Configure Site-Global Didit Identity Verification
Enter Didit API Key, Workflow ID, webhook signing secret, use the generated QCDS webhook URL, save/test the connection, and enable global Identity Verification when ready.
This guide applies to Pro / Max / All Access; authorized administrator and follows the accepted QC Digital Signature 2.0.7 implementation. Where older walkthrough language differs from the current interface or source behavior, use the current QCDS state as the authority.
Before You Begin
- Treat the signer link as personal transaction access. Do not publish, forward, or paste it into public support posts.
- If Level 2 Identity Verification is required, confirm the applicable Didit or Shufti provider profile is configured and tests successfully before sending.
- Test the signer experience in a normal browser/mobile context, not only while logged into Joomla as an administrator.
Step-by-Step Workflow
- Open Administrator > QC Digital Signature > Identity Verification and choose Didit.
- Enter the Didit API Key and Workflow ID.
- Copy the QCDS Didit Webhook URL into the appropriate Didit webhook configuration and enter the matching Webhook Signing Secret in QCDS.
- Save; when credentials are present, QCDS tests the selected provider as part of Save.
- Use Test Connection for an explicit retest, then enable Global Site Identity Verification for new Requests only when the profile is ready.
Enter Didit API Key
Level 2 Identity Verification is additional provider-backed assurance, available with eligible Pro/Max/All Access entitlement. Current QCDS 2.0.7 supports Didit and Shufti. Site-global settings can provide an installation-wide provider profile; sender/account settings can provide an account-level profile where the global configuration is not overriding it. Ordinary secure-link signing remains separate, so a provider outage affects signers who were specifically required to verify rather than making every QCDS transaction provider-dependent.
For Configure Site-Global Didit Identity Verification, verify this behavior using the actual object involved rather than a generic assumption. A global administrator setting, a sender-workspace preference, a reusable Template, and a sent Request have different ownership and history rules. QCDS is intentionally designed so changes for future work do not silently rewrite the evidence of an already-sent transaction.
Workflow ID
Level 2 Identity Verification is additional provider-backed assurance, available with eligible Pro/Max/All Access entitlement. Current QCDS 2.0.7 supports Didit and Shufti. Site-global settings can provide an installation-wide provider profile; sender/account settings can provide an account-level profile where the global configuration is not overriding it. Ordinary secure-link signing remains separate, so a provider outage affects signers who were specifically required to verify rather than making every QCDS transaction provider-dependent.
For Configure Site-Global Didit Identity Verification, verify this behavior using the actual object involved rather than a generic assumption. A global administrator setting, a sender-workspace preference, a reusable Template, and a sent Request have different ownership and history rules. QCDS is intentionally designed so changes for future work do not silently rewrite the evidence of an already-sent transaction.
Webhook signing secret
Level 2 Identity Verification is additional provider-backed assurance, available with eligible Pro/Max/All Access entitlement. Current QCDS 2.0.7 supports Didit and Shufti. Site-global settings can provide an installation-wide provider profile; sender/account settings can provide an account-level profile where the global configuration is not overriding it. Ordinary secure-link signing remains separate, so a provider outage affects signers who were specifically required to verify rather than making every QCDS transaction provider-dependent.
The generated QCDS webhook URL
Level 2 Identity Verification is additional provider-backed assurance, available with eligible Pro/Max/All Access entitlement. Current QCDS 2.0.7 supports Didit and Shufti. Site-global settings can provide an installation-wide provider profile; sender/account settings can provide an account-level profile where the global configuration is not overriding it. Ordinary secure-link signing remains separate, so a provider outage affects signers who were specifically required to verify rather than making every QCDS transaction provider-dependent.
Save/test the connection
Level 2 Identity Verification is additional provider-backed assurance, available with eligible Pro/Max/All Access entitlement. Current QCDS 2.0.7 supports Didit and Shufti. Site-global settings can provide an installation-wide provider profile; sender/account settings can provide an account-level profile where the global configuration is not overriding it. Ordinary secure-link signing remains separate, so a provider outage affects signers who were specifically required to verify rather than making every QCDS transaction provider-dependent.
How This Fits into the QCDS Workflow
Ordinary QCDS signing is a secure-link workflow and does not require the signer to have a Joomla account. Identity Verification is an additional assurance layer for selected transactions; it does not replace the core signing system.
Signer usability and evidence quality are linked. Clear field placement, private secure-link handling, and explicit Identity Verification requirements make it easier for the signer to complete the intended act without ambiguous workarounds.
Verify the Result
- Provider Test Connection succeeds and a representative Level 2 test follows the expected provider flow.
- A direct follow-up test confirms the change affects future/current workflow behavior without rewriting historical sent Request evidence.
Common Mistakes to Avoid
- Treating provider-backed Identity Verification as required for every ordinary secure-link signing workflow.
- Posting provider credentials, webhook secrets, or identity evidence in public diagnostics.
Troubleshooting
- If Level 2 verification fails, use the provider Test Connection and inspect provider/profile/callback configuration; ordinary Level 1 signing and historical evidence should not be reset.
Operational Best Practice
Test meaningful changes with controlled data before relying on them in production. Keep QCDS, Joomla mail, Scheduled Tasks, and entitlement health observable; preserve successful Requests and completed evidence; and make the smallest change that solves the actual problem. For handoff or support, record the QCDS version, relevant Request/Template reference, the exact action taken, and the visible result without including secrets.
Community Discussion
Want to compare workflows, share practical tips, or discuss how you use this QCDS feature? Visit the QC Digital Signature Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.