Qualified signatures with CMD
Mobile Digital Key is the Portuguese State’s electronic identity service. In AssinaJá it is the only way to produce a QES — a signature legally equivalent to signing by hand across the European Union.
Why CMD is qualified
Section titled “Why CMD is qualified”What makes a signature qualified is not the platform that collects it, but who issues the certificate and where the private key lives.
| Issuer | AMA — Agência para a Modernização Administrativa, a QTSP on the Portuguese EU Trust List |
| Private key | In AMA’s HSM — never on your phone, never in AssinaJá |
| eIDAS level | QES |
| Identity verification | High |
The qualified character comes exclusively from AMA, not from AssinaJá — see the limits, stated plainly.
Before you can sign
Section titled “Before you can sign”Your Chave Móvel Digital must have Digital Signature activated. Having CMD for authentication is not enough — signing is a separate feature, activated at autenticacao.gov.pt.
If AMA does not return the signing certificate, AssinaJá shows:
AMA did not return the signing certificate for this number. This may be a temporary failure: please try again in a moment. If it persists, check that the number is correct and that the digital signature of your Chave Móvel Digital is active at https://www.autenticacao.gov.pt.
Signing with CMD, step by step
Section titled “Signing with CMD, step by step”The CMD wizard has four steps — Identification, Authentication, Processing and Completion. You enter your phone number and your signing PIN (not the authentication one), then the 6-digit security code, within 2 minutes. Your visual signatures must be done first: CMD seals the document. What you see on each screen is in Sign a document.
CMD and CMD with Professional Attributes
Section titled “CMD and CMD with Professional Attributes”This is the distinction that confuses most, and it states simply:
- CMD proves who signed.
- CMD with Professional Attributes (SCAP) proves in what capacity they signed — and that capacity is attested cryptographically by the certifying body itself, not by the signer and not by AssinaJá.
SCAP is the State-run Sistema de Certificação de Atributos Profissionais. A lawyer signing with SCAP is not merely signing as a citizen: the document gains an additional signature from the professional body, confirming that on that date they held that capacity.
Who can request a SCAP signature
Section titled “Who can request a SCAP signature”The SCAP option is only offered to whoever prepares the document when the organisation meets two conditions at once:
- it has an Enterprise subscription in force — the plan’s validity counts with the same 10-day margin as the plan’s quota;
- its entitlement to sign with professional attributes is switched on. It comes on for every organisation; AssinaJá can switch it off for a particular one.
If either is missing, the SCAP type is not offered when sending, and the server refuses a document that asks for it. On the plan cards, the CMD signature with professional attributes line only shows as included in Enterprise.
Whoever signs needs none of this: the decision belongs to the sender, and a guest who receives a SCAP zone signs it.
What changes when signing
Section titled “What changes when signing”| CMD | CMD with Attributes | |
|---|---|---|
| Prior authentication | — | OAuth at autenticacao.gov.pt |
| Choosing attributes | — | At least one, from those available |
| Authorising the capacities to be included | — | Required, at the Confirmation step |
| Phone + PIN | Yes | Yes |
| Security code | Yes | Yes |
| Signatures on the final PDF | Platform seal + your QES | Platform seal + your QES + one per certifying body |
The SCAP wizard has six steps: Attributes, Confirmation, Identification, Authentication, Processing and Completion. The capacities are chosen first, before identification.
In the attributes step each body appears with its attributes as checkboxes. You may pick several, including across different bodies, but at least one is required — “Select at least one attribute”.
Next, the Confirmation step exists only to confirm the choice:
Confirm the capacity you are signing in
These are the capacities recorded in the signature: {n} across {n} entity(ies). They cannot be changed once you sign.
Each entity appears with its NIPC beside the name — which is what tells two similarly named companies apart — and the chosen capacities listed underneath. If something is wrong, Change selection goes back a step.
Below the list is the wizard’s only mandatory checkbox:
I authorise including the selected qualifications in this document’s signature.
Unless it is ticked, the wizard does not move on and shows “Authorise including the qualifications to continue.” The authorisation is given document by document.
The capacity you sign in stays in the document and cannot be corrected afterwards — which is why it has a step of its own.
What becomes visible on the document
Section titled “What becomes visible on the document”A signature with attributes adds three lines to the stamp, beyond name and date:
| Line | Content |
|---|---|
| Certificado com: | SCAP |
| Certificado Por: | The certifying bodies |
| Atributos Certificados: | The chosen attributes, per body |
The same information appears in the Completion Report and is recorded as evidence attached to the signer.
Rules to know
Section titled “Rules to know”| Rule | What it means |
|---|---|
| One qualified zone per signer and document | “You can only have one signature of this kind for each signer/document combination.” In the editor, a second attempt gives “Each signer signs with the Digital Mobile Key only once per document. Remove the existing qualified zone before placing another.” |
| One certificate-based method per signer | CMD, SCAP or LDC (Local Digital Certificate): a signer can hold visual signatures and one of these three, never two |
| The phone belongs to the signer | The number is not asked for when preparing the document: the signer enters it in the Chave Móvel Digital wizard |
| Already-signed documents | A PDF that already carries digital signatures accepts only CMD or CMD with Attributes, so the existing ones stay valid |
| “Sign now” does not support CMD | The owner’s immediate signing does not go through AMA; the document has to be sent for signature |
Both methods consume the same CMD quota from the subscription. When it runs out, the send does not go: the dialog “You need {n} more Chave Móvel Digital signatures to send this document” opens — see Send a document for signature.
If something goes wrong
Section titled “If something goes wrong”The waiting and refusal screens common to any signature are in Sign a document. These are the messages specific to Chave Móvel Digital:
| Message | Meaning |
|---|---|
| The Chave Móvel Digital (AMA) signature failed | “This is a failure of the AMA (Chave Móvel Digital) service, not of the document. You can try again.” |
| The Mobile Digital Key service is not available! Please try again later. | AMA-side outage |
| The security code is incorrect. | Wrong code |
| The security code has expired. | The 2 minutes elapsed |
| The pin you provided is incorrect. | Wrong signing PIN |
| Invalid mobile number. | Phone number format |
| The signing session has expired. Please start the process again. | Start the process again |
| No response from the signing server. Please check your connection and try again. | Check the connection and retry |
| This document currently has no qualified signature available for you. Please contact whoever sent you the document. | None of your CMD/SCAP zones is open right now — AMA is not even contacted, and your code is not spent |
The first two are AMA’s, not AssinaJá’s and not the document’s. Retrying later usually resolves them.
You always see one of these sentences, never an internal code such as
Documents.CMD.AuthErrorMessages.….
Giving up part-way releases the document
Section titled “Giving up part-way releases the document”Closing the wizard releases your row on the document immediately — see Sign a document.
Signature longevity
Section titled “Signature longevity”A CMD signature sits at the PAdES-BASELINE-T profile: fully valid, without the revocation information embedded. What that changes, and why you should keep the signed PDF and the Completion Report together, is in Long-term validation (LTV).
UNVERIFIED: the profile of a CMD with Professional Attributes signature. The
two sources disagree: the signature policy (§3) places CMD and CMDSCAP at
PAdES-BASELINE-T; the only measurement so far, taken in a test environment
(docs/eidas/proof/2026-08-22/dss/summary.md, M5), reports the signer’s
signature without a qualified timestamp — PAdES-BASELINE-B. A
measurement on a production SCAP signature is still missing.