Skip to content
KanchanFlow
IntegrationLiveLast tested 2026-08-27Signature

Aadhaar eSign for Manufacturing

Get a legally valid electronic signature on a quote acceptance or supply agreement in minutes, using India's OTP-based eSign service.

In short

KanchanFlow, the RFQ-to-Order CRM, connects to a licensed eSign Service Provider so a buyer can sign a quote acceptance or supply agreement with an Aadhaar OTP and a legally valid digital signature is embedded in the PDF. The signature receipt and full audit trail attach to the quote revision that was signed, not to a loose file.

Diagram of the Aadhaar eSign integration: fields KanchanFlow writes to Aadhaar eSign on the left, fields it reads back on the right.

Who this is for. This connector is for USA manufacturers with India operations, India-based contract customers, or manufacturers exporting to India. Only signatories with an Aadhaar number and a mobile number registered against it can use it, so it complements rather than replaces your normal signature process.

Chasing a signed acceptance is the slowest part of winning a job. A quote is agreed on a call, and then a scanned page with a rubber stamp arrives four days later, sometimes against a revision that is no longer current. Half the disputes we hear about start with somebody signing the wrong revision.

Aadhaar eSign fixes both halves. The buyer receives the exact quote revision as a PDF, authenticates with an OTP against their Aadhaar number, and the signature is embedded in the document by a licensed ESP. The signed PDF, the ESP receipt, the timestamp and the IP address bind to that revision permanently.

Status
Live in production
Category
Signature
Plan availability
All tiers — India regulatory and signature features are never gated by plan
Sync cadence
Real time via webhook during the signing ceremony; status reconciliation every 15 minutes

Field by field

What syncs, in both directions

These are the actual fields that move. Anything not on these two tables does not sync, and we would rather write that down than let you assume it does.

KanchanFlow → Aadhaar eSign

What we write out when a record moves forward.

FieldWhat we send
Document hash for signingWe send the SHA-256 hash of the exact quote revision PDF to the ESP. The document itself does not leave your workspace during the signing ceremony.
Signatory detailsName and mobile number of the named buyer on the quote, used to address the OTP challenge. We never transmit or store the Aadhaar number itself.
Signature placement coordinatesThe page, x and y coordinates and the box size where the signature block is to be embedded, taken from the document template.
Document type and retention flagQuote acceptance, supply agreement, NDA or amendment, which drives both the retention policy and which template is used.
Reminder scheduleThe reminder cadence for an unsigned request, sent by email and, where enabled, by WhatsApp through the WABA connector.

Aadhaar eSign → KanchanFlow

What comes back onto the customer, quote or order record.

FieldWhat we read
Signed PDF with embedded signatureThe returned PDF carries the embedded digital signature and is stored against the quote revision as an immutable attachment.
ESP signature receiptThe provider's own receipt, including certificate serial and the signing timestamp, stored alongside the document.
Signer audit trailTimestamp, IP address, device user agent and OTP verification result for each attempt, successful or not.
Status transitionsSent, viewed, OTP requested, signed, declined or expired, each written to the quote timeline as it happens.

Sync cadence. Real time via webhook during the signing ceremony; status reconciliation every 15 minutes. Every record also carries a Sync now control, and the last successful sync time is shown on the record so nobody works from a number of unknown age.

Figures

What this looks like in the product

We do not ship stock imagery or mocked-up screens. These three figures describe the exact shots a designer must capture from a live workspace, each carrying a visible date stamp and recaptured at every quarterly re-test.

Figure 1 · to be captured
The Send for eSign dialog on a quote, showing the exact revision number being sent and the named signatory with their mobile number partially masked.

Capture date required. Capture from a live workspace with the mobile number masked in the UI itself, not blurred afterwards. Date stamp required.

Figure 2 · to be captured
The ESP's own OTP consent screen as the signer sees it on a phone, showing the document hash and the consent text.

Capture date required. Capture the genuine provider screen on a real handset in sandbox mode. Date stamp required.

Figure 3 · to be captured
The completed quote timeline showing sent, viewed, signed events with timestamps, and the signed PDF attached to Rev 2.

Capture date required. Capture a genuinely multi-revision quote so the revision binding is visible. Date stamp required; recapture each quarter.

11 steps

Setting it up

Written for the person who will actually do it, in the order they will do it. Nothing here assumes you have done this before.

