For the complete documentation index, see llms.txt. This page is also available as Markdown.

SigningHub v10.0.4

February 2026

New Features

Authentication via Passkey (SHE-49628)

SigningHub now supports passkey-based authentication, allowing users to register, manage, and log in without passwords across supported devices and browsers. Passkeys can be used for both single and bulk signing, providing a secure and streamlined passwordless experience.

DDoS Protection and API Rate Limiting (SHE-47457)

DDoS prevention with an application-level rate limiting mechanism has been added to protect against excessive incoming requests. Administrators can configure global rate limits, per-IP concurrency limits, and stricter controls for sensitive endpoints, ensuring stable system performance while throttling potential malicious traffic. Hourly alerts can be sent to notify administrators when thresholds are exceeded.

Artificial Intelligence (AI) v1.1.x Integration (SHE-50981)

SigningHub now delivers AI-powered capabilities within documents and workflows, enabling users to simplify content, summarise text, analyse legal implications, and detect errors. Administrators can control AI access through enterprise roles and recipient permissions, with usage monitored via token limits and notifications, providing secure and intelligent document processing across workflows.

This is a license-based feature.

Document Stamps (SHE-57314)

SigningHub now allows users to manage and apply both personal and enterprise stamps to documents. Role-based permissions restrict stamp usage to authorised users only, ensuring controlled and secure application across workflows.

Custom Timestamping Authority Support (SHE-25263)

SigningHub now allows signatures and document enhancements to be timestamped using a configurable Timestamping Authority (TSA). Administrators can integrate either the default ADSS TSA or any external TSA server through a dedicated connector, providing greater flexibility while maintaining compliance with trusted timestamping standards.

Remember Image for Signature and Initials (SHE-57950)

SigningHub now provides a 'Remember image' option for signatures and initials. When selected, the chosen image is remembered for reuse within the session, allowing users to consistently use the same image across multiple signature or initials fields until manually changed.

Signature Image Customisation (SHE-55523)

SigningHub now allows users to rotate uploaded signature or initials images and adjust their transparency using a slider. Adjusting the transparency lets users remove the background for a cleaner, more professional look.


Improvements

Docker-Based Regular Release Installation Support (SHE-58522)

SigningHub now supports applying regular releases through the Docker installer for existing Linux-based deployments. This enhancement enables administrators to update running SigningHub containers to a newer release while preserving the existing configuration and database.

Session and Token Management Enhancements (SHE-58161)

SigningHub now enforces a configurable concurrent session limit per user, requiring users who exceed the limit to revoke existing sessions before logging in. Additionally, a new 'Refresh token idle expiry' setting allows administrators to specify how long a refresh token can remain inactive before being automatically revoked.

Bulk Sign and Bulk Share Enhancements (SHE-57269)

SigningHub now ensures that Bulk Sign and Bulk Share options appear correctly when multiple documents are selected, applying the actions only to eligible documents.

Allowed Domains for Embedded Viewer (SHE-51071)

SigningHub Admin provides an optional 'Allowed Domains' setting for system integrations. When specified, only the listed domains can embed the Document Viewer and SmartForms via iFrame; if left empty, embedding is allowed from all domains.

Branding Screen UI Improvement (SHE-57337)

The ‘Login Page Appearance’ tab in SigningHub Admin has been updated to align with the branding design in SigningHub Web, providing a consistent experience when configuring background images and slider content.

HashiCorp UAMI URL Configuration Support (SHE-58252)

SigningHub now supports configuring a dedicated UAMI URL for HashiCorp Key Vault integration, allowing administrators to explicitly define the Azure management URL used during authentication.

CSP Configuration for Allowed Domains (SHE-57311)

The Content Security Policy (CSP) for SigningHub Web has been updated to append allowed domains using a frame-ancestors directive. This ensures that only the domains specified in system integrations can embed the Document Viewer and SmartForms via iFrame, while leaving the setting empty allows embedding from any domain.

In-App Attachment Preview (SHE-57253)

SigningHub now provides recipients the ability to preview workflow attachments directly within the application, without downloading them. The 'Allow preview of document attachments' option can be configured by the document owner in the 'Recipient Permissions' settings.

Slider Activation Control (SHE-57041)

Administrators can now control the visibility of sliders by marking them as active or inactive. This option is available at both the SigningHub Admin and Enterprise levels, allowing precise management of slider content across desktop web and native applications.

