Skip to main content
NEW Didit KYC Identity Verification is live, verify signers with government ID & biometrics for eIDAS Advanced signatures Learn more

Compliance

RFC 3161 Timestamping

Prove exactly when a document was signed

Cryptographic timestamps from independent Time Stamp Authorities — tamper-proof, court-admissible and applied automatically on every signature.

RFC 3161 · certified TSA · embedded token · long-term validity

Independent time proof, not just a server clock

RFC 3161 timestamps come from a trusted third party with its own certificate — stronger evidence than a system clock anyone can change.

Certified TSA tokens

Accredited Time Stamp Authorities issue cryptographic proof of the exact signing moment.

RFC 3161 standard

Implements the IETF RFC 3161 protocol used worldwide for trusted timestamping.

Embedded in the PDF

The timestamp token lives inside the digital signature for self-contained verification.

How trusted timestamping works

Every signed document can receive an independent, cryptographically signed time token automatically.

  1. 1

    Generate document hash

    When signing completes, WPsigner creates a SHA-256 hash of the signed document.

  2. 2

    Request a TSA token

    The hash is sent to your configured Time Stamp Authority via RFC 3161. The TSA signs a timestamp token with its certificate.

  3. 3

    Embed the token

    The signed timestamp is embedded in the PDF digital signature for anyone to verify.

  4. 4

    Retain long-term proof

    The timestamp remains valid even after your signing certificate expires.

Choose your Time Stamp Authority

WPsigner includes a default TSA configuration. Prefer DigiCert, GlobalSign, Sectigo, FreeTSA or another RFC 3161 endpoint? Point settings at any compliant TSA — no add-on fee.

  • Tamper-proof time proof from an independent TSA
  • Legal admissibility for disputes and IP priority dates
  • Automatic application when documents are signed
  • Multiple RFC 3161-compliant TSA endpoints supported
  • Included in every WPsigner plan
Explore compliance →

Timestamping capabilities

  • Certified TSA timestamps
  • RFC 3161 compliance
  • Tamper-proof time proof
  • Token embedded in the PDF
  • Court-admissible evidence
  • Long-term validity after cert expiry
  • Multiple TSA providers
  • Automatic application on sign

When trusted time matters

Legal disputes

Prove the signature occurred at a specific, independently attested time.

IP and priority dates

Support claims where existence-at-time evidence is critical.

Regulatory audits

Provide verifiable timestamps that do not depend on your server clock.

Long retention files

Keep time proof valid after signing certificates expire.

Frequently asked questions

What is RFC 3161 timestamping?

RFC 3161 is an internet standard for trusted timestamping. A Time Stamp Authority (TSA) — an independent third party — issues a cryptographically signed token proving that a specific data hash existed at a specific time. This is stronger than a server clock timestamp because it comes from a trusted, independent source.

Why is trusted timestamping important?

Server timestamps can be manipulated by changing the system clock. RFC 3161 timestamps cannot — they come from an independent TSA with its own certificate. That matters in legal disputes, intellectual property claims and regulatory compliance where audit trails require verifiable time.

Does this cost extra?

No. RFC 3161 timestamping is included in every WPsigner plan with a default TSA configuration. You can configure any RFC 3161-compliant endpoint (DigiCert, GlobalSign, etc.) in settings.

How is this different from a regular timestamp?

A regular timestamp records time from your server clock, which admins can change. An RFC 3161 timestamp comes from a trusted third-party TSA with its own cryptographic certificate — independent, court-admissible proof of signing time.

Which TSA providers can I use?

Any RFC 3161-compliant endpoint — including FreeTSA, DigiCert, GlobalSign, Sectigo and others you configure in WPsigner settings.

Do timestamps survive certificate expiry?

Yes. RFC 3161 timestamps remain valid indefinitely, even after your signing certificate expires, supporting long-term archival use cases.

Certified timestamps on every document

RFC 3161 timestamping is included in every WPsigner plan. No add-ons required.

Unlimited Usage · Self-Hosted

Stop paying per envelope

Choose an annual or lifetime license with unlimited documents and no per-envelope fees. Keep control of your data and signing workflows.