The strongest levels of digital signature

Your digital signature…
on a USB key that never leaves you.

When a contract deserves the highest level of protection, its owner signs it with an accredited token: a USB key holding their digital certificate issued by a licensed authority such as Misr for Central Clearing. They plug the token into their device, the local Wthaiq agent reads the certificate, they enter their PIN, and a PAdES signature with a trusted timestamp is embedded inside the PDF file itself — the strongest cryptographic standing there is.

An accredited certificate A key that never leaves the token PAdES + timestamp
The local Wthaiq agent — digital signing with a token Secure session
The local Wthaiq agentToken status
Wthaiq
E-signature certificate
NameMahmoud Tawfik
Issuing authorityMisr for Central Clearing MCDR
ValidityValid · 2027
Digitally signed — the contract is secured
Signature PAdES Embedded in the PDF + a trusted timestamp · any change after signing breaks the seal immediately
An accredited electronic certificateIssued by a licensed certification authority
The key never leaves the tokenSigning takes place inside the chip itself
Embedded PAdES signatureinside the PDF file and visible in any reader
Trusted TSA timestampTiming that cannot be denied
The highest standard of proof

Why token signing is The strongest legally?

An ordinary signature proves consent; a token signature proves identity and content together with mathematical proof that cannot be denied. It brings together three elements no other method offers: An officially accredited certificate, andA private key locked inside the chip, andA signature embedded in the file itself — so your contract comes as close as it can to a formally executed instrument.

An accredited electronic certificate

The certificate on the token is issued by a licensed certification authority such as Misr for Central Clearing (MCDR), after an official check of your identity — so it carries legal value recognised by public bodies and courts.

The private key never leaves the token

The entire signing operation is carried out inside the token's secure cryptographic chip. Your private key is never copied, never exported and never passes through our servers — impersonating or duplicating it is practically impossible.

PAdES signature embedded inside the PDF

The signature is embedded inside the contract file under the international PAdES standard, not in a separate file. It travels with the document wherever it goes, and appears as a valid digital signature in any PDF reader that supports verification.

Trusted TSA timestamp

The signature carries a timestamp from a trusted time service that establishes the moment of signing precisely. No party can claim the contract was signed on another date or go back on it after their time has passed.

Any change after signing breaks the seal

The signature is tied to a cryptographic fingerprint of the file's entire content. Changing one letter or one comma after signing changes the fingerprint and breaks the signature immediately, showing a clear warning that the document was altered after it was approved.

The local Wthaiq agent is secure

The agent is a small program installed once to connect the browser to the token. Its only role is to pass the signing request to the chip, without ever seeing or sending your key — an encrypted bridge between your device and the platform.

The full journey

How signing works With a token?

1

Connect the token to your device

Plug your accredited signing token into any USB port on your computer. No setup needed each time — once it is connected it is ready, and the local Wthaiq agent recognises it automatically within seconds.

USB portNo repeated set-upAutomatic recognition
2

The Wthaiq agent reads your certificate

The local agent reads your digital certificate's details from the token — the name, the issuing authority and the validity — and displays them on the signing page. You confirm it is the right certificate before continuing, and your private key stays locked inside the chip.

Reading the certificateView its detailsThe key is protected
3

Enter the PIN

You enter the token's PIN to authorise the signature. Only then does the chip carry out the signing internally. The PIN is never sent to any server, and without it nobody can use the token even if they get hold of it.

Signing authorisationhappens inside the chipTwo layers of protection
4

Embedded signature + timestamp

A PAdES signature is embedded inside the PDF file accompanied by a trusted timestamp, together with a cryptographic fingerprint of the entire content. You get a final contract whose signature shows as valid in any reader, and any later change gives itself away immediately.

PAdES built inTSA timestampCryptographic fingerprint
Plug the token into a USB port
E-signature certificate
NameMahmoud Tawfik
Issuing authorityMisr for Central Clearing MCDR
ValidityValid · 2027
The Wthaiq agent reads your certificate securely
123456789
Enter the PIN — the key never leaves the token
Embedded PAdES signatureTrusted timestamp · 2026
A signature embedded in the PDF + a timestamp
Choose the strongest option when you need it

When to use it Signing with a token?

High-value contracts

Major supply deals, partnership agreements and investment contracts carrying enormous financial obligations — where every clause deserves the strongest proof that the signature is genuine and that no one can deny it later.

