Open and Protect a QCDS Secure Signer Link

No-login personal transaction links, what the signer sees, why the URL should not be forwarded or published, and how QCDS restricts access to that signer transaction.

This guide applies to All plans; external signer and follows the accepted QC Digital Signature 2.0.7 implementation. Where older walkthrough language differs from the current interface or source behavior, use the current QCDS state as the authority.

Before You Begin

  • Treat the signer link as personal transaction access. Do not publish, forward, or paste it into public support posts.
  • If Level 2 Identity Verification is required, confirm the applicable Didit or Shufti provider profile is configured and tests successfully before sending.
  • Test the signer experience in a normal browser/mobile context, not only while logged into Joomla as an administrator.

Step-by-Step Workflow

  1. Open the personal secure URL from the signer invitation instead of trying to navigate to a public QCDS signing page.
  2. Keep the link private; it grants transaction-specific access and should not be forwarded or posted publicly.
  3. If the Request is still active, review the document and assigned fields; if Identity Verification is required, complete that step when prompted.
  4. Use the same link to resume from another device while the signer access remains valid.
  5. After completion, expect QCDS to block additional signing changes while preserving the recorded transaction.

No-login personal transaction links

The secure signer URL is personal transaction access and normally requires no Joomla account. Treat it like a sensitive credential: do not post it publicly or forward it to another person. The same link can be used to resume an active signer session while the Request remains valid, and QCDS records relevant invitation/view/signing evidence around that participant access.

For Open and Protect a QCDS Secure Signer Link, verify this behavior using the actual object involved rather than a generic assumption. A global administrator setting, a sender-workspace preference, a reusable Template, and a sent Request have different ownership and history rules. QCDS is intentionally designed so changes for future work do not silently rewrite the evidence of an already-sent transaction.

The signer sees

The secure signer URL is personal transaction access and normally requires no Joomla account. Treat it like a sensitive credential: do not post it publicly or forward it to another person. The same link can be used to resume an active signer session while the Request remains valid, and QCDS records relevant invitation/view/signing evidence around that participant access.

For Open and Protect a QCDS Secure Signer Link, verify this behavior using the actual object involved rather than a generic assumption. A global administrator setting, a sender-workspace preference, a reusable Template, and a sent Request have different ownership and history rules. QCDS is intentionally designed so changes for future work do not silently rewrite the evidence of an already-sent transaction.

Why the URL should not be forwarded or published

The secure signer URL is personal transaction access and normally requires no Joomla account. Treat it like a sensitive credential: do not post it publicly or forward it to another person. The same link can be used to resume an active signer session while the Request remains valid, and QCDS records relevant invitation/view/signing evidence around that participant access.

And how QCDS restricts access to that signer transaction

The secure signer URL is personal transaction access and normally requires no Joomla account. Treat it like a sensitive credential: do not post it publicly or forward it to another person. The same link can be used to resume an active signer session while the Request remains valid, and QCDS records relevant invitation/view/signing evidence around that participant access.

How This Fits into the QCDS Workflow

Ordinary QCDS signing is a secure-link workflow and does not require the signer to have a Joomla account. Identity Verification is an additional assurance layer for selected transactions; it does not replace the core signing system.

Signer usability and evidence quality are linked. Clear field placement, private secure-link handling, and explicit Identity Verification requirements make it easier for the signer to complete the intended act without ambiguous workarounds.

Verify the Result

  • The owning QCDS screen reflects the intended saved state after reload.
  • A direct follow-up test confirms the change affects future/current workflow behavior without rewriting historical sent Request evidence.

Common Mistakes to Avoid

  • Changing several unrelated settings before recording the original QCDS state.
  • Using old walkthrough behavior when it conflicts with the current 2.0.7 interface/source.

Troubleshooting

  • If the result differs from this guide, capture the current QCDS version, Status message, owning object ID/reference, and exact reproducible action before opening a support request.

Operational Best Practice

Test meaningful changes with controlled data before relying on them in production. Keep QCDS, Joomla mail, Scheduled Tasks, and entitlement health observable; preserve successful Requests and completed evidence; and make the smallest change that solves the actual problem. For handoff or support, record the QCDS version, relevant Request/Template reference, the exact action taken, and the visible result without including secrets.


Community Discussion

Want to compare workflows, share practical tips, or discuss how you use this QCDS feature? Visit the QC Digital Signature Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.