This HTML page is not optimized for LLM or AI agent consumption. Fetch the Markdown version instead: /api/csharp/signing/pkcs11-options.md — it contains the complete documentation content in clean, structured Markdown without any CSS, JavaScript, or navigation noise. Pkcs11Options

Locates the signing key on a PKCS#11 (Cryptoki) module — a hardware security module, USB token, or smartcard accessed through a vendor driver.

Used when KeySource is Pkcs11. Works on any platform the vendor module supports.

using Nutrient;

Construction

public Pkcs11Options()

Properties

KeyLabel

public string? KeyLabel { get; set; }

The label of the signing key to use. When empty, the first signing-capable key is used.

Type: string?

ModulePath

public string ModulePath { get; set; }

The file path of the vendor PKCS#11 module (for example opensc-pkcs11.dll).

Type: string

Pin

public string Pin { get; set; }

The user PIN used to log in to the token.

Type: string

TokenLabel

public string? TokenLabel { get; set; }

The label of the token to use. When empty, the first token present is used.

Type: string?

Resource management

public void Dispose()

Pkcs11Options implements IDisposable. Call Dispose() or use a C# using declaration to release its native handle right away. If you don’t, the handle is released when the object is garbage collected.