Download the PHP package tcc/laravel-emdha-esign without Composer

On this page you can find all versions of the php package tcc/laravel-emdha-esign. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package laravel-emdha-esign

tcc/laravel-emdha-esign

Laravel package for EMDHA eSign digital signature integration — Saudi Arabia's government-grade digital signing platform.

Requirements

Installation

Publish the configuration file:

This creates config/emdha.php in your application.

SDK Setup

The EMDHA SDK consists of Java JAR files that must be available on your server. They are not included in this package.

1. Create a secure directory

Add to your .gitignore:

2. Copy SDK files

Place these files from your EMDHA SDK distribution into storage/app/emdha/sdk/:

File Description
emdhaCLI.jar Main SDK CLI
eaCore.jar Core library
gson-2.8.5.jar Google Gson dependency
*.lics License file (e.g., UAT-GOV-TCC01_JAVA.lics)
*.pfx PFX certificate (e.g., ClientSDKDEV.pfx)

3. Set directory permissions

Configuration

Add the following to your .env file:

Configuration Reference

Key Default Description
EMDHA_BASE_URL https://esign-dev.emdha.sa/eSign/SignDoc EMDHA API endpoint
EMDHA_SIP_ID '' Your SIP ID (provided by EMDHA CA)
EMDHA_LICENSE_PATH '' Absolute path to your .lics license file
EMDHA_PFX_PATH '' Absolute path to your .pfx certificate
EMDHA_PFX_PASSWORD '' Password for the PFX certificate
EMDHA_PFX_ALIAS '' Alias within the PFX keystore
EMDHA_SDK_JAR_PATH '' Absolute path to emdhaCLI.jar
EMDHA_SDK_CLASSPATH '' Java classpath (colon-separated). If set, uses java -cp instead of java -jar
EMDHA_ENV sandbox Environment: sandbox or production
EMDHA_CONTENT_ESTIMATED 40000 Estimated content size for the SDK
EMDHA_SIGN_ALGORITHM ECC Signing algorithm
EMDHA_HASH_ALGORITHM SHA256 Hash algorithm
EMDHA_RESPONSE_SIG_TYPE PKCS7 Response signature type
EMDHA_KYC_ID_PROVIDER nid KYC ID provider. Use nid (National ID)
EMDHA_SIP_IS_RKA true Whether SIP is RKA
EMDHA_TIMEOUT 120 Timeout in seconds for SDK and API calls
EMDHA_TEMP_PATH storage_path('app/emdha/temp') Directory for SDK temp files

Using Classpath (Multiple JARs)

When EMDHA_SDK_CLASSPATH is set, the package uses java -cp <classpath> com.emdha.cli.Main instead of java -jar. This is needed when eaCore.jar and gson-2.8.5.jar must be on the classpath alongside emdhaCLI.jar:

Quick Start

API Reference

Facade: Emdha

The Emdha facade provides the primary interface to the EMDHA signing service.

signDocument()

Signs a single PDF document.

signMultipleDocuments()

Signs multiple PDF documents in a single transaction (shared signer info).

generateTransactionId()

Generates a unique 26-character transaction ID.

DTO: SignerInfo

Create from array:

DTO: DocOptions

Positions: bottomRight, bottomLeft, bottomMiddle, topRight, topLeft, topMiddle

Pages: all, Last, First, or specific page coordinates like 1,50,50,170,110

DTO: EmdhaSigningResult

The result object returned from all signing operations.

Signature Appearance Types

No Image

Minimal text-only signature appearance.

EMDHA Logo (default)

Displays the EMDHA logo alongside signature text.

Custom Logo

Displays your custom image alongside the signature. Pass the image as a base64-encoded string in appearanceBackgroundImage.

Multi-Document Signing

Sign multiple PDFs in a single EMDHA transaction:

All documents share the same signer info and transaction ID.

Error Handling

Error Codes

Code Description
ESIGN-1001 Invalid Request Format
ESIGN-1003 Invalid Version
ESIGN-1004 Invalid SIP Access Key Hash — check PFX, password, alias, license, SIP ID
ESIGN-1005 Invalid Transaction ID
ESIGN-1006 Invalid SIP ID
ESIGN-1008 Request exceeds maximum number of documents
ESIGN-1009 Invalid Timestamp
ESIGN-1011 Invalid KYC XML data — check signer fields
ESIGN-1012 Duplicate Transaction ID
ESIGN-1014 Invalid character in the name
ESIGN-1999 Unknown error from OSP
ESIGN-2001 Invalid Document Hash
ESIGN-2002 Invalid response signature type
ESIGN-2003 Invalid hash algorithm
ESIGN-2013 Invalid Signature Algorithm
ESIGN-2036 XML Signature validation failed
ESIGN-2038 Insufficient counter at SIP
ESIGN-2047 CN Length Validation Failed
SDK-0001 SDK JAR file not found
SDK-0002 SDK process execution failed
SDK-0003 SDK output file not created
SDK-0004 Invalid JSON response from SDK
SDK-0005 SDK process exception
API-0001 HTTP error from EMDHA API
API-0002 EMDHA API request failed
API-0003 Invalid response: SignResp element not found
API-0004 Failed to parse XML response
VAL-0001 KYC ID (National ID) is required
VAL-0002 English Name is required
SYS-0001 System error during signing

Error Lookup

Handling Errors in Signing

Integration Guide

Example: Blade Application

Migration:

Controller:

Example: Inertia + React Application

The package works the same way — use the Emdha facade in your controllers and return Inertia responses:

Example: API-Only (Sanctum)

Artisan Commands

emdha:check

Verifies your EMDHA SDK setup:

Checks:

How It Works

The EMDHA signing flow consists of three steps:

  1. Generate Request XML — The SDK JAR (GenerateSignDocRequestXML) creates a digitally-signed XML request containing the PDF hash, signer identity, and signing parameters.

  2. Send to EMDHA API — The request XML is sent to the EMDHA gateway via HTTP POST (application/x-www-form-urlencoded). The API verifies the signer's identity against the Saudi KYC system and returns a signed response.

  3. Append Response — The SDK JAR (AppendSignDocResponse) merges the API's digital signature back into the original PDF, producing a fully-signed document.

Important Technical Notes

Troubleshooting

"SDK JAR file not found" (SDK-0001)

"Invalid SIP Access Key Hash" (ESIGN-1004)

"java: command not found"

Classpath Issues

If you see class loading errors, set the classpath to include all JARs:

On Windows, use ; as the separator instead of :.

"Invalid KYC XML data" (ESIGN-1011)

Temp Directory Issues

If the SDK cannot write temp files:

Or set a custom path:

Security Considerations

Changelog

v1.0.0

License

The MIT License (MIT). Please see License File for more information.


All versions of laravel-emdha-esign with dependencies

PHP Build Version
Package Version
Requires php Version ^8.3
illuminate/support Version ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0
illuminate/http Version ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0
symfony/process Version ^6.0 || ^7.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package tcc/laravel-emdha-esign contains the following files

Loading the files please wait ...