User authentication and registration with digital certificate

Reliably identify users and legal representatives through qualified digital certificates, without passwords or complex verification processes.

* SaaS service compatible with qualified digital certificates from the European Union.

User identification with qualified digital certificates
Security and trust issues in online user identification.

The challenge of securely identifying users in digital environments

Traditional registration and login systems based on username and password create friction, drop-offs and security risks.

Access through third-party accounts such as Google or Facebook is convenient, but does not prove the user’s real identity.

In sensitive or regulated processes, organizations need mechanisms that guarantee the true identity of the person accessing their digital services.

Certvalidator, authentication with real digital identity

Certvalidator is a SaaS service that enables user authentication and registration through qualified digital certificates, validating the user’s identity from the first access without adding technical complexity to the platform.

How Certvalidator works

Certvalidator acts as a secure intermediary between the user and the platform, managing the complete authentication process using a digital certificate.

The user accesses your platform

The user starts the registration or login process and is redirected to the Certvalidator service to identify themselves with their digital certificate. The browser displays a list of available certificates.

Digital certificate validation

Certvalidator verifies that the selected certificate is authentic and trustworthy: valid, not revoked (OCSP/CRL), and issued by a Certification Authority accepted under eIDAS (TSL).

User identification

Once the certificate is validated, Certvalidator processes its content (X.509) and extracts the identity data required to identify the user or the legal representative of a company (specific OIDs).

Data returned to your platform

Certvalidator returns the validation result and certificate data to the platform in structured format via custom HTTP headers, allowing the access or registration process to be completed.

What data your platform receives after authentication

Certvalidator returns to your platform the data extracted from the digital certificate once validated, ready to be processed directly by your backend.

  • User identity
    Certificate holder identifier (Tax ID/National ID or equivalent) and full name, extracted directly from the digital certificate.
  • Contact details
    Certificate holder’s email address when present in the certificate.
  • Company and legal representative
    Name and tax ID of the represented organization, along with the legal representative’s details, in legal entity certificates when applicable.
  • Validation status
    Result of the certificate validation process, indicating whether it is valid, revoked, expired or untrusted.
  • Certificate issuer
    Information about the Certification Authority that issued the digital certificate.
  • Full digital certificate
    User certificate in standard format (PEM), available for auditing, traceability or additional checks.

Available fields depend on the type of certificate and the service configuration.

Example of HTTP headers

Data is delivered as HTTP headers so your backend can process it immediately.

X-status: good
X-ID: 12345678Z
X-DN: subject=C=ES, serialNumber=12345678Z, SN=GARCIA, GN=JOSE
X-email: [email protected]
X-organization: Empresa S.A.
X-representative: Juan Pérez
X-representative-ID: 12345679S
X-issuer: CN=AC..., O=..., C=ES

# Certificado digital completo (opcional)
X-cert: -----BEGIN CERTIFICATE-----
MIIF...
... (contenido PEM)
-----END CERTIFICATE-----

Using the full certificate (PEM) is optional and only necessary if the platform requires auditing, traceability or additional validations.

In which scenarios is Certvalidator useful?

Certvalidator fits scenarios where users or companies need to be securely identified through digital certificates, without adding technical complexity.

Identify users through digital certificates

For platforms that need to know the real identity of users in registration or login processes, without relying on passwords or third-party accounts.

Replace username and password in sensitive access

When access to private areas, backoffice or critical services requires strong, secure and traceable authentication.

Identify companies and legal representatives

For B2B scenarios where it is necessary to know the represented company and its legal representative, without requesting powers of attorney or additional documentation.

Avoid additional verification processes

When the user already has a digital certificate and you want to complete registration or onboarding without running additional processes such as eKYC.

Accepted digital certificates and coverage

The service is capable of validating more than 4,000 certificates from 440 qualified trust service providers (TSPs) across different European countries, as well as other countries in America, Africa and the Middle East. The process is fully transparent for the end user, regardless of the certificate or country of origin.

