Mon–Sat 10–7 Chhani Jakatnaka, Vadodara
Harsiddhi Services Documentation & Compliance
Handling legal & government documents since 2017 Fixed price in writing before we start No hidden charges — government fees separate Rated by clients on Google
Home Digital Signature (DSC) USB Token
DSC · Hardware

The USB token — where your signature actually lives

Every Class 3 DSC in India comes on a small cryptographic USB device, and that is not a sales add-on: CCA security requirements put your private key inside FIPS-validated hardware it can never leave. Here is how the token works, how to keep it alive, and when your old one can be reused instead of replaced.

Since 2017 1,000+ DSC applications issued Updated: July 2026

Typical reply within minutes during office hours.

9+ yearsIn service
1,000+DSC applications
CSC 136237240013Govt-approved CSC
GST 24ETLPP2031J1ZMRegistered business
PID 242000004888GPLGST practitioner
★ GoogleRead client reviews

Speak to a person, not a call centre

Call or WhatsApp and you reach the Vadodara team that actually files your work — typically within minutes in office hours.

Ask anything first. Quotes are free and stay valid.

Message us now Class 3 DSC — typically issued in 24 hours
Why hardware

Why your certificate cannot just be a file

A digital signature is only as trustworthy as the secrecy of the private key that makes it. If that key sat in a file on your laptop, anyone who copied the file could sign as you — silently, perfectly, forever. That is why the CCA's security requirements for cryptographic devices have Class 3 subscriber keys generated inside, and permanently confined to, a hardware cryptographic token validated to FIPS standards (the international benchmark for tamper-resistant security modules — see the CCA's published requirements at cca.gov.in).

Three consequences make the token genuinely safer than any software arrangement:

  • The key never leaves the chip. Signing happens on the token: the document's fingerprint goes in, the signature comes out, and the key itself is non-exportable by design.
  • A PIN guards every use. Even with the physical token in hand, nothing signs without your PIN — and repeated wrong guesses lock the device.
  • Theft is visible. A copied file leaves no trace; a missing token does. You notice, you revoke, the certificate dies. That failure mode is precisely what the rules are engineered for.

So when a cut-price vendor offers to "email you the DSC", understand what is actually on offer: not a legitimate Class 3 certificate. Every certificate we arrange is delivered the compliant way — on a validated token.

Models

The tokens you will actually meet

The Indian market has settled on a handful of FIPS-validated models, and you will recognise them by name on any DSC desk: Feitian ePass2003 (and its Auto variant), Watchdata ProxKey, HYP2003, TrustKey and mToken. They differ in driver software and small conveniences, not in what they fundamentally do — each is a secure chip in a USB stick that holds keys and signs on demand.

We supply a current, supported model with every new DSC, chosen for compatibility with the issuing Certifying Authority and the portals you use. The quote we send on WhatsApp names the inclusion explicitly — certificate, token, courier, service — so there is no "token extra" surprise at checkout. A useful spec to know: one token can hold multiple certificates, which is how a signature-plus-encryption combo pair for tenders travels on a single device.

Download

How the certificate gets onto the token

  1. Approval first. Your eKYC and video verification clear with the Certifying Authority (the process described on our DSC hub), and the CA issues a download credential for your approved certificate.
  2. Token plugged in, keys born on-chip. With the token connected and its driver installed, the download utility instructs the token to generate the key pair inside the secure chip. The private key comes into existence already locked in hardware.
  3. Certificate written to the token. The CA binds your verified identity to the key and the certificate is stored on the device. You set your PIN.
  4. Verified working before handover. We test-sign and check the certificate details before the token leaves our hands — collected at our Vadodara office or couriered anywhere in India.

The download step is one-way and one-time: interrupt it carelessly (unplugging mid-write is the classic) and the credential can be consumed with nothing usable on the token, which then means support tickets with the CA. It is the single best reason to let us do the download rather than experimenting at home.

Care

Token care — five habits that prevent five emergencies

  • Guard the PIN, not just the token. Choose a PIN you will remember and store it somewhere other than a sticky note on the token. Repeated wrong attempts lock the device, and recovery options vary by model — sometimes unpleasantly.
  • Do not format or "repair" it. Windows may occasionally offer to format the unfamiliar device. Decline. The token is not a pen drive, and its contents cannot be restored from a backup — private keys are non-exportable by design.
  • Store it like a cheque book. Whoever holds the token and PIN can sign as you or your firm. Keep it with a specific person, in a specific place, and know where it is on filing day.
  • Report a loss immediately. Lost or stolen token: tell us or the CA promptly and revoke the certificate, then reissue on a new device. The PIN buys you time; revocation ends the risk.
  • Physical care is ordinary care. No heat, no water, no keychain acrobatics. These devices routinely serve for many years across multiple certificate cycles.
Renewal

Reusing your old token at renewal

Here is money-saving news the volume sellers rarely volunteer: a new token is not automatically required when your DSC expires. Renewal means a fresh certificate (fresh eKYC, fresh video — see DSC renewal), but the new certificate can be downloaded onto your existing token if the model and firmware are still supported. Since tokens outlive certificates by years, most renewals reuse the hardware.