  1. 1Confirm your signing use case is one eSign supports. Aadhaar eSign is valid for commercial contracts and acceptances; it is not valid for documents excluded under the first schedule of the IT Act, such as certain negotiable instruments and powers of attorney.
  2. 2Contract with a licensed eSign Service Provider. KanchanFlow supports ESPs that expose the standard eSign 2.1 API; your provider must confirm they do.
  3. 3Obtain your ASP credentials and the signing certificate from the provider, plus their sandbox endpoint.
  4. 4In KanchanFlow, open Settings, Integrations, Aadhaar eSign, enter the credentials and upload the provider certificate.
  5. 5Set the callback URL shown in the connector inside your ESP dashboard so signature completion webhooks reach your workspace.
  6. 6Configure the signature block position on each document template you intend to have signed. A signature that lands over a price table is a support ticket waiting to happen.
  7. 7Set the document expiry window. Seven days is the default; anything past thirty invites signing against a stale revision.
  8. 8Decide which roles can send a document for signature. This is a legal act and should not be available to every user by default.
  9. 9Enable WhatsApp reminders only if the WABA connector is configured and the signatory has opted in, otherwise reminders go by email alone.
  10. 10Run a sandbox ceremony end to end with a colleague, including a deliberate OTP failure, so you have seen what a decline looks like.
  11. 11Switch to production and sign one real low-value acceptance before using it on a contract that matters.

Honest ceilings

What this integration cannot do

Every connector has limits. You will find these in week three whether or not we write them down, so we write them down.

  • The signatory must hold an Aadhaar number with a currently registered mobile number. Anyone outside India, or without that mobile linkage, cannot use this method at all, which rules out most USA-based buyers.
  • OTP delivery depends on the UIDAI service and Indian mobile networks. Neither we nor the ESP can guarantee delivery time, and during outages there is no fallback except waiting.
  • Signatures bind to a specific quote revision. If the quote is revised after sending, the outstanding request is voided rather than transferred, which is deliberate and cannot be turned off.
  • We do not offer a document-signing workflow with multiple sequential signatories, counter-signature routing or in-person witness capture. One document, one signatory, one ceremony.
  • Aadhaar eSign is not accepted for every document class under Indian law, and it carries no validity outside India. Cross-border contracts usually need a different instrument, and we will tell you so rather than let you assume otherwise.
  • Certificates issued through this route are short-validity signing certificates. The signature remains verifiable, but the certificate is not reusable for other systems the way an organisational DSC token is.

From the quarterly re-test

Errors you will actually hit

Each of these was reproduced deliberately during testing. The wording is the error as the system reports it, not a paraphrase.

ErrorLikely causeFix
Signer reports no OTP receivedThe mobile number on the quote is not the number registered against that Aadhaar, or UIDAI's OTP service is congested.Confirm the registered mobile with the signer directly, correct it on the quote, and resend. Do not send to a colleague's phone; the number must be the signer's own registered number.
Signature request shows Voided after a revisionThe quote was revised while a signature request was outstanding, so we voided the request rather than let a signature bind to superseded numbers.Send a fresh request against the new revision. Tell the signer why, because they may have the old PDF open.
Webhook never arrives and status stays at OTP requestedThe callback URL in the ESP dashboard is wrong, or an outbound firewall is blocking the provider.Re-copy the callback URL from the connector page. Our 15-minute reconciliation poll will eventually correct the status, but webhooks should be fixed rather than relied on failing.
Signed PDF fails signature validation in a third-party readerThe verifying application does not trust the Indian CCA root chain by default.Install the CCA India root certificates in the reader's trust store. The signature is valid; the reader simply does not know the issuer.
Provider returns Consent text mismatchThe consent wording configured in the connector differs from the wording registered with the ESP.Copy the exact consent text from your ESP contract into the connector. This text is legally prescribed and cannot be reworded for tone.

Questions people ask about the Aadhaar eSign integration

Yes, under the Information Technology Act it carries the status of a valid electronic signature for most commercial documents, with specific exclusions. Your legal counsel should confirm it fits your document class before you rely on it.

Keeping this page true

This connector was last tested end to end on 2026-08-27 against a live sandbox: fresh authorisation, an outbound write, an inbound read checked field by field, and the failure paths above triggered deliberately. It is re-tested every quarter and the date on this page changes when it is. Read how we test integrations, or see what is shipping today.

See a live quote draft built from a real RFQ

Fourteen days, no credit card, sample data pre-loaded. If it does not fit your shop, we will tell you in the first call.

  • Delaware LLC
  • SOC 2 Type II
  • USA Data Centers (AWS)