Guias de Desenvolvimento

Signing Sessions

Guias dos SDKs

Biometria + OTP — BIOMETRIC_PLUS_OTP

Combina verificação biométrica facial com confirmação por código OTP. Máxima segurança.


O que é

O perfil BIOMETRIC_PLUS_OTP combina verificação facial com confirmação OTP. O signatário completa o liveness biométrico, tem o rosto comparado, e depois recebe e insere um código OTP. Ideal para fluxos que exigem dupla verificação (biometria + posse de email/telefone).

Liveness (câmera) ──> Comparação facial ──> OTP enviado ──> Código digitado ──> COMPLETED

Requisitos

CampoObrigatórioNotas
nameSimNome completo
cpfSimPara comparação biométrica
emailSim**Para OTP por email
phoneAlternativoPara OTP via SMS, com otpChannel: 'sms'
userExternalIdSimID no seu sistema

Pré-requisito: Enrollment biométrico prévio.


Criar a sessão

const pdfBase64 = readFileSync('contrato.pdf').toString('base64');

const session = await client.signingSessions.create({
  purpose: 'DOCUMENT_SIGNATURE',
  policy: { profile: 'BIOMETRIC_PLUS_OTP' },
  signer: {
    name: 'Fernanda Costa',
    cpf: '12345678901',
    email: 'fernanda@example.com',
    userExternalId: 'user-010',
  },
  document: { content: pdfBase64, filename: 'contrato.pdf' },
  returnUrl: 'https://app.example.com/done',
  locale: 'pt-BR',
  expiresInMinutes: 60,
});

console.log('Client Secret:', session.clientSecret);

const result = await client.signingSessions.waitForCompletion(session.sessionId);
console.log('Status:', result.status);
console.log('Evidence ID:', result.evidenceId);
session = client.signing_sessions.create(CreateSigningSessionRequest(
    purpose='DOCUMENT_SIGNATURE',
    policy=Policy(profile='BIOMETRIC_PLUS_OTP'),
    signer=Signer(
        name='Fernanda Costa', cpf='12345678901',
        email='fernanda@example.com', user_external_id='user-010',
    ),
    document=InlineDocument(content=pdf_base64, filename='contrato.pdf'),
    return_url='https://app.example.com/done',
    locale='pt-BR',
    expires_in_minutes=60,
))

print('Client Secret:', session.client_secret)

result = client.signing_sessions.wait_for_completion(session.session_id)
print('Status:', result.status)
print('Evidence ID:', result.evidence_id)
session, err := client.SigningSessions.Create(ctx, &signdocs.CreateSigningSessionRequest{
    Purpose: signdocs.PurposeDocumentSignature,
    Policy:  signdocs.Policy{Profile: "BIOMETRIC_PLUS_OTP"},
    Signer: signdocs.Signer{
        Name: "Fernanda Costa", CPF: "12345678901",
        Email: "fernanda@example.com", UserExternalID: "user-010",
    },
    Document:         &signdocs.DocumentInline{Content: pdfBase64, Filename: "contrato.pdf"},
    ReturnURL:        "https://app.example.com/done",
    Locale:           "pt-BR",
    ExpiresInMinutes: 60,
})
if err != nil { log.Fatal(err) }

fmt.Println("Client Secret:", session.ClientSecret)

result, err := client.SigningSessions.WaitForCompletion(ctx, session.SessionID)
if err != nil { log.Fatal(err) }
fmt.Println("Status:", result.Status)
fmt.Println("Evidence ID:", result.EvidenceID)
String pdfBase64 = Base64.getEncoder().encodeToString(Files.readAllBytes(Path.of("contrato.pdf")));

CreateSigningSessionRequest request = new CreateSigningSessionRequest();
request.purpose = "DOCUMENT_SIGNATURE";
request.policy = new Policy("BIOMETRIC_PLUS_OTP");
request.signer = new Signer("Fernanda Costa", "user-010");
request.signer.cpf = "12345678901";
request.signer.email = "fernanda@example.com";
request.document = new CreateSigningSessionRequest.InlineDocument(pdfBase64, "contrato.pdf");
request.returnUrl = "https://app.example.com/done";
request.locale = "pt-BR";
request.expiresInMinutes = 60;

SigningSession session = client.signingSessions().create(request);
System.out.println("Client Secret: " + session.clientSecret);

SigningSessionStatusResponse result = client.signingSessions().waitForCompletion(session.sessionId);
System.out.println("Status: " + result.status);
System.out.println("Evidence ID: " + result.evidenceId);
$pdfBase64 = base64_encode(file_get_contents('contrato.pdf'));

$session = $client->signingSessions->create(new CreateSigningSessionRequest(
    purpose: 'DOCUMENT_SIGNATURE',
    policy: new Policy(profile: 'BIOMETRIC_PLUS_OTP'),
    signer: new Signer(
        name: 'Fernanda Costa', cpf: '12345678901',
        email: 'fernanda@example.com', userExternalId: 'user-010',
    ),
    document: ['content' => $pdfBase64, 'filename' => 'contrato.pdf'],
    returnUrl: 'https://app.example.com/done',
    locale: 'pt-BR',
    expiresInMinutes: 60,
));

echo "Client Secret: " . $session->clientSecret . "\n";

$result = $client->signingSessions->waitForCompletion($session->sessionId);
echo "Status: " . $result->status . "\n";
echo "Evidence ID: " . $result->evidenceId . "\n";
var pdfBase64 = Convert.ToBase64String(await File.ReadAllBytesAsync("contrato.pdf"));

var session = await client.SigningSessions.CreateAsync(new CreateSigningSessionRequest
{
    Purpose = "DOCUMENT_SIGNATURE",
    Policy = new Policy { Profile = "BIOMETRIC_PLUS_OTP" },
    Signer = new Signer
    {
        Name = "Fernanda Costa", Cpf = "12345678901",
        Email = "fernanda@example.com", UserExternalId = "user-010",
    },
    Document = new InlineDocument { Content = pdfBase64, Filename = "contrato.pdf" },
    ReturnUrl = "https://app.example.com/done",
    Locale = "pt-BR",
    ExpiresInMinutes = 60,
});

Console.WriteLine($"Client Secret: {session.ClientSecret}");

var result = await client.SigningSessions.WaitForCompletionAsync(session.SessionId);
Console.WriteLine($"Status: {result.Status}");
Console.WriteLine($"Evidence ID: {result.EvidenceId}");

Experiência do signatário

A página hospedada executa automaticamente todas as 4 etapas: câmera para liveness → comparação facial → OTP enviado → campo para digitar o código.


← Biometria  |  Próximo: Certificado Digital →

Voltar para Visão Geral