The exception is genuinely old stock: some early tokens need a vendor-published CSP or firmware upgrade before they accept new certificates, and a few are simply past support and must be replaced. The check takes one WhatsApp message — send us the token model printed on the device, and we tell you "reuse" or "replace" before quoting, with the quote reflecting whichever is true.

When you do NOT need to buy from us. If your token is healthy and supported, we renew onto it and the quote drops accordingly — we do not bundle unnecessary hardware. And if your only problem is a driver or a portal that stopped seeing an otherwise valid certificate, that is an installation fix, not a new purchase; start at DSC installation help or the troubleshooting notes in common DSC errors.

Drivers

Drivers and portal utilities — the two-layer setup

A token that works perfectly can still be invisible to your portal, because there are two software layers and both must be right:

  • Layer one — the token's own driver/middleware. Each model ships its manager software (the ePass2003 token manager, the ProxKey PKI client, and so on). Without it, Windows or macOS cannot see the certificate at all.
  • Layer two — the portal's signing utility. Government portals bring their own bridge software: emSigner for GST, emBridge for income tax e-filing and MCA's V3 utility, an eMudhra-provided utility for DGFT. Each must be installed, running, and on speaking terms with your browser.

Most "my DSC is not working" panics live in the gap between these layers — utility not running, an old certificate shadowing the new one, a browser update breaking the bridge. Our installation help page walks through the full setup portal by portal, and remote installation support is included with every DSC we supply. Vadodara clients can simply bring the laptop and token to the office and leave with everything signing.

Before you decide

The bottom line

If you have read this far, you know more than most agents will ever tell you. The next step is simple: send us your case on WhatsApp, get the exact fee and timeline in writing, and decide with full information. That quote costs nothing.

Get the written quote

FAQs

USB tokens — common questions

Why can't my DSC just be a file on my computer?
CCA security requirements have Class 3 private keys generated and stored inside FIPS-validated hardware tokens. The key never leaves the device and signing happens on the token itself, PIN-protected — a .pfx file on disk offers none of that protection and is not how Class 3 subscriber keys are issued.
Which USB token brands are used in India?
Common FIPS-validated models include Feitian ePass2003, Watchdata ProxKey, HYP2003, TrustKey and mToken. We supply a supported current model with your DSC; the specific brand can vary with stock and the Certifying Authority.
Can I reuse my old token when I renew my DSC?
Usually yes — the renewed certificate downloads onto the same token if the model and firmware are still supported. Very old tokens sometimes need a vendor upgrade tool or replacement. Send us your token model and we will confirm before you renew.
How does the certificate get onto the token?
After the Certifying Authority approves your application, a download credential is issued. With the token plugged in, the certificate — and its private key, generated on the device — is written into the token's secure chip. From then on the key exists only there.
What is the token PIN and what if I enter it wrongly?
The PIN is set by you and asked for at every signature. Repeated wrong attempts lock the token — a security feature, not a bug. If you have forgotten the PIN, contact us before guessing; recovery options depend on the token model and can be limited.
Can one token hold more than one certificate?
Yes. A signature-plus-encryption combo pair lives on one token as standard, and a token can also carry certificates for different purposes. What cannot happen is copying a certificate off one token onto another — private keys are non-exportable.
What do I install on my computer to use the token?
Two layers: the token's own driver or middleware (for example the ePass2003 token manager or ProxKey PKI client), and then whatever signing utility your portal requires — emSigner for GST, emBridge for income tax and MCA, an eMudhra utility for DGFT. We set both up remotely or at our office.
What happens if I lose the token?
Treat it like a lost cheque book: inform us or the Certifying Authority promptly so the certificate can be revoked, then apply for a fresh DSC on a new token. The PIN protects you in the meantime, but revocation is the correct response, not hope.
Is the USB token included in your DSC quote?
Yes — our fixed WhatsApp quote states whether it includes a new token or assumes reuse of your existing one, along with courier. No separate token charge appears later.
Does the token expire with the certificate?
No. The token is hardware; the certificate inside it has the 1, 2 or 3-year validity. When the certificate expires you renew the certificate onto the same token — the hardware serves for years across multiple renewal cycles.

Token trouble, or DSC with token included — sorted on WhatsApp

Send us your token model (or just "I need a new DSC with token"). We confirm reuse or replacement, quote one fixed price before you pay, and handle download, drivers and portal setup end to end.