Signer Identity Verification

Electronic Signature Identity Verification

E-signature identity verification is the step that confirms who a signer is, using a one-time passcode, your own identity provider, or a sandbox override, before a legally binding signature is captured and the method is written onto the certificate of completion.

What is identity verification for electronic signatures?

Identity verification is the difference between a document that anyone with a link could sign and one where you can prove who actually signed. It confirms the signer before their signature is captured, then writes how they were confirmed into the permanent record of the document.

TurboDocx builds this directly into TurboSign, so the same platform that generates a document can verify the person signing it. You choose the level of assurance per signer, and nothing about the signer-of-record changes: they keep their real email address on the completed document.

How do you verify a signer's identity before they sign?

TurboDocx offers four ways to establish who a signer is, selectable per recipient. A one-time passcode by email or SMS covers most cases; an assertion from your own identity provider covers signers already logged into your app; and a sandbox override exists for development. The table below compares them.

Email OTP

A single-use code is emailed to the signer, who enters it before the document opens.

SMS OTP

The same single-use code is texted to the signer’s mobile number instead of emailed.

External identity provider

Your app authenticates the signer through your own IdP or SSO and asserts that when it requests the signing URL.

Sandbox override

A sender explicitly requests a link that skips verification, for development and testing only.

Comparison of TurboDocx signer identity verification methods
MethodWhen to use itWhat the signer seesOn the certificate
Email OTPThe default. Works for any signer with an email address and needs no phone number.A "verify your identity" gate, a Send Code button, then a code entry field.Recorded as email one-time passcode.
SMS OTPHigher-assurance signers, or when email is untrusted. Needs a phone number and a connected SMS provider.The same gate, with the code arriving by text message.Recorded as SMS one-time passcode.
External identity providerYou already know who the signer is because they are logged into your product.No passcode step. The document opens straight away inside your app.Recorded as external identity assertion.
Sandbox overrideLocal development and staging. Never production.No passcode step, and the signed record is flagged.Recorded as not identity-verified.

Email OTP vs SMS OTP: what's the difference?

Both deliver a single-use one-time passcode that the signer enters before the document opens. Email OTP sends the code to the signer's email address and works everywhere. SMS OTP texts the code to a mobile number, which is harder to reach from a compromised inbox but needs a phone number on file and a connected SMS provider. Pick email for reach, SMS for a higher bar on out-of-band delivery.

Can I verify signers with my own identity provider?

Yes. When a signer is already authenticated inside your product through your own identity provider or single sign-on, a passcode is redundant. Your backend asserts that verification at the moment it requests the signing URL, and TurboDocx skips its own passcode step while still recording that the signer was verified externally. This is the natural fit for embedded signing inside a logged-in app. Developers can wire it up with the e-signature API and the createSigningUrl guide.

Is a verified signer legally binding under the ESIGN Act and UETA?

A signature captured through TurboDocx is intended to be legally binding under the U.S. ESIGN Act and UETA, the same as any electronic signature we produce. Identity verification does not change that; it strengthens the evidence behind it by recording how the signer was confirmed. For the legal groundwork, see our guides on US e-signature compliance and how electronic signatures work.

Where is the verification method recorded?

On the certificate of completion and the audit trail for the document. Every signer's method, email OTP, SMS OTP, external identity assertion, or sandbox override, is written into the signed record, so a reviewer, auditor, or opposing party can see exactly how each signer's identity was confirmed. Verification you cannot point to later is not worth much; TurboDocx makes it part of the evidence.

How is embedded signing kept secure across domains?

With a deny-by-default allow-list. No website can place the TurboDocx signing page in an iframe until you explicitly add its domain to your allowed embedding domains. The list starts empty, which means the signing page cannot be framed anywhere until you decide otherwise, closing the clickjacking gap that an open embed policy would leave.

The mechanics of requesting a short-lived, single-use signing URL and mounting it are covered on the embedded e-signature page and in the document signing API reference.

What makes TurboDocx signer verification different?

Most e-signature platforms can authenticate a signer in some way. The difference is the combination: three ways to verify selectable per signer, a deny-by-default embedding policy, the verification method recorded on the certificate, the signer's real email kept as signer-of-record, and all of it in the same platform that generated the document. You are not stitching a signing tool to a separate identity tool.

  • Email OTP, SMS OTP, or your own identity provider, chosen per signer
  • Deny-by-default allowed embedding domains
  • Verification method written onto the certificate of completion
  • Signer keeps their real email as signer-of-record
  • Generation and signing in one platform
  • Developer-first API with an open-source core

Building at scale? Compare approaches for developers and legal teams, or send at volume with the bulk signature sending guide.

Frequently Asked Questions

What is identity verification for electronic signatures?

Identity verification for electronic signatures is the step that confirms who a signer is before their signature is captured. TurboDocx verifies each signer with a one-time passcode by email or SMS, an assertion from your own identity provider, or an explicit sandbox override, and records the method that was used on the certificate of completion.

What is the difference between email OTP and SMS OTP for signing?

Both send a single-use one-time passcode that the signer enters before the document opens. Email OTP delivers the code to the signer's email address and works everywhere. SMS OTP texts the code to a mobile number, which is harder to reach from a compromised inbox but requires a phone number on file and a connected SMS provider.

Can I verify signers with my own identity provider instead of a passcode?

Yes. If your application already authenticates the signer through your own identity provider or single sign-on, it can assert that verification when it requests the signing URL, and TurboDocx skips the passcode step. The signer is still recorded with the verification method that was used.

Is a signature from a verified signer legally binding?

A signature captured this way is intended to be legally binding under the U.S. ESIGN Act and UETA, the same as any other TurboDocx signature. Identity verification strengthens the audit trail by recording how the signer was confirmed. See our e-signature compliance guide for the legal details.

Where is the verification method recorded?

The verification method, whether email OTP, SMS OTP, an external identity assertion, or a sandbox override, is written onto the certificate of completion and the audit trail for the document. Anyone reviewing the signed record can see how each signer's identity was confirmed.

How is embedded signing kept secure across domains?

Embedded signing is protected by a deny-by-default allow-list. No website can place the TurboDocx signing page in an iframe until you explicitly add its domain to your allowed embedding domains, which stops other sites from framing the signing experience.

Does the signer still use their real email as signer-of-record?

Yes. Identity verification confirms who the signer is; it does not change who signs. The signer keeps their real email address as the signer-of-record on the completed document and its audit trail.

Verify every signer before they sign

Add identity verification to your signing flow in minutes. Start free, or see how the pieces fit on the pricing page.