An SME that invoices
Time-stamping 15,000 documents a month costs about €10,000 excl. VAT a year at a qualified provider's public prices. With OTSPI, the baseline service is €0.
White paper — public consultation v0.9
As Let's Encrypt did for Web encryption, OTSPI wants to make eIDAS qualified proof available to everyone through APIs: time-stamping, certificates, signatures. Free for the baseline service, open, with a pilot already online.
A working RFC 3161 pilot already runs. Get a time-stamp token in 30 seconds, with no account or API key (test environment, not qualified).
Key figures
Digital identity, e-invoicing and Web certificates are becoming mandatory or unavoidable within less than three years. Yet the proof that makes them legally enforceable is still billed per transaction.
until each of the 27 Member States must provide a European Digital Identity Wallet.
One year later, banks, energy, transport and telecom operators will have to accept it.
Regulation (EU) 2024/1183, Art. 5a and 5feconomic actors in France affected by mandatory e-invoicing, according to the Ministry of the Economy (broadest scope).
Receiving e-invoices has been mandatory since 1 September 2026; SMEs and micro-businesses must issue them from 1 September 2027.
economie.gouv.frto time-stamp 15,000 documents a month with a qualified provider, at public list prices.
An act with a near-zero marginal cost, billed token by token.
White paper, § 2.1for the OTSPI baseline service, identical for everyone and with no prior contract.
Only enhanced commitments (volumes, availability, support) involve a contribution.
White paper, § 5.4maximum validity of a TLS certificate in 2029, down from 398 days in 2025.
Nearly eight renewals per year and per site: without automation, nobody will keep up.
CA/Browser Forum, ballot SC-081v3of websites rely on a single certificate authority, established outside the Union.
An exemplary commons, but a single point of dependency for the European Internet.
W3Techs, September 2026Who is it for?
What an open qualified provider changes for those the current model shuts out.
Time-stamping 15,000 documents a month costs about €10,000 excl. VAT a year at a qualified provider's public prices. With OTSPI, the baseline service is €0.
Long-term archiving, public procurement, diplomas: qualified proof becomes accessible with no tender and no subscription to a single provider.
Time-stamp and sign releases through standard APIs (RFC 3161, ACME), with the usual tools and no prior contract.
The EUDI Wallet offers a free qualified signature, but Member States may reserve it for non-professional use. Once you act in a professional capacity, you fall back into the paid model.
The problem
As of 24 September 2026, the EEA trusted lists include 280 qualified providers, 158 of which offer qualified time-stamping. Yet they all share the same model: prior contract, per-unit pricing, proprietary interfaces and markets fragmented by country.
Verifiable attestation of the counterparty, issued from an identity wallet.
EUDI Wallet · business walletsStructured invoice issued and transmitted through an approved platform.
Approved platformsQualified seal and time-stamp on the fly, through an API, with no per-transaction fee.
OTSPI's roleTransfer to archiving with enforceable proof of integrity for the entire retention period.
Archiving systemsThe Web has been here before. In 2015, fewer than 30 % of Web pages were encrypted. Let's Encrypt, run by a non-profit organisation, made certificates free and automated: around 80 % of pages are encrypted today. OTSPI applies this method to eIDAS qualified services, while fully accepting their specific liability, supervision and audit requirements.
Our response
In line with its statutory purpose, OTSPI covers the entire chain of trust and makes it available to everyone on the same terms.
A non-profit association under the French law of 1901, currently being formed. Its draft statutes entrench its purpose, permanently forbid any conversion into a commercial company and place assets and keys beyond any appropriation.
The whole software stack is published under the EUPL 1.2, a European copyleft licence compatible with the AGPL v3: improvements stay free, including when they are operated as a service.
RFC 3161, ETSI EN 319 422, ACME: no proprietary layer. The baseline service is free and identical for everyone; only enhanced commitments involve a contribution.
Executive management, the Trust Policy Committee and Authority Officers are strictly separated, in line with ETSI EN 319 401 and WebTrust requirements.
Services
Each service opens only once the previous one is qualified and stable. Qualified time-stamping comes first: it requires no identity verification and focuses the effort on time accuracy and key protection.
Compliant with ETSI EN 319 421 and 422 and RFC 3161. Authenticated Galileo (OSNMA) and GPS time reference, oscillator holdover, automatic stop in case of drift. Legal presumption of accuracy (Article 41 of the eIDAS Regulation).
Two branches: DV, issued instantly through ACME with no prior account, under a WebTrust root; OV / QWAC, issued through ACME after a one-time onboarding of the organisation, recognised both by browsers and as eIDAS qualified certificates (regulated uses, PSD2).
Qualified seal and signature certificates, then remote signing and sealing through an API: seal, time-stamp and archive every e-invoice without subscribing to a single provider.
