IDStamp verifies your customers' identity documents and captures a signed contract before the order is placed. This guide covers installation, configuration, the checkout flows, storage and retention, the compliance features and the licensing model.

Contents

  1. Requirements & hosting
  2. Install
  3. Choose the verification backend
  4. Write the contract
  5. Where the UI appears
  6. Storage and retention
  7. The compliance pack (Pro)
  8. Reviewing and evidence
  9. Privacy and data model
  10. Licensing and updates
  11. Troubleshooting

1. Requirements & hosting

  • WordPress 6.2+, PHP 8.0+. WooCommerce is optional: without it, the shortcodes still work on any page.
  • Local OCR backend: Node.js 18+ on the server (one-click install from IDStamp → Settings → Environment). No Node? Use the remote or manual backend.
  • Storage: a writable wp-content/uploads/, or an S3-compatible bucket, or your own HTTP endpoint (Pro).
  • nginx hosts: add the deny rule shipped in uploads/idstamp-protected/nginx-deny.conf to your server block, so the protected folder is never served directly.
  • IDStamp is HPOS and cart/checkout blocks compatible.

2. Install

Install IDStamp from Plugins → Add New (WordPress.org) or upload the zip, then activate it and open IDStamp → Settings. Owners of IDStamp Pro install it the same way: it activates on top of the free plugin and asks for the license key.

3. Choose the verification backend

  • Local OCR (ocrideu) — recommended. Reads EU/EEA identity documents (ICAO 9303 MRZ plus QR/barcodes) on your own server. Node.js required: use Environment → Install OCR engine or npm i -g @tuchsoft/ocrideu. Custom command templates cover nvm/pnpm/npx setups.
  • Remote endpoint — POST the file to your own service (raw body or multipart) and map the JSON response fields to IDStamp's: name, lastname, fiscal_code, birthdate, doc_number, valid, side.
  • Manual review — no automation: uploads queue for a human decision. It is also the automatic fallback when OCR fails or a required field is missing.

Related options: Offer manual verification, Allow ordering while pending review, Required fields, Max upload size, and (Pro) the duplicate fiscal-code guard.

4. Write the contract

The contract text supports placeholders resolved at signing time:

{name} {lastname} {fiscal_code} {birthdate} {email} {site_name} {order_number} {date} {ip}

The signer sees the rendered text, ticks the consent checkbox and signs with a mouse or a finger. What gets stored per signature: the rendered contract text, its SHA-256 hash, the signature image, its hash, the UTC timestamp, the IP and the user agent. Pro adds the disclosure acceptance, the OTP record and the signed certificate PDF.

5. Where the UI appears

  • Classic checkout — the upload and signature UI renders inside the checkout and the order cannot be placed until the requirements are met.
  • Block checkout — enforcement is server-side, with a clear message about what is missing. Put the UI on a dedicated page (see below).
  • Shortcodes (any page, WooCommerce optional): [idstamp_documents] [idstamp_contract] [idstamp_status] [idstamp_panel] (the full panel, recommended for a “Verification” page).
  • Per-product requirements (Pro) force verification, signature or both only for the products that need it.

6. Storage and retention

  • Protected folder (default) — uploads/idstamp-protected/, web access denied, files served only through authenticated PHP endpoints.
  • Media library — simplest, but URLs are semi-public.
  • S3-compatible (Pro) — AWS, MinIO, R2; external endpoint (Pro) — PUT/POST to your own storage service.

Retention (Pro): keep forever, delete after N days (daily cron), or delete right after verification, keeping hashes and extracted data only. Run retention purge now forces a pass.

7. The compliance pack (Pro)

  • ESIGN/UETA disclosure shown above the signature; its acceptance is recorded with a hash of the exact text.
  • Certificate PDF for every signature: contract text, SHA-256 hashes, timestamp, IP and verification outcome. Downloadable from the audit log, the order screen and by the customer.
  • Hash-chained audit log: every entry carries the hash of the previous one. Alter a record and the chain breaks.
  • OTP signing: a one-time code (email through the site mail, or SMS with your own provider — Twilio or a generic JSON webhook) proves the signer controls the channel: the evidence that moves you from a simple to an advanced signature under eIDAS.

8. Reviewing and evidence

IDStamp → IDStamp is the review queue: confirm, mark verified, or reject with a note (the customer gets the email). IDStamp → Audit log lists every event, with CSV export (Pro) and the certificate download. The admin order screen shows the verification status, the extracted data and the signed record.

9. Privacy and data model

Documents and signature records live in dedicated tables; the files live in the storage backend you chose. WordPress Export/Erase Personal Data includes IDStamp records. With “delete right after verification” you keep only extracted fields and hashes. Guests are tracked with a session token, not an account, and their records are bound to the order and the billing email. The plugin provides the tools; the legal basis and the privacy policy remain yours.

10. Licensing and updates

The Lite version is free. Pro is one tier: 99 €/year, everything included (updates, support, all Pro features). The license key gates updates and support, not functionality: the plugin keeps working without it. Anything outside the tier — volume licensing, qualified signatures via accredited providers, custom integrations — contact us.

11. Troubleshooting

  • “OCR engine is not installed” → Environment tab → Install OCR engine, or switch backend.
  • PDF documents → local OCR reads images; send PDFs to the remote backend or manual review.
  • Checkout still blocked after signing → the gate reads the saved state: check [idstamp_status]. Guests must use the same browser session.
  • nginx serves files directly → apply the shipped deny rule (see Requirements).
  • License says “no key entered” → paste the key from your purchase email in Settings → Compliance & OTP.

← Back to IDStamp