eForms Server by Aloaha

Feature reference Every feature, in one place.

This page lists what the eForms Server can do, grouped by the stages of a form: design, publishing, filling in, delivery, signing, e-invoicing, users and operation.

Designing forms

  • WYSIWYG designer in the browser: no installation; works on any workstation with a current browser.
  • Field types: text fields, multi-line text, check boxes, radio buttons, drop-down lists, buttons, lines, images, plain text and signature fields.
  • Layout: font, font size, colours, background colour, alignment, maximum length, required fields.
  • Validation: a regular expression per field, with ready-made rules for e-mail addresses and ID card numbers and custom error messages.
  • Letterheads and cascaded documents: a form can depend on a letterhead; change the letterhead once and every dependent form follows.
  • Templates and cloning: start from a template wizard or clone an existing form.
  • Backup: export a form with all settings and restore it on the same or another server.

Publishing

  • Three formats from one design: dynamic PDF (AcroForm, for Adobe Reader), responsive HTML for phones and tablets, and static HTML that keeps the print layout.
  • Automatic format choice: the server detects the device and delivers the suitable format; links can also request a format explicitly (pdf=1, web=1, static=1).
  • Release workflow: preview the PDF, release the form, receive an e-mail when rendering is complete.
  • Multilingual: language variants of forms and of all e-mail texts.

Filling in and submitting

  • Any device: phones, tablets, desktop browsers and Adobe Reader.
  • Attachments: users can add documents before submitting; images become PDF pages, other files are zipped and attached. Forms can require attachments.
  • Spam protection without CAPTCHA: an invisible check built into the server keeps bots out. Nobody has to click pictures or type distorted letters, and no third-party service such as Google reCAPTCHA sees your visitors.
  • Remembers your entries: when someone opens the same form again, their earlier entries are filled in from their own browser, separately for every form. Nothing is stored on the server, and one click clears them.
  • Pre-filling from a verified identity: after sign-in with an Aloaha or CodeB account, for example with the EU Digital Identity Wallet at www.aloaha.com, name and address fields can be filled automatically.
  • Handwritten signature fields right in the form, see Signatures.

Delivery and data

  • Sealed PDF: every submission is rendered as PDF and digitally sealed by the server.
  • Two e-mails: the submitter receives the sealed PDF; the business owner receives the PDF plus the form data as XML for further processing. Additional recipients can be configured.
  • Mail templates: subject, body and footer per form group and language, with placeholders such as form ID, document ID, submission ID and link.
  • No submission database: data are delivered and removed. An optional encrypted archive keeps password-protected PDFs, retrievable only with the submission ID.
  • Counters and reports: submissions per form and per month, as CSV report.

Signatures

  • Handwritten electronic signature with finger, pen or mouse, bound to the document by a SHA-512 server signature.
  • Optional timestamp from an RFC 3161 timestamp server, such as the Aloaha Timestamping Server.
  • X.509 signature fields: text fields named esignature become PDF signature fields for certificates and smart cards (advanced and qualified signatures).

E-invoicing

  • ZUGFeRD / Factur-X: invoice forms are converted to EN 16931 e-invoices on submission (PDF/A-3 with embedded XML).
  • ZUGFeRD tools: extract the XML from a ZUGFeRD PDF, embed XML into an existing PDF, or create the PDF from XML with a DOCX template; also as web service.

Users, groups and sign-in

  • Roles: administrators, users (form designers) and guests.
  • Form groups: each group sees and manages its own forms; every form has a business owner and a designer.
  • Sign-in with Aloaha and CodeB accounts: next to local accounts, the log-in page offers sign-in with www.aloaha.com, phone.codeb.io and phone.aloaha.com (OpenID Connect, authorization code flow with PKCE). The role of the account (administrator, user or guest) is applied unchanged, and the account's server becomes its form group.
  • Passkeys and EU Digital Identity Wallet: www.aloaha.com already supports sign-in with password, passkey (FIDO2 / WebAuthn) and the upcoming European Digital Identity Wallet (eIDAS 2.0, OpenID4VP, SD-JWT VC). Because the eForms Server signs in through it, these methods work for the form server, too. More on the EU Digital Identity Wallet.
  • Per-form authentication: a form can require sign-in before it can be filled in.

Aloaha ID: one sign-in for your applications

The sign-in behind the eForms Server is www.aloaha.com, a standard OpenID Connect provider operated by Aloaha. You can use it for your own applications as well:

  • Standard protocol: OpenID Connect with the authorization code flow and PKCE, signed ID tokens (RS256), userinfo, logout and token revocation. Any OIDC library works; the discovery document is at www.aloaha.com/.well-known/openid-configuration.
  • Modern sign-in methods: password, passkey (FIDO2 / WebAuthn), e-mail link and the European Digital Identity Wallet (eIDAS 2.0, OpenID4VP, SD-JWT VC), ready before the wallet becomes mandatory to accept.
  • Roles and groups: the role and groups claims let your application keep administrator, user and guest rights in one place.
  • Privacy controls: data agreements, consent receipts, an access log and data deletion requests for every user.

The same service runs on phone.codeb.io and phone.aloaha.com. To connect your application, write to info@aloaha.com or read the API documentation.

Integration and operation

  • Embedding: link to a form or embed it in your website; the URL decides the format.
  • On-premises or hosted: run it in your own data centre or use a server hosted by Aloaha.
  • Requirements: Windows Server with IIS (integrated pipeline) and .NET Framework 4.7.2.
  • Training and support: free online training and integration help; free updates for rented in-house servers.

Frequently asked questions

Which field types does the designer support?

Text fields, multi-line text, check boxes, radio buttons, drop-down lists, buttons, lines, images, plain text and signature fields.

How is input validated?

Each field can have a regular expression and an error message. Ready-made rules exist for e-mail addresses and ID card numbers.

What happens to attachments?

Images are converted into PDF pages; other files are zipped and attached to the submitted PDF.

Which sign-in methods are available?

Local user accounts and sign-in with an Aloaha or CodeB account through OpenID Connect: www.aloaha.com, phone.codeb.io and phone.aloaha.com. The role of the account (administrator, user or guest) is kept.

Do the forms use a CAPTCHA?

No. The eForms Server has its own invisible bot protection: the browser solves a small computing task in the background while the form is being filled in, and the server also checks timing, a hidden trap field and that each form is sent only once. People see nothing of it, and no third-party CAPTCHA service is involved.

Can people sign in with the EU Digital Identity Wallet?

Yes, through www.aloaha.com. It already accepts the upcoming European Digital Identity Wallet as well as passkeys, and passes the verified sign-in to the eForms Server by OpenID Connect.

Last updated: