The USB token — where your signature actually lives
Every Class 3 DSC in India comes on a small cryptographic USB device, and that is not a sales add-on: CCA security requirements put your private key inside FIPS-validated hardware it can never leave. Here is how the token works, how to keep it alive, and when your old one can be reused instead of replaced.
Typical reply within minutes during office hours.
Speak to a person, not a call centre
Call or WhatsApp and you reach the Vadodara team that actually files your work — typically within minutes in office hours.
Ask anything first. Quotes are free and stay valid.
Why your certificate cannot just be a file
A digital signature is only as trustworthy as the secrecy of the private key that makes it. If that key sat in a file on your laptop, anyone who copied the file could sign as you — silently, perfectly, forever. That is why the CCA's security requirements for cryptographic devices have Class 3 subscriber keys generated inside, and permanently confined to, a hardware cryptographic token validated to FIPS standards (the international benchmark for tamper-resistant security modules — see the CCA's published requirements at cca.gov.in).
Three consequences make the token genuinely safer than any software arrangement:
- The key never leaves the chip. Signing happens on the token: the document's fingerprint goes in, the signature comes out, and the key itself is non-exportable by design.
- A PIN guards every use. Even with the physical token in hand, nothing signs without your PIN — and repeated wrong guesses lock the device.
- Theft is visible. A copied file leaves no trace; a missing token does. You notice, you revoke, the certificate dies. That failure mode is precisely what the rules are engineered for.
So when a cut-price vendor offers to "email you the DSC", understand what is actually on offer: not a legitimate Class 3 certificate. Every certificate we arrange is delivered the compliant way — on a validated token.
The tokens you will actually meet
The Indian market has settled on a handful of FIPS-validated models, and you will recognise them by name on any DSC desk: Feitian ePass2003 (and its Auto variant), Watchdata ProxKey, HYP2003, TrustKey and mToken. They differ in driver software and small conveniences, not in what they fundamentally do — each is a secure chip in a USB stick that holds keys and signs on demand.
We supply a current, supported model with every new DSC, chosen for compatibility with the issuing Certifying Authority and the portals you use. The quote we send on WhatsApp names the inclusion explicitly — certificate, token, courier, service — so there is no "token extra" surprise at checkout. A useful spec to know: one token can hold multiple certificates, which is how a signature-plus-encryption combo pair for tenders travels on a single device.
How the certificate gets onto the token
- Approval first. Your eKYC and video verification clear with the Certifying Authority (the process described on our DSC hub), and the CA issues a download credential for your approved certificate.
- Token plugged in, keys born on-chip. With the token connected and its driver installed, the download utility instructs the token to generate the key pair inside the secure chip. The private key comes into existence already locked in hardware.
- Certificate written to the token. The CA binds your verified identity to the key and the certificate is stored on the device. You set your PIN.
- Verified working before handover. We test-sign and check the certificate details before the token leaves our hands — collected at our Vadodara office or couriered anywhere in India.
The download step is one-way and one-time: interrupt it carelessly (unplugging mid-write is the classic) and the credential can be consumed with nothing usable on the token, which then means support tickets with the CA. It is the single best reason to let us do the download rather than experimenting at home.
Token care — five habits that prevent five emergencies
- Guard the PIN, not just the token. Choose a PIN you will remember and store it somewhere other than a sticky note on the token. Repeated wrong attempts lock the device, and recovery options vary by model — sometimes unpleasantly.
- Do not format or "repair" it. Windows may occasionally offer to format the unfamiliar device. Decline. The token is not a pen drive, and its contents cannot be restored from a backup — private keys are non-exportable by design.
- Store it like a cheque book. Whoever holds the token and PIN can sign as you or your firm. Keep it with a specific person, in a specific place, and know where it is on filing day.
- Report a loss immediately. Lost or stolen token: tell us or the CA promptly and revoke the certificate, then reissue on a new device. The PIN buys you time; revocation ends the risk.
- Physical care is ordinary care. No heat, no water, no keychain acrobatics. These devices routinely serve for many years across multiple certificate cycles.
Reusing your old token at renewal
Here is money-saving news the volume sellers rarely volunteer: a new token is not automatically required when your DSC expires. Renewal means a fresh certificate (fresh eKYC, fresh video — see DSC renewal), but the new certificate can be downloaded onto your existing token if the model and firmware are still supported. Since tokens outlive certificates by years, most renewals reuse the hardware.
The exception is genuinely old stock: some early tokens need a vendor-published CSP or firmware upgrade before they accept new certificates, and a few are simply past support and must be replaced. The check takes one WhatsApp message — send us the token model printed on the device, and we tell you "reuse" or "replace" before quoting, with the quote reflecting whichever is true.
When you do NOT need to buy from us. If your token is healthy and supported, we renew onto it and the quote drops accordingly — we do not bundle unnecessary hardware. And if your only problem is a driver or a portal that stopped seeing an otherwise valid certificate, that is an installation fix, not a new purchase; start at DSC installation help or the troubleshooting notes in common DSC errors.
Drivers and portal utilities — the two-layer setup
A token that works perfectly can still be invisible to your portal, because there are two software layers and both must be right:
- Layer one — the token's own driver/middleware. Each model ships its manager software (the ePass2003 token manager, the ProxKey PKI client, and so on). Without it, Windows or macOS cannot see the certificate at all.
- Layer two — the portal's signing utility. Government portals bring their own bridge software: emSigner for GST, emBridge for income tax e-filing and MCA's V3 utility, an eMudhra-provided utility for DGFT. Each must be installed, running, and on speaking terms with your browser.
Most "my DSC is not working" panics live in the gap between these layers — utility not running, an old certificate shadowing the new one, a browser update breaking the bridge. Our installation help page walks through the full setup portal by portal, and remote installation support is included with every DSC we supply. Vadodara clients can simply bring the laptop and token to the office and leave with everything signing.
The bottom line
If you have read this far, you know more than most agents will ever tell you. The next step is simple: send us your case on WhatsApp, get the exact fee and timeline in writing, and decide with full information. That quote costs nothing.
USB tokens — common questions
Why can't my DSC just be a file on my computer?
Which USB token brands are used in India?
Can I reuse my old token when I renew my DSC?
How does the certificate get onto the token?
What is the token PIN and what if I enter it wrongly?
Can one token hold more than one certificate?
What do I install on my computer to use the token?
What happens if I lose the token?
Is the USB token included in your DSC quote?
Does the token expire with the certificate?
Token trouble, or DSC with token included — sorted on WhatsApp
Send us your token model (or just "I need a new DSC with token"). We confirm reuse or replacement, quote one fixed price before you pay, and handle download, drivers and portal setup end to end.