Enterprise
PKI API
A modern, high-performance, and flexible REST/SOAP interface with no graphical interface of its own, built to integrate advanced cryptographic services into applications and enterprise architectures.
Certificate management, under your control
PKI API manages the key pairs and digital certificates required for secure digital processes — acting as an integration layer between your applications and PKI infrastructure.
Main benefits
Fast integration
Connects to your existing systems and enterprise architectures through a standardized REST/SOAP interface.
Automated management
Automates certificate and key-pair management without manual intervention.
Deployment flexibility
Deploy in the cloud or on-premise, depending on your infrastructure and security requirements.
Lower operating costs
Reduces the cost of running and maintaining your own PKI infrastructure.
Modular architecture
Certificate management,
under
your control
PKI API manages the key pairs and digital certificates required for secure digital processes — acting as an integration layer between your applications and PKI infrastructure.
Certificate Provider
Generates key pairs, creates CSRs, and obtains the certificate from a certification authority.
- Key generation locally and on devices
- CSR creation and certificate storage
- Integration with certification authorities
Certificate Hub
- Connection to NFQES Enterprise CA
- Support for qualified and non-qualified devices
- Direct integration with QSCD and HSM
Virtual HSM
A virtualized cryptographic material store for secure signing without an HSM of your own.
- Use of certified signing algorithms
- Secure key storage
- Scalable for small and large deployments
A building block
for vašu PKI
PKI API suits small, medium, and large enterprises that need to work with certificates and keys.
Financial
institutions
Companies building their own PKI
Businesses building a custom PKI infrastructure.
Integrators and developers
Teams that need to work directly with keys and certificates.
QES support
Deployments requiring support for qualified electronic signatures.
Business Benefits
What deploying PKI API
brings your business
From fast integration to scalability for organizations of any size.
Fast integration
Automation
Lower costs
Reduces the cost of running and maintaining your own PKI infrastructure.
Scalability
Supports a broad range of devices and scenarios, for small and large organizations alike.
Full support for standards
and cryptographic algorithms
Access and compatibility
Access to functionality through a standardized API.
INCLUDES:
- REST and SOAP interface
- Compatibility with QSCD devices
- Compatibility with certified HSMs
- Connects to any CA
Cryptographic algorithms
Support for a broad range of signing and hashing algorithms.
INCLUDES:
- RSA, EC
- MD2, MD4, MD5
- RIPEMD 128/160/256/320
- SHA-1, SHA-224, SHA-256, SHA-384, SHA-512
System requirements
Supported operating systems, key stores, and databases.
INCLUDES:
- GNU/Linux (Ubuntu, Red Hat), Windows
- Key stores: HSM, PEM, JKS
- MySQL, MariaDB, PostgreSQL, SQLite
QES support
Support for qualified electronic signatures under eIDAS.
Standardized API
Access to functionality via a REST or SOAP interface.
QSCD & HSM devices
Direct integration with QSCD and certified HSM devices.
Enterprise CA connectivity
Integrates with a central PKI infrastructure, e.g. NFQES Enterprise CA.
Flexible deployment
Cloud or on-premise deployment, based on your organization’s needs.
No interface of its own
An integration component built to be embedded directly into your applications.
Technical Specifications
References – selected projects
Trusted by companies
and
a institutions
Solution can be implemented and adapted to a wide range of processes for businesses across industries.
Tatraleasing
Reduced workload, lower hardware requirements, time and cost savings, and high legal certainty.
Medante
Digital signatures for medical records and contracts, implemented within the existing MEDANTE system.
BVS
Digitized communication, online forms and contracts, electronic signing via infrastructure or API.
What exactly does PKI API solve?
Does PKI API have its own graphical interface?
No. It is an integration component with no separate UI, designed to be embedded directly into your applications and enterprise architectures via REST/SOAP.
Can PKI API integrate with our own HSM?
Yes. The solution integrates directly with QSCD and certified HSM devices, and can also use a virtualized store via Virtual HSM.
Which certification authorities are supported?
PKI API integrates with any certification authority, including connection to a central infrastructure such as 4SIGNER Enterprise CA.
Is the solution suitable for smaller companies too?
Yes, it scales for small, medium, and large organizations — from individual integrators to enterprises building their own PKI infrastructure.
Still have questions?
Feel free to ask — we will gladly advise you on selection and deployment.
Deploy PKI API
within your architecture
We will prepare a price quote and a custom integration proposal for your environment — with no obligation.
Related solutions
Other modules
from the Enterprise ecosystem
Enterprise Web Signer
Signing · On-premise
Enterprise Archive
Local archiving of documents with issued certificates, integrable with any DMS.
Archive
Enterprise RemoteHSM
On-site HSM virtualization for Portal, PKI API, and Archive with a secure connection.
Infrastructure