Country № Accepted certificate providers № Accepted certificate types
Austria791
Belgium15105
Bulgaria777
Cyprus18
Czechia8334
Germany27904
Denmark313
Estonia254
Greece5120
Spain60327
Finland119
France35250
Croatia432
Hungary19319
Ireland410
Iceland26
Italy53451
Liechtenstein49
Lithuania864
Luxembourg319
Latvia129
Malta39
Netherlands1384
Norway1447
Poland12118
Portugal1090
Romania7116
Sweden37
Slovenia983
Slovakia10234
United Kingdom169
Total3574038

You can see the detailed list of European Union countries and providers at this link: https://eidas.ec.europa.eu/efda/tl-browser/#/screen/home

Country Accepted certificate provider
United States of AmericaEntrust.net Certification Authority (2048)
United States of AmericaAdobe Systems Incorporated
ColombiaGlobal Certification Authority Root GSE
ColombiaAutoridad Raiz GSE
ColombiaROOT CA ANDES SCD S.A.
ColombiaAC Raíz Certicámara S.A.
ColombiaCAEDICOM Root
ColombiaThomas Signe Root
ColombiaOlimpiaIT ECD
ColombiaAC CAMERFIRMA S.A.
ColombiaPKI Services Root CA
ColombiaVALID COLOMBIA ROOT CA
ColombiaCertification Authority Root Lleida SAS
PeruDIGITAL CERTIFICATES ISSUED BY CERTIFICATION AUTHORITY TO THE PERUVIAN STATE-ECEP CLASE III SHA 1
PeruDIGITAL CERTIFICATES ISSUED BY CERTIFICATION AUTHORITY TO THE PERUVIAN STATE-ECEP CLASS III SHA 256
PeruDIGITAL CERTIFICATES ISSUED BY CERTIFICATION AUTHORITY TO THE PERUVIAN STATE-ECEP CLASS II SHA 256
PeruDIGITAL CERTIFICATES ISSUED BY CERTIFICATION AUTHORITY TO THE PERUVIAN STATE-ECEP CLASS II SHA 1
PeruDIGITAL CERTIFICATES ISSUED BY CERTIFICATION AUTHORITY TO THE PERUVIAN STATE-ECEP CLASS I SHA 256
PeruDIGITAL CERTIFICATES ISSUED BY CERTIFICATION AUTHORITY TO THE PERUVIAN STATE - ECEP CLASS I SHA 256
PeruDIGITAL CERTIFICATES ISSUED BY CERTIFICATION AUTHORITY TO THE PERUVIAN STATE-SHA256
PeruDIGITAL CERTIFICATES ISSUED BY CERTIFICATION AUTHORITY TO THE PERUVIAN STATE-SHA1
PeruWISEKEY CERTIFYID ADVANCED GB CA 2
PeruWISEKEY CERTIFYID ADVANCED SERVICES CA 4
PeruACCREDITED DIGITAL CERTIFICATES
PeruAC COMODO (SHA256) TO FULFILL THE SD 105-2012-PCM
PeruDIGITAL CERTIFICATES ISSUED BY THE ECEP USING THE ECERNEP PERU CA ROOT 3 HIERARCHY
PeruDIGITAL CERTIFICATES ISSUED BY ECEP-RENIEC USING THE ECERNEP PERU CA ROOT 3 HIERARCHY
PeruEREP (DNIE NATURAL PERSON) BY RENIEC
PeruDIGITAL SIGNATURE SOFTWARE BY RENIEC
PeruESIGNACRYPTO DIGITAL SIGNATURE SOFTWARE BY INDENOVA S.L.
PeruAC ENTRUST INC TO FULFILL THE SD 105-2012-PCM
PeruCA-ENTRUST INC TO FULFILL THE S D 105-2012-PCM
PeruCA DIGI SIGN TO FULFILL THE SUPREME DECREE 105-2012-PCM
PeruINTERMEDIATE AC ACEDICOM
PeruCA ACEDICOM ROOT
PeruAC FIRMA PROFESIONAL S.A. TO FULFILL THE SD 105-2012-PCM
PeruAC CERTISIGN TO FULFILL THE SD 105-2012-PCM
PeruAC GSE TO FULFILL THE SD 105-2012-PCM
PeruAC CERTICAMARA TO FULFILL THE SD 105-2012-PCM
PeruAC GLOBALSIGN TO FULFILL THE SD 105-2012-PCM
PeruTSU CAMERFIRMA PERU SAC
PeruAC CAMERFIRMA PERÚ - 2016
PeruGLOBAL CHAMBERSIGN ROOT - 2016
PeruEC AC CAMERFIRMA PERU - 2016 POR CAMERFIRMA PERU S.A.C
PeruQUALIFIED CERTIFICATES ISSUED BY CA AC RACER 2009
PeruANF AC ROOT CERTIFICATION ENTITY PERU
PeruANF AC AUTHORITY CERTIFICATION PERU S.A.C
PeruEC BMCERT
PeruENTIDAD DE CERTIFICACION INDENOVA PERU
PeruINDENOVAS ROOT CERTIFICATION AUTHORITY OF PERÚ
PeruACEPTA - INTERMEDIA SELLADO DE TIEMPO 2018
PeruACEPTA - INTERMEDIA FIRMA DIGITAL 2018
PeruACEPTA - INTERMEDIA FIRMA ELECTRONICA 2018
PeruACEPTA - ROOT 2018
PeruENTIDAD DE CERTIFICACION CORE ANDINA
PeruENTIDAD DE CERTIFICACIÓN CORE ANDINA - RAÍZ
PeruCA BIT4ID SAC CA2 2016 BY UANATACA
PeruCA BIT4ID SAC CA1 2016 BY UANATACA
PeruCA BIT4ID SAC ROOT 2016 BY UANATACA
PeruCA LLAMA.PE SHA256 STANDARD CA BY LLAMA.PE
PeruCA LLAMA.PE ROOT CA BY LLAMA.PE
PeruSIGNE CERTIFICATION AUTHORITY
PeruCERTIFICATION AUTHORITY FIRMAPROFESIONAL CIF A62634068
PeruINTERMEDIATE CA OF INDENOVA PERU
PeruROOT CERTIFICATION AUTHORITY OF INDENOVA PERU
PeruSOFT & NET SOLUTIONS SAC INTERMEDIATE CERTIFICATION AUTHORITY
PeruSOFT & NET SOLUTIONS SAC ROOT CERTIFICATION AUTHORITY
PeruROOT AND SUBSEQUENT LEVEL CERTIFICATION AUTHORITY OF TOC PERU SAC
PeruAC ROOT 5 OF THE SECRETARIA DE GOBIERNO Y TRANSFORMACION DIGITAL
Dominican RepublicABA CA1
Dominican RepublicAVANSI CERTIFICADOS DIGITALES
Dominican RepublicVIAFIRMA TSA SUB CA
Dominican RepublicVIAFIRMA QUALIFIED CERTIFICATES
Dominican Republicdigifirma CA Subordinada 1
Dominican RepublicinDenova SUB CA 003
Dominican RepublicOGTIC QUALIFIED CERTIFICATES
Dominican RepublicECD Thomas Signe Colombia
Total77
Country Accepted certificate provider
United Arab EmiratesUAE Global Root CA G4 E2
United Arab EmiratesDigitalTrust Root CA G3
United Arab EmiratesDigitalTrust Root CA G4
MoroccoBaridesign AC Class 3
MoroccoBaridesign AC Class 2
MoroccoEurafric Trust Root CA
Total6

