# xades-open > Opens electronically signed files in the browser: XAdES (.xades and signed .xml, from Poland), CAdES (.sig from Poland, .csig from Spain's AutoFirma, .p7s and .p7m) and ASiC containers (.asice and .bdoc from Estonia, .edoc from Latvia, and ASiC-S) holding either. It shows the signed documents, who signed them and when, and checks each signature's integrity. The file is read in the browser tab and never uploaded. Viewing, downloading and checking are free with no account. A stamped PDF costs €2.99 for one document or €14.99 for a year, paid once by card on Stripe Checkout. Run by agentwares. It does not check the certificate's issuer against the EU Trusted List or whether the certificate was revoked, so it never says a signature is qualified or legally valid. The buyer is the person holding the signed file. A person completes the card page; nothing here can be bought without one. ## Prices (EUR, one payment each) - xades-open stamped PDF (sku "export"): €2.99 once, no renewal. One signed document as a stamped PDF with a signature-report page. Covers one signed document: the one whose commitment the checkout carried; its stamped PDF can be downloaded again for 30 days. - xades-open unlimited for a year (sku "year"): €14.99 once, no renewal. Unlimited stamped PDF exports for 365 days from payment; one payment, no renewal. Covers stamped PDFs of any signed files for 365 days from payment, in the browser that holds the unlock. - The price shown is the amount charged; Checkout adds no tax line. - The stamped PDF is the document with a note on every page and a signature-report page (who signed, when, what was checked and what was not), with the original signed file attached. It is built in the browser tab; there is no API that returns it. - Machine-readable: https://xades-open.vercel.app/pricing.json ## How a checkout starts 1. In the browser, after a signed file is opened: POST https://xades-open.vercel.app/api/checkout with {"sku": "export", "lang": "en", "commit": "<64 hex>", "format": "cades"} or {"sku": "year", "lang": "es", "format": "xades"}. The commit is SHA-256(salt || SHA-256(file)); the browser keeps the salt, and neither it nor the file is sent. The optional format ("xades", "cades", "asice", "bdoc", "edoc" or "asics") is the kind of signed file open when buying, so sales can be counted per format. 2. The answer is {"url": ""}. A person opens it and pays by card. 3. Stripe returns to https://xades-open.vercel.app//paid?session_id=. That page calls GET https://xades-open.vercel.app/api/claim?session_id=, receives a signed unlock token and keeps it in the browser. There is no account. 4. Dropping the file again unlocks the stamped PDF. Every error is JSON {error: {code, cause, fix, retryable}}. ## Pages - Viewer: https://xades-open.vercel.app/pl · https://xades-open.vercel.app/pl/xades · https://xades-open.vercel.app/pl/asice · https://xades-open.vercel.app/pl/bdoc · https://xades-open.vercel.app/pl/edoc · https://xades-open.vercel.app/pl/sig · https://xades-open.vercel.app/pl/sig-na-pdf · https://xades-open.vercel.app/pl/podpis-cades · https://xades-open.vercel.app/en · https://xades-open.vercel.app/en/xades · https://xades-open.vercel.app/en/asice · https://xades-open.vercel.app/en/bdoc · https://xades-open.vercel.app/en/edoc · https://xades-open.vercel.app/en/sig · https://xades-open.vercel.app/en/csig · https://xades-open.vercel.app/es/csig · https://xades-open.vercel.app/es/csig-a-pdf - Refunds (a full refund within 30 days, for any reason): https://xades-open.vercel.app/refunds - Terms: https://xades-open.vercel.app/terms · Privacy: https://xades-open.vercel.app/privacy Updated 2026-10-10.