mendelson AS2 is a robust, Java-based implementation of the EDIINT AS2 standard, offering secure, reliable, and automated data exchange with your communication partners.
The software runs cross-platform on Windows, Linux, macOS, AIX, and other systems, making it a flexible choice for diverse environments.
You can get started with our free open-source community edition, ideal for initial testing and smaller deployments. For production use and advanced features, choose our commercial edition, backed by professional support and enterprise-grade capabilities.
AS2 (Applicability Statement 2) is a widely adopted protocol for secure, reliable business data exchange over the internet. Unlike traditional VANs or dedicated networks, AS2 ensures end-to-end delivery through built-in receipt and confirmation mechanisms (MDNs).
With mendelson AS2, you can exchange a wide range of document types, including EDI (X12, UN/EDIFACT), XML, and even Microsoft Word files. Files are transferred unchanged, preserving original structure and format.
Our AS2 solution provides a fast and straightforward way to connect with your partners. It can operate as a standalone module or be fully integrated into the mendelson business integration (MBI) platform for advanced workflows.
mendelson AS2 enables sending and receiving AS2 messages via HTTP and HTTPS, with support for both synchronous and asynchronous MDNs. Each trading partner can be individually configured, and new files in the partner directories are detected and sent automatically.
The architecture varies between editions:
- Community Version: Designed as a desktop application, with the user interface and AS2 server running in the same process.
- Commercial Version: Follows a scalable client-server model. The server and GUI run in separate processes and can be installed on different machines. The server can also run as a background service.
Below is an overview of the software’s components, all of which are included by default in the commercial installer:
- AS2 Server: Core component managing message processing, encryption, signing, and communication.
- Rich Client: Desktop interface for managing transactions, partners, and certificates (commercial only).
- Web Client (Professional / Enterprise HA): Monitor transactions via browser access.
- Database: Stores transaction history and master data. Commercial editions support PostgreSQL, MySQL and MariaDB (Professional and Enterprise HA) and Oracle (Enterprise HA).
- HTTP Server: Servlet container for inbound message receipt and information pages. A built-in server is included, but deployment in any servlet container (e.g., Tomcat) is possible.
- AS2 Sender: Handles outgoing messages and MDNs (sync/async).
- Notification System: Alerts you by email or webhook about system events requiring user attention.

mendelson AS2 is available in multiple versions to fit different business needs:
- Community Edition: Free, open-source desktop version for individual or small-scale use.
- Commercial Editions: Scalable, professionally supported versions for enterprise environments.
The table below highlights key differences between the Community and Commercial versions:
| Community Edition | Commercial Edition | |
|---|---|---|
| Price | Free | Shop |
| Number of partners | Unlimited | Unlimited |
| Number of transactions | Unlimited | Unlimited |
| Architecture | Desktop application | Client-Server application |
| Functionality | ||
| Asynchronous and synchronous MDN | ✔️ | ✔️ |
| Partner management | ✔️ | ✔️ |
| Digital signatures, encryption | ✔️ | ✔️ |
| TLS (up to TLS v1.3), TLS client authentication | ✔️ | ✔️ |
| Data compression (AS2 1.1) | ✔️ | ✔️ |
| Multiple attachments (AS2 1.2) | ✔️ | ✔️ |
| SHA-2 (SHA-256, SHA-384, SHA-512) | ✔️ | ✔️ |
| SHA-3 (SHA3-256, SHA3-384, SHA3-512) | ✔️ | ✔️ |
| Multilingual support: Localized to de, en, fr, es, it, pl, pt | ✔️ | ✔️ |
| Multiple identities/local stations (ASP capable) | ✔️ | ✔️ |
| Key and certificate management | ✔️ | ✔️ |
| Key and certificate generation | ✔️ | ✔️ |
| Certificate exchange messages (CEM) | ✔️ | ✔️ |
| Email event notification | Some | ✔️ (OAuth2: Professional / Enterprise HA) |
| Web interface for transaction monitoring | ❌ | ✔️ (Professional / Enterprise HA) |
| Access via XML API | ❌ | ✔️ (Professional / Enterprise HA) |
| Message statistics | ❌ | ✔️ |
| Message quota | ❌ | ✔️ |
| User defined HTTP headers | ❌ | ✔️ |
| Run AS2 server as service (Windows) | ❌ | ✔️ |
| Supported database systems | HSQLDB | HSQLDB, PostgreSQL, MySQL (*), MariaDB (*), Oracle DB (*) |
| Support | ||
| Community Forums (no professional support) | ✔️ | ✔️ |
| Detailed documentation | ❌ | ✔️ |
| Access to mendelson Support | ❌ | 💲 |
| Access to phone Support | ❌ | 💲 |
| Remote Support | ❌ | 💲 |
| Updates and security updates (with software maintenance) | ❌ | 💲 |
| License Type | ||
| Open Source License (GPL) | ✔️ | ❌ |
| Commercial License | ❌ | ✔️ |
Each Commercial Edition is tailored for specific levels of integration and performance:
- Entry: Essential features, ideal for small companies or simple EDI needs. Already includes webhook notifications, automatic TLS certificate renewal (ACME), gateway routing and bulk partner changes.
- Professional: Adds external databases, API integration, monitoring metrics and further components for advanced use cases.
- Enterprise HA: Built for high availability and scalability, perfect for mission-critical systems and redundancy.