Arabic Locale Support for Date Fields (SHE-56736)

A new 'Locale' property has been added to the 'Date' field. By default, the locale is set according to the user’s language, Arabic for Arabic users, and English for all others. The locale can be manually updated in draft mode through the 'Date' field's properties dialogue box. Once the field becomes a part of the PDF, the selected locale is embedded and remains unchanged regardless of where the document is opened.

Field Appearance Enhancements (SHE-56732)

The canvas size of the 'Initials' field has been reduced to ensure that the signed initials appear consistent with their size during signing. Additionally, field opacity in draft mode has been lowered to help users better visualise underlying document content while placing fields.

Signature Statistics by Signing Server (SHE-47456)

SigningHub now allows administrators to filter and export signature statistics by signing server, with server information recorded for both single and bulk signing.

Bulk Actions Support for APIs (SHE-55090)

SigningHub now introduces bulk action support for the following APIs:

  • Bulk 'Delete is now supported for:

    • Contacts (Personal & Enterprise)

    • Groups (Personal & Enterprise)

    • Libraries (Personal & Enterprise)

    • Templates (Personal & Enterprise)

    • Legal Notices (Personal & Enterprise)

    • SmartForms (Personal & Enterprise)

    • Users (Registered Users and Invitations)

    • Roles

    • Documents (Enterprise)

    • Electronic Seals (Enterprise)

    • Certificate Filters

    • Integrations (Enterprise)

  • Bulk 'Move to Folder' is now supported for:

    • Libraries (Personal & Enterprise)

Scope-Based Authentication for Dashboard Integrations (SHE-56527)

SigningHub now supports scope-based authentication for dashboard integration links. This allows users to securely access SigningHub via an embedded dashboard experience and perform bulk signing without requiring credential-based authentication.

SAP Multipart Upload (SHE-58612)

SigningHub now supports the handling of binary-formatted documents generated via SAP using multipart/form-data.

Improved CSV Header Handling (SHE-58633)

CSV header processing has been improved to handle leading and trailing spaces, ensuring headers are matched correctly during import.

CSC Signing with Explicit SCAL 2 (SHE-58603)

CSC signing now fully supports explicit SCAL 2 authentication, prompting users for PIN/OTP during signing to ensure the selected documents are signed correctly.

Improved Workflow Status Handling (SHE-58506)

Workflow processing for shared-space templates has been improved to ensure documents move correctly through all signatories, with statuses updated accurately at each step.

Arabic Mobile Number Alignment (SHE-58372)

Mobile numbers in the Arabic UI now display correctly, with digits shown left-to-right within right-to-left pages, ensuring accurate and consistent representation across all relevant screens.

Document Deletion Enhancement (SHE-58352)

The document deletion process has been enhanced to ensure files are reliably removed from the configured storage directory whenever workflows or documents are deleted.

Workflow Sharing for Non-Conformant PDFs (SHE-58258)

The PDF parsing process has been enhanced to support workflow sharing for documents without a conformance dictionary, ensuring workflows are shared reliably without errors.

Workflow Evidence Report (SHE-58246)

Error handling for Workflow Evidence Report generation has been enhanced, with additional checks to ensure reports are generated reliably across all workflows.

Workflow Attachment Download (SHE-58205)

Attachment downloads in workflows are now governed exclusively by the document owner’s ‘Download Document’ recipient permission, ensuring users can easily access and review all attachments before signing.

User Role Picklist Enhancement (SHE-58078)

The user role picklist now supports dynamic loading and text search, allowing all roles to be displayed and easily found when assigning roles to a user.

Webhook Report Improvement (SHE-58057)

Webhook reports now display the reviewer’s information in signing workflows, presenting the user in the “Performed By” field.

Duplicate Signature Handling (SHE-57566)

Bulk signing with SES-level assurance now prevents duplicate signatures by correctly tracking the processing status of signature fields.

XML Commitment Type Standardisation (SHE-57490)

The “Proof of Sender” value in XML signatures now follows the official XAdES standard. This ensures that signed XML files correctly indicate the signer is the sender of the document, improving compatibility and compliance with electronic signature specifications.

Improved Unique Identifier Handling (SHE-57420)

In 'Only me' workflows, SES-level signatures now generate documents with the Unique Identifier applied once, preventing duplication and ensuring the signed document renders as expected.

Login Screen UI Improvement (SHE-57260)

When a user chooses the SigningHub ID, Passkey, or Verisec public authentication profiles, the Credentials Email page is displayed, and other profiles are hidden, clearly indicating the chosen method.

Workflow Library Icon (SHE-57233)

The 'Library' icon has been updated with a new design for both Desktop and Mobile views, improving visibility and making it easier for users to access their saved documents.

OIDC Logout Enhancement (SHE-58952)

SigningHub Web logout for OIDC authentication profiles has been improved. The logout URL now includes the required id_token_hint parameter, ensuring user sessions are correctly terminated, and login/logout flows operate as expected.

Improved Database Collation Handling (SHE-58095)

Database operations now handle mixed collation environments correctly, eliminating collation-related errors and ensuring reliable execution without requiring any changes to existing database or server settings.

Email Service Logging Optimisation (SHE-57952)

Repeated log entries from the email service (GetEmailTemplates) have been removed, reducing unnecessary log noise and keeping API logs cleaner and easier to monitor.

Improved Load-Balanced Node Upgrade Handling (SHE-58100)

SigningHub automatically skips unnecessary database scripts when the database is already up to date, preventing errors and ensuring a seamless upgrade.

Admin API Refresh Token Support (SHE-56665)

The SigningHub Admin API now supports refresh tokens, allowing long-lived sessions and authentication without requiring repeated login.


Security Improvements

Enhanced Email Security Validation (SHE-58618)

SigningHub now enforces stricter email validation to mitigate homograph and impersonation risks. Email addresses using punycode domains or mixed Unicode scripts are no longer permitted.

Updated Third-Party Libraries

The following updates have been made to third-party libraries:

  • Common

    • ABCpdf updated from 13.3.5 to 13.3.10

    • Aspose updated from 25.7.0 to 25.10.0

  • Web

    • @angular/cli updated from 19.2.12 to 20.3.14

  • Admin

    • @angular/cli updated from 19.2.11 to 20.3.14

    • @angular-devkit/build-angular updated from 19.2.11 to 20.3.14

In addition, several other third-party dependencies have been updated to improve stability, security, and compatibility.


New ADSS Server Support

ADSS Server Support

SigningHub now supports ADSS Server 8.3.14.


New AI Server Support

AI Server Support

SigningHub supports AI Server 1.1.x.


Important System Changes

As part of the upgrade to SigningHub 10.0.4:

  • All existing refresh tokens will be invalidated. Users must re-authenticate to generate new tokens.

  • Concurrent sessions are now limited per user, and unlimited sessions are no longer allowed. Sessions remain active until the user logs out or explicitly revokes them using the revoke API. If the maximum number of active sessions is reached, new login attempts are blocked until an existing session is revoked. The default limit is 10 concurrent sessions per user, with a maximum allowed limit of 100.

  • The following API responses have been updated for consistency when no data is available:

    • Get Workflow Users of Enterprise Package API now returns an empty array with 200 OK instead of 400 Bad Request.

    • Get Enterprise Package Timeline API now returns 204 No Content instead of 404 Not Found.

  • The URLs of the following APIs have changed. Integrations using the previous endpoints must update to the new URLs:

    • Import Enterprise Invitations Templateenterprise/invitations/import-template

    • Import Enterprise User Templateenterprise/users/import-template

    • Import Recipient (Template)templates/{templateId:int}/workflow/users/import-template

    • Import Recipient Templatepackages/{packageId:long}/workflow/users/import-template

  • For the Add TextBox Field, Add TextBox Field (Template), and AutoPlace Fields APIs, if field_local is not provided in the request, SigningHub will use the user’s configured locale. For Arabic users, field_local is automatically set to Arabic along with the corresponding font. The field_local and font objects are now included in the API response.

  • The Generate Integration URL for Encrypted Data (Coding) API now validates that the package and the API integration key belong to the same enterprise before generating the integration URL. Requests that fail this validation are rejected to prevent cross-enterprise access.


Compatibility with Earlier Versions of SigningHub

SigningHub (iOS) & (Android) v10.0.4 are compatible with SigningHub 10.0.3 except for the breaking changes mentioned in the Important System Changes section.


For further details, contact us at sales@ascertia.com or visit www.ascertia.com.

Last updated