Official documents

Instruments submitted to government, judicial or regulatory bodies, which require the highest level of authentication. Token signing gives them standing equivalent to a printed certified signature.

Bodies that require an accredited signature

When you deal with institutions, tenders or parties that expressly require a digital signature with an accredited certificate, the token meets that requirement out of the box, so your contract goes through with no objection and no request to sign again.

Quick guide

Everything you want to know about The signing token.

What is a signing token?
How it differs from an ordinary signature
What is PAdES and how does it protect the file?
Requirements: the token and the local agent

What is an electronic signature token?

An electronic signature token is a small device shaped like a USB stick that holds an accredited digital certificate and a private key protected inside a crypto chip from which it cannot be extracted. It is issued by a licensed certification authority such as Misr for Central Clearing, Depository and Registry (MCDR) after your identity has been verified, making it your official signature in digital form. Every signing operation is carried out inside the token itself once you enter your PIN, and your key never leaves the device at any moment.

A secure USB keyAn accredited certificateA protected private key

What is the difference between it and an ordinary signature?

A standard electronic signature proves consent through a link and a verification code sent to your email or phone, and that is enough for most day-to-day transactions. Token-based signing adds a layer of encryption that cannot be forged: an accredited certificate issued by an official authority, a private key locked inside the chip, and a mathematical fingerprint embedded in the file itself. The result is a signature carrying the highest degree of legal weight, hard to deny or challenge before any authority. And the standard signature remains the quick option for less sensitive transactions.

Higher legal standingHard to denyFor sensitive transactions

What is PAdES and how does it protect the file?

PAdES stands for PDF Advanced Electronic Signatures, a global standard for embedding the digital signature inside the PDF file itself instead of attaching it as a separate file. When you sign, a cryptographic fingerprint is calculated across the entire content of the document, sealed with your private key and a trusted timestamp, and then stored inside the file. Any later change, even a single character, alters that fingerprint and breaks the signature. The warning appears immediately in any PDF reader that supports validation. So you can be sure the contract in your hands is exactly the one that was signed.

Embedded signatureA fingerprint of the whole fileReveals any change

What are the requirements (the token + the local agent)?

You need just two things: an accredited signing token issued in your name by a licensed authority and carrying a valid certificate, and the Wthaiq local agent, a small program installed once on your machine to connect the browser to the token securely. After installation, simply plug the token into any USB port and open the signing page, and the agent recognises your certificate automatically and asks for your PIN to complete the signature, with no further setup. The agent works with Chrome, Edge, and Firefox on Windows.

Approved tokenLocal agentA one-time installation
Quick questions

FAQ before your first token signature.

Where do I get an accredited signing token?

It is issued by the licensed authorities in your country — in Egypt, for example, Misr for Central Clearing (MCDR) and other electronic certification service providers. You apply, the authority verifies your identity, then hands you a USB token carrying your digital certificate in your name or your company’s.

Does it work with any browser and operating system?

Yes — the local Wthaiq agent runs on your device and the browser talks to it automatically, so it works with Chrome, Edge and Firefox. All you need is to install the agent once and plug in the token, and your certificate appears ready on the signing page.

What does the local Wthaiq agent do? And is it safe?

The agent is a secure bridge between your browser and the token: it reads your certificate details and passes the signing request to the chip, nothing more. Your private key never leaves the token and never passes through our servers, and the signature is executed inside the chip itself once you enter your PIN.

Can a contract be tampered with after it is signed with a token?

No — a PAdES signature binds a cryptographic fingerprint to the entire content of the file. Any later change, even a comma, alters the fingerprint and breaks the signature, so it appears immediately as a “document has been modified since signing” warning in any PDF reader that supports verification.

What is the difference between signing with a token and signing with identity verification?

Identity verification confirms who the signer is through a face check and an official document at the moment of signing, while a token signs with a cryptographic fingerprint from an officially accredited certificate. The token carries the strongest legal standing because it combines an identity already verified by the issuing authority with an embedded digital signature that cannot be altered.

Is token signing legally recognised?

Yes — signing with an accredited certificate issued by a licensed certification authority carries the highest evidentiary weight under electronic signature law. A document signed this way is treated as a formally signed instrument, accompanied by a trusted timestamp and a verification record that strengthen it as evidence.

Your contract deserves The strongest signature.

Got an accredited token? Plug it in, enter your PIN, and sign your contract with an embedded digital signature and a trusted timestamp — all from inside Wthaiq.

Sign with the token now