Transparent pricing and SaaS model

Certvalidator is offered as a SaaS service with a fixed fee and a variable cost per use, adapting to the authentication volume of each platform.

Monthly subscription

To get started quickly and flexibly

25 € /month

+ 0,35 € per authentication performed

  • Fixed monthly fee
  • Pay-per-use based on volume
  • Ideal for pilots or ramp-up

Annual subscription

Better monthly price with annual commitment

Recommended
19 € /month

+ 0,35 € per authentication performed

  • Reduced monthly fee
  • Pay-per-use based on volume
  • Ideal for production

The usage cost applies per processed authentication. For volume needs or specific coverage, contact us.

Frequently asked questions about Certvalidator

Certvalidator is designed for web platforms that need to securely identify their users, especially in registration, login, onboarding or digital procedures where knowing the user’s real identity is required.

The digital certificate acts as an access credential. Certvalidator uses it to identify the user, verify its validity and extract the necessary data so the platform can authorize access or complete registration.

Yes. The service validates digital certificates issued by recognized Certification Authorities, providing multi-country support and returning data in a standardized format for the platform.

Yes. When supported by the certificate, Certvalidator identifies the represented company and its legal representative, facilitating business onboarding without requiring additional documentation.

If the certificate is expired, revoked or does not meet the configured criteria, Certvalidator reports the validation result so the platform can decide how to proceed.

No. The use of the full certificate in PEM format is optional. The platform may use only the extracted data or store the certificate solely if traceability or auditing is required.

It does not replace it, but it can complement it. In many cases, when the user has a digital certificate, Certvalidator allows the identification process to be completed without running an additional eKYC flow.

No. Certvalidator is designed for simple integration, delegating the complexity of handling digital certificates and returning only the data required for the platform’s business logic.

No. Certvalidator focuses exclusively on user authentication. For electronic signature or signed document validation, Lleida.net offers specific solutions such as USVC.

Do you have a specific use case or need advice?

Talk to our team and we will help you integrate Certvalidator into your platform.