Electronic attestations of attributes for the EUDI Wallet and business wallets, and open integration building blocks for local authorities, education and associations. Issuing identity data remains the responsibility of Member States.
Proof of concept
The RFC 3161 time-stamping service already runs in a public test environment, on an engine written in Rust and published as open source. You can try it right now.
Hash a document locally, get a time-stamp token and verify it. No file is uploaded: only the fingerprint leaves your browser.
Open the demoGet a real RFC 3161 token with standard tools, with no account and no API key:
printf 'OTSPI' > demo.txt
openssl ts -query -data demo.txt -sha256 -cert -out demo.tsq
curl -s -H "Content-Type: application/timestamp-query" \
--data-binary @demo.tsq -o demo.tsr https://api.staging.open-eidas.eu/tsa
openssl ts -reply -in demo.tsr -text
Time-stamping engine in Rust, Web demo and deployment configuration, published on GitHub.
Test environment. Tokens issued are not qualified and have no legal value; they demonstrate how the service works and interoperates. The demo still carries the project's former name, Open eIDAS.
Trust architecture
The architecture is designed for audit: every control is documented, every ceremony is witnessed, every token issued is recorded in a public log.
Keys are generated and used exclusively in HSMs certified Common Criteria EAL4+ against the CEN EN 419 221-5 protection profile, hosted in two European sites certified ISO/IEC 27001.
Offline root CA, activated by 3 smart cards out of 5 held by separate officers. Backup cards under seal with separate notarial offices, subject to an exclusive activation clause.
Verifiable Merkle log of issued tokens, open source code and reproducible builds, public Certification Practice Statement following RFC 3647, published audit results.
Statutes
Many open projects have been bought out, turned into commercial offerings or abandoned. For an infrastructure carrying legal proof over decades, and eventually identity data, this risk is ruled out by design. These safeguards will take effect once the statutes are adopted by the founding general meeting.
| Safeguard | Statutory mechanism |
|---|---|
| Entrenched purpose | The public-interest purpose and the continuity clauses are declared permanent and unamendable (Articles 2 and 13). |
| No for-profit conversion | The association may never become a commercial company or any other for-profit entity (Article 13.1). |
| Inalienable assets | Software, trademarks, domain names and equipment may not be transferred to a for-profit entity (Article 13.2). |
| Keys beyond appropriation | Private keys, root certificates and HSM access are held in technical escrow; nobody may claim any private right over them (Article 8 ter). |
| Amendment all but impossible | 75 % quorum, unanimity of voting full members and a veto right for all members; protected articles can only be amended at the order of an authority or an auditor (Articles 11 and 11 bis). |
| Guaranteed continuity | Ring-fenced reserve fund for the termination plan, perpetual transfer of assets to a similar body, and mandatory adoption of the same clauses by any successor (Articles 12 bis, 13 and 13 bis). |
| Universal access | Services available on a universal, neutral and non-discriminatory basis (Article 12 quater). |
Just as with the root key, no one can act alone. The full draft statutes are published (in French) on about.otspi.org.
Roadmap
This roadmap describes the steps OTSPI intends to take. It does not prejudge the opinions of the institutions consulted, nor decisions that fall within their sole competence. No timetable will be set until those opinions have been gathered.
Presenting the white paper to the competent authorities and the research community to gather their opinions; setting up the advisory board; revising the roadmap and publishing the multi-year budget.
Public test environment (RFC 3161 API, transparency log), validation of the time chain, pilot Time-Stamping Policy and Certification Practice Statement, root CA ceremony; first work on identity.
Audit by an accredited body (ETSI EN 319 403-1) and application for qualified status to the supervisory body, which alone is competent to grant it.
WebTrust and QWAC roots, DV and OV / QWAC sub-CAs, WebTrust and ETSI audits, applications for inclusion and qualification; ACME service in testing, then in production once the WebTrust root is included.
Qualified seal and signature certificates, remote signing through an API, electronic attestations of attributes for European wallets.
Manifesto
Ten principles to keep European digital identity and trust services as digital commons. Individuals and organisations can sign it.
Call for partners
We are looking for specific contributions. Pick yours:
The white paper is open for public consultation. Your comments, criticism and partnership proposals are welcome, in English or in French. The expense items are detailed in the white paper.
Spread the word
OTSPI moves forward thanks to those who talk about it. A share, a forward to the right person or a signature of the manifesto counts as much as funding.
Your CIO, your elected representatives, your management, your lab, your invoicing software vendor: a pre-written e-mail is enough to start the conversation.
Send a pre-written e-mailThe manifesto for a free and open digital identity brings together individuals and organisations. Every signature brings in more.
Sign the manifesto