure directly, not a document upload or self-attestation.

Tamper-proof by design

The signing private key is generated inside a Hardware Security Module and destroyed immediately after use, leaving no reusable credential to steal.

Industries

Wherever a signature stands between intent and execution

Banking & NBFCs

Loan agreements, sanction letters, KFS execution.

Insurance

Policy issuance, proposal forms, claim consent.

Fintech

Account opening, KYC, mandate forms.

Staffing & HRTech

Offer letters, employment contracts, policy acknowledgments.

Mobility & gig workforce

Partner agreements and onboarding contracts.

Marketplaces

Seller and merchant agreements.

Use cases

Where Aadhaar eSign closes the loop

Banking & NBFC

Loan origination

Borrower eSigns the sanction letter and KFS the moment the loan is approved, keeping the digital journey unbroken.

Insurance

Insurance issuance

Policyholder eSigns proposal and consent forms without a branch visit.

Fintech

Customer onboarding

Account opening and mandate forms signed and stored with a compliant audit trail.

HRTech

Workforce onboarding

Offer letters and policy acknowledgments signed remotely at scale.

Marketplaces

Merchant and vendor agreements

MSAs and NDAs executed without printing, courier, or a meeting.

See it for your use case →

How it works

Several specialised players behind the scenes — three steps for the signer

01

Upload and initiate

Your application calls the Aadhaar eSign API to upload the document and start a signing request. The Application Service Provider computes the document hash that will be signed.

02

Authenticate with Aadhaar

The signer enters their Aadhaar number and verifies via OTP or biometric. Authentication is performed by UIDAI — credentials are encrypted at the point of capture, and neither Gridlines nor your platform stores biometric data.

03

Sign and deliver

On successful authentication, the eSign Service Provider — itself a CCA-licensed Certifying Authority — generates a key pair inside a Hardware Security Module and issues a one-time Electronic Signature Certificate. The document is signed, and the API returns the signed file with a complete audit log.

Because the private key is created inside the HSM and destroyed immediately after signing, there is no reusable credential that could later be stolen or misused.

Integration

API Specifications

REST APIs and a full sandbox — integrate at your own pace before going live.

Compliance

The legal basis, in full — not just the summary

Legal basis

Aadhaar eSign was formally notified into the Second Schedule of the Information Technology Act, 2000 by Gazette Notification GSR 61(E), dated 28 January 2015, under the Central Government's powers in Section 3A. The technical procedure is governed by the Information Technology (Electronic Signature or Electronic Authentication Technique and Procedure) Rules, 2015. Because it sits in the Second Schedule, an Aadhaar eSign carries the same legal standing as a handwritten signature under Section 5 of the IT Act for most commercial and consumer transactions.

Evidentiary value

This comes from the Bharatiya Sakshya Adhiniyam, 2023, which replaced the Indian Evidence Act on 1 July 2024. Section 63 governs the admissibility of electronic records, Section 73 allows a court to verify a digital signature against the signer's Electronic Signature Certificate, and Section 87 creates a presumption as to the correctness of that certificate.

Excluded documents

The First Schedule of the IT Act excludes negotiable instruments, powers-of-attorney, trusts, wills and other testamentary dispositions, and contracts for the sale or conveyance of immovable property.An important carve-back applies for regulated lenders: cheques, demand promissory notes, and bills of exchange issued in favour of — or endorsed by — an entity regulated by the RBI, NHB, SEBI, IRDAI, or PFRDA can be eSigned, as can powers-of-attorney empowering such an entity to act on the signer's behalf.

Data protection

Under the Digital Personal Data Protection Act, 2023, consent must be free, specific, informed, and unambiguous, and the data fiduciary carries the burden of proving it was obtained. An eSign audit trail is that proof, captured automatically at the moment of consent.

Certifications

ISO 27001:2022ISO 9001:2015SOC 2 Type IIGDPR compliantNASSCOM member
Gridlines provides technology infrastructure for configurable signing workflows. Customers remain responsible for consent notices, document eligibility, data usage, and compliance with applicable law.

Last reviewed: 10 August 2026

Why Gridlines

Signing is one step, not a separate vendor.

Aadhaar eSign runs on the same platform as Aadhaar OVSE verification, DigiLocker workflows, Video KYC, and fraud-risk signals — so a borrower can be verified, screened, and signed inside one configurable journey.

Signing routes through an authorised, CCA-licensed eSign Service Provider, and Gridlines handles the orchestration around it — document handling, signer routing, status callbacks, and audit logging — so your team maintains one contract and one integration rather than stitching signing to the rest of your onboarding stack.

Book a Demo

1B+

Verifications processed

Across the full Gridlines identity platform.

600Mn+

Transactions a year

Run through Gridlines' infrastructure.

99.9%

Platform uptime

Built for high-volume, mission-critical signing.

4,000+

Clients

Across banking, lending, insurance, and fintech.

FAQs

Common questions

It lets businesses build legally valid, Aadhaar-based signing into their own product — for contracts, loan agreements, KYC forms, and consent documents — without building and maintaining the signing workflow themselves.

Get started

Ready to make signing the fastest step in your workflow?

Get sandbox access and run your first eSign today, or talk to us about volume and compliance requirements.