Signing
Install and use the
Fatoora USB token signer
Install the local signer on the PC that holds your Egypt Trust token, paste the tenant signer API key, sign READY_TO_SIGN documents from Fatoora, and keep the PIN on the PC only.
USB token signer EgyptEgypt Trust ePass2003
Fatoora local signerتوقيع USB فاتورةlocalhost:7733
ETA requires CAdES signatures with your hardware certificate. The private key never leaves the USB token. Fatoora therefore uses a local signer on the PC that holds the token.
What the signer does
- Pulls documents in status READY_TO_SIGN from your
Fatoora tenant
- Canonicalizes and signs with the token
- Posts the signed payload back so status becomes SIGNED
- You then click Submit ETA in
Fatoora
Install (typical package under tools/eta-signer)
- First time: run Create Desktop Shortcut.bat (desktop shortcut “RHO Invoice Signer” /
Fatoora signer branding may vary by package)
- Daily: open that shortcut or Start … Signer.bat and leave the console open
- Browser UI: `http://localhost:7733`
- Settings page: `http://localhost:7733/settings`
- Stop: close the window or the Stop bat file
- Prerequisites: Node.js LTS; .NET build of `CadesSigner` if you build from source
Configure a profile
In the signer settings, add a profile with:
- CRM /
Fatoora base URL (your live site origin)
- Signer API key copied from
Fatoora Settings (read-only field)
- Certificate thumbprint / card name (e.g. Egypt Trust / ePass2003)
- Token PIN (stored only on the PC — never in
Fatoora cloud)
Default listen port is 7733.
Protocol used by
Fatoora
The signer authenticates with `Authorization: Bearer {signerApiKey}` and calls:
- `GET /api/e-invoicing/signer/pending` (alias `/api/signer/pending`)
- `POST /api/e-invoicing/signer/signed` (alias `/api/signer/signed`) with `{ results: [{ id, signedPayload, error? }] }`
Sign from the
Fatoora UI
On a document in READY_TO_SIGN, click Sign (local). Fatoora opens `http://localhost:7733/?oneshot=1` so the signer can process pending documents. When signing finishes, refresh the document — status should be SIGNED.
Operations tips
- Install signer only on PCs that physically hold tokens
- Train a backup signer user
- After Rotate key in Settings, update every signer profile or signing stops
- Never paste token PIN into chat, tickets, or
Fatoora fields