Skip to main content
Odoo · eIDAS electronic signature

eIDAS Signatures in Odoo with e-Signature.eu: itsme, Evrotrust and Pay-Per-Signature

The e-Signature.eu connector for Odoo sends quotations, invoices, purchase orders or contracts out for eIDAS signature — SES by OTP, AES with Veriff, QES with itsme® or Evrotrust — with no subscription: you buy credits and each signature spends credit. It is published for Odoo 17, 18 and 19. Here is which level you actually need per document, what each method asks of the signer, and what changes in the Odoo flow when you move from SES to QES.

Cuenta de e-Signature.eu configurada dentro de Odoo, con los métodos itsme, Evrotrust, Veriff y OTP y el saldo de créditos

e-Signature.eu is a European eIDAS signature platform: it does not sell annual fees, it sells credit, and each signature spends it. The connector that plugs it into Odoo is built and maintained by us, with a version for each series — 17, 18 and 19 — (module page). This article covers what almost nobody tells you before you buy: which signature level you actually need, what the other party has to do in order to sign, and how the numbers change when you pay per signature instead of per year.

Scope note: we are not explaining eIDAS from scratch here; that is in eIDAS electronic signature in Odoo: SES, AES and QES. This is only about how it lands with e-Signature.eu inside Odoo.

The three eIDAS levels, told by what they change in your process

Regulation (EU) 910/2014 defines three levels and the legal difference is in its own text (Articles 3, 25 and 26). What is not in the regulation is the operational difference: each level asks something different of the signer, and the more you ask, the more people drop off.

LevelWhat the signer has to doReal frictionMethod in the connector
SES — simpleOpen an email and type a one-time code.Almost none. Nothing to install, no ID document to show.OTP (email/SMS)
AES — advancedPhotograph their ID document and pass a liveness check.Minutes, a camera and decent light. Drop-off goes up.Veriff
QES — qualifiedAlready have a qualified digital identity, or enrol in one.High. The cost is not the credit: it is enrolling the counterparty.itsme® or Evrotrust

Those four methods are the connector's entire catalogue, and it is not user-editable: nobody can label as “qualified” a signature that is not.

When do you genuinely need QES?

Most companies asking about qualified signatures want them for documents that do not need one. The useful test is not “how much is the contract worth”, it is “is there someone who will demand it in writing”:

  • Filings with an administration that requires it. In France, e-Signature.eu documents that since January 2023 INPI has required a qualified signature for the company modification and termination formalities filed through the Guichet unique. No debate: either it is QES or the filing bounces.
  • Counterparties whose procurement policy says so. Large accounts, insurers and some banks ask for it by default.
  • Documents you expect someone to challenge. If litigation is a realistic scenario, QES puts the burden of proof on your side.

Everything else — confirmations, acknowledgements of receipt, internal annexes — lives in SES; standard B2B contracts live in AES. And an honest caveat: QES does not replace the deeds the law requires to be executed before a notary. The most expensive mistake is not aiming too low: it is making QES the default and then wondering why people take four days to sign a delivery note.

itsme, Evrotrust, Veriff and OTP: what each one asks of the signer

itsme® is the Belgian digital identity. In Belgium the classic enrolment asks for your eID and a card reader, or a Belgian bank card; outside Belgium a passport, identity card or residence permit is enough, per e-Signature.eu, but coverage depends on the itsme® country list: check it before promising anyone a QES. Evrotrust is a Bulgarian qualified trust service provider (QTSP) on the EU trusted list; also a mobile app, wider country coverage, and the method French INPI has accepted since 2026, per e-Signature.eu.

Veriff is not a QTSP: it is identity verification, ID document plus selfie, and out comes an AES. OTP is a code by email or SMS, and out comes a SES. There is a detail here that cost us a whole review round with e-Signature.eu: the platform silently discards any phone number that is not “+” followed by bare digits. A human types “+32 483 22 90 07”, the platform stores it empty and SMS OTP silently falls back to email. The connector normalises the number before sending it; the seventh review round turned it up, on 14 July 2026.

What changes in the Odoo flow depending on the level

The connector adds a Send for Signature button to quotations, invoices, purchase orders, employment contracts (hr.version on Odoo 19, hr.contract on 18 and 17), applicants, contacts and any PDF attachment. It does not depend on the Sign app, which is not even in the manifest, and that matters, because Odoo's own documentation says Sign generates simple electronic signatures, the first of the three levels: for AES or QES you have to go out to a trust service provider.

The wizard makes you choose the minimum legal level and the methods separately, and it will not let you combine them badly: with the minimum on “Qualified”, a send with OTP or Veriff is refused, and the same validation applies to the account's default methods. It looks trivial and it prevents the most common failure: a process labelled QES and served by an SMS code.

Solicitud de firma completada dentro de Odoo: nivel legal mínimo, método de firma, barra de estados en Signed y botones de descarga del documento firmado, verificación eIDAS y audit trail

With SES the send goes straight out: the signer types the code and the signed PDF comes back on its own. With QES there is an identification step you have to design: the signer needs the app installed and their identity already verified, and first time round that enrolment can take longer than the contract. The practical consequence is boring and it works: warn the counterparty before you send.

