---
title: "Pkcs11Options"
canonical_url: "https://www.nutrient.io/api/csharp/signing/pkcs11-options/"
md_url: "https://www.nutrient.io/api/csharp/signing/pkcs11-options.md"
last_updated: "2026-10-08T08:55:57.713Z"
description: "Locates the signing key on a PKCS#11 (Cryptoki) module — a hardware security module, USB token, or smartcard accessed through a vendor driver."
---

Locates the signing key on a PKCS#11 (Cryptoki) module — a hardware security module, USB token, or smartcard accessed through a vendor driver.

Used when `KeySource` is `Pkcs11`. Works on any platform the vendor module supports.

```csharp

using Nutrient;

```

## Construction

```csharp

public Pkcs11Options()

```

## Properties

### KeyLabel

```csharp

public string? KeyLabel { get; set; }

```

The label of the signing key to use. When empty, the first signing-capable key is used.

**Type:** `string?`

### ModulePath

```csharp

public string ModulePath { get; set; }

```

The file path of the vendor PKCS#11 module (for example `opensc-pkcs11.dll`).

**Type:** `string`

### Pin

```csharp

public string Pin { get; set; }

```

The user PIN used to log in to the token.

**Type:** `string`

### TokenLabel

```csharp

public string? TokenLabel { get; set; }

```

The label of the token to use. When empty, the first token present is used.

**Type:** `string?`

## Resource management

```csharp

public void Dispose()

```

`Pkcs11Options` implements `IDisposable`. Call `Dispose()` or use a C# `using` declaration to release its native handle right away. If you don't, the handle is released when the object is garbage collected.

---

## Related pages

- [Signing](/api/csharp/signing.md)
- [Digital Signature Options](/api/csharp/signing/digital-signature-options.md)
- [Signature Appearance](/api/csharp/signing/signature-appearance.md)
- [Signature](/api/csharp/signing/signature.md)
- [Timestamp Configuration](/api/csharp/signing/timestamp-configuration.md)