There are two modes: in email mode e-Signature.eu sends the invitation; in Odoo workflow mode the quotation goes out through the native circuit and the customer signs from their portal, where “Sign” replaces “Accept & Pay”. The second hid a bug we fixed: the session at e-Signature.eu must only be created once the email is genuinely sent; before, discarding the draft left the request marked as sent.

Subscription versus pay-per-signature: the napkin maths

A subscription is paid whether you sign or not, and it almost always carries an envelope quota. e-Signature.eu's model is the opposite: you buy credit packs, the price per credit falls with volume and each signature consumes credit according to its level. In their catalogue — the same one the connector mirrors — a QES with itsme® or Evrotrust consumes one credit per signer, an AES with Veriff 0.7 and an OTP SES 0.4, whether one or five documents travel in the request.

The maths is one line: divide the annual fee by the price of a credit and you get the number of signatures above which a subscription pays off. Do it with the fee you are quoted and the rate e-Signature.eu publishes on its site: the result is a number, not an opinion. And there is a second-order effect: on a subscription you pay the same whether you sign SES or QES, so nothing pushes you to right-size the level; with credits, choosing AES instead of QES costs 30 % less on that signature. Choosing the level goes from abstract legal debate to economic decision, on every send.

The balance is visible inside Odoo with its update timestamp: the API has no balance endpoint — it returns the figure inside each request response — so the connector captures it from the most recent one and refreshes it with a daily cron, instead of faking a live figure that does not exist.

What gets stored and where the evidence lives

A signature with no retrievable evidence is worthless the day you need it. When the request completes, three things are left in Odoo:

  • The signed PDF, attached to the source document and named after it (S00026-signed.pdf), not after the request's internal id. It sounds cosmetic until someone looks for their contract and cannot find it.
  • e-Signature.eu's official audit trail, stored as <document>-audit-trail.pdf. Careful: the platform generates it shortly after the request completes, so it may not be there if you ask the second the last signature lands; the connector says so instead of failing silently.
  • An evidence report from the module itself, with the eIDAS level actually achieved, the methods, the signing time, the SHA-256 of the signed document and, per signer, their verified identity, the method used and when they signed.

And one button you will not see in many connectors: Verify eIDAS signature opens the European Commission's DSS validation tool so you can validate the signed PDF against something that is neither us nor e-Signature.eu. Underneath, the state syncs through a webhook signed with HMAC-SHA256, an idempotency log and an hourly rescue cron; and deleting a finished request also deletes it from the e-Signature.eu history.

Ten review rounds with e-Signature.eu itself

This connector was not written against the documentation and shipped: it was put in front of the e-Signature.eu team, broken and rewritten. The repository holds one test file per round, from test_round2.py to test_round10.py. Two examples, on top of the round-7 phone number:

  • Round 9. A request cancelled from the e-Signature.eu dashboard stayed “Sent” inside Odoo forever. And the obvious fix — re-fetching it — did not work either: cancelling from the dashboard deletes it at e-Signature.eu and the lookup answers 401.
  • Round 10. Stopping a half-signed request left the signer pending forever: the platform rejects the operation while nobody has signed yet, and the code swallowed the error and marked it stopped anyway.

There is even a feature the connector refuses to fake: manual signature placement is documented, but the production validator rejects it — 22 variants probed against the live API on 10 July 2026, all rejected. Omitting the field would make the send succeed with the signature placed automatically, silently ignoring your coordinates; we prefer it to fail with an explanation. Today it is 121 green tests on Odoo 17, 18 and 19 from the same source, and the suite has also been run on a real Odoo.sh build.

Useful links

e-Signature.eu ConnectorScreenshots, versions and documents coveredeIDAS electronic signature in OdooWhat SES, AES and QES areAn Odoo connector for your softwareNative integrations with technology partnerse-Signature.eu's own Odoo page ↗The module as told by e-Signature.eu, with pricing

Frequently asked questions

Can I sign with QES from Odoo without Odoo Enterprise?

Yes. The connector does not depend on the Sign app: its dependencies are base, mail, portal, sales, accounting, purchase, HR and recruitment. It is published for Odoo 17, 18 and 19 and runs on Community, Enterprise and Odoo.sh.

What is the difference between itsme® and Evrotrust if both give QES?

The legal level is identical; who can use them is not. itsme® is the Belgian digital identity, convenient for Belgians and the Dutch; Evrotrust is a Bulgarian QTSP on the EU trusted list, covering more countries. Since the connector lets you offer several methods in the same request, the practical answer is to offer both and let the signer pick the one they already have.

How do I check that the signature really is qualified?

Without taking anyone's word for it: download the signed PDF and upload it to the European Commission's DSS validation tool, which the module opens from a button. There you will see the certificate, the trust service provider and whether the signature is qualified. Odoo also records the level actually achieved, not the one you asked for.

Not sure which signature level you need?

We will tell you, with no strings attached, which eIDAS level each document you sign actually calls for, and what it would take to wire it into your Odoo. Email comercial@flexigobe.com or call +34 616 809 504.

Talk to an engineer