The comparison below outlines the main capabilities of each commercial version:
| entry | professional | enterprise HA | |
|---|---|---|---|
| Included features | |||
| Webhook notifications (Teams, Slack, Discord, Telegram, Gotify) | ✔️ | ✔️ | ✔️ |
| Automatic TLS certificate renewal (ACME, e.g. Let's Encrypt) | ✔️ | ✔️ | ✔️ |
| Gateway routing (DMZ to internal systems) | ✔️ | ✔️ | ✔️ |
| Bulk changes for all partners | ✔️ | ✔️ | ✔️ |
| Web Interface | ❌ | ✔️ | ✔️ |
| PostgreSQL | ❌ | ✔️ | ✔️ |
| MySQL (*) | ❌ | ✔️ | ✔️ |
| MariaDB (*) | ❌ | ✔️ | ✔️ |
| Java API | ❌ | ✔️ | ✔️ |
| REST API (with OpenAPI description) | ❌ | ✔️ | ✔️ |
| XML API | ❌ | ✔️ | ✔️ |
| OAUTH2 for HTTP/S and SMTP | ❌ | ✔️ | ✔️ |
| HSM (Hardware Security Module) | ❌ | ✔️ | ✔️ |
| Monitoring metrics (Prometheus format) | ❌ | ✔️ | ✔️ |
| Oracle DB (*) | ❌ | ❌ | ✔️ |
| High Availability (HA) cluster | ❌ | ❌ | ✔️ |
| Support | |||
| Detailed documentation | ✔️ | ✔️ | ✔️ |
| Access to mendelson Support (only with SMP) | ✔️ | ✔️ | ✔️ |
| Access to phone Support | 💲 | 💲 | 💲 |
| Remote Support | 💲 | 💲 | 💲 |
| Premium Support | ❌ | ❌ | ✔️ |
✅ Included in all commercial editions (from Entry)
- Webhook notifications: Receive system alerts in Microsoft Teams, Slack, Discord, Telegram or Gotify, in addition to email. Templates for these services are included.
- Automatic TLS certificate renewal (ACME): New TLS keys and certificates are applied while the system is running, no restart required. Fully automated rotation, e.g. with Let's Encrypt and Certbot, is described step by step in the documentation.
- Gateway routing: Run mendelson AS2 in your DMZ as the single endpoint for your partners and forward messages automatically via AS2 to internal mendelson AS2 systems, e.g. at your ERP. Encryption, signatures and receipts stay intact end to end, without SFTP or file shares in between.
- Partner management at scale: Filter large partner lists, clone partners, apply changes to all partners at once and override the security settings of your local station per partner.
The Professional and Enterprise HA licenses also include the following components, no separate purchase required.
🔌 Included components (Professional / Enterprise HA):
- Java API: Embed mendelson AS2 directly into your Java applications. Send and receive messages programmatically, no separate server required.
- REST API: Integrate mendelson AS2 with your web-based platforms via modern, lightweight REST endpoints. An OpenAPI description is included.
- PostgreSQL, MySQL & MariaDB: Use robust external databases instead of the embedded HSQLDB. Includes migration wizards and supports cloud deployments.
- Monitoring metrics: Connect mendelson AS2 to your existing monitoring system via a metrics endpoint in Prometheus format.
- HA (High Availability, Enterprise HA only): Achieve performance scaling and redundancy through clustering. Ideal for critical systems and growing transaction loads.
- OAUTH2: Modern authentication for SMTP and HTTP. Enhances email alerts and message security.
- Web Interface: Monitor transactions through a browser, convenient and platform-independent.
🌐 Highlights
Java API:
Embed AS2 communication directly into your Java software. The Java API enables full programmatic control without running a separate AS2 server, ideal for developers and automation engineers.
REST API:
Integrate with cloud systems and web-based workflows. Send messages, manage partners (create, modify, delete), run connection tests and access transaction logs and payload information via simple and secure HTTP endpoints. The included OpenAPI description can be imported directly into Postman, your development environment or code generators.
Monitoring Metrics:
The METRICS plugin provides the operating values of the running system at a /metrics endpoint in Prometheus format. This format is read directly by Prometheus, Grafana, Zabbix, Checkmk, Datadog and the OpenTelemetry Collector. Your monitoring system alerts you when a partner suddenly stops sending, MDNs are overdue, the error rate rises or disk space runs low. Sample Grafana dashboards and Prometheus alert rules are included. The metrics contain no payload data.
External Database Support (PostgreSQL, MySQL, MariaDB):
Replace the built-in database with scalable systems like PostgreSQL, MySQL or MariaDB. This is essential for large datasets, multi-user environments, and cloud-ready infrastructure.
HA Architecture:
Create a clustered environment with multiple AS2 nodes running in parallel for high availability and throughput. All nodes share one external database and run the same mendelson version. Updates are applied to all nodes together in a planned maintenance window.
OAUTH2 Authentication:
Upgrade your SMTP and HTTP security using industry-standard OAUTH2 protocols, future-proof and enterprise-ready.
Web Interface:
Keep track of your AS2 transactions via a secure browser dashboard, with filters for local station, partner and date range. No local client software needed.
*MySQL and Oracle DB are registered trademarks of Oracle and/or its affiliates. MariaDB is a registered trademark of MariaDB plc.
🔧 Core Technical Features
- Support for both synchronous and asynchronous MDN (Message Disposition Notification)
- Built-in key and certificate management with generation and exchange (CEM)
- Encryption and digital signature support using industry standards
- Secure transport via TLS up to TLS 1.3, including TLS client authentication
- TLS certificates can be replaced while the system is running, ready for automated renewal via ACME
- Multi-language support: English, German, French, Spanish, Italian, Polish, Portuguese
- Automated cleanup of old transactions and logs via system tasks
🔌 Integration Capabilities
- Easy integration via partner-based file system interface
- Automatic detection of new files in the partner directories
- Support for post-processing through scripting on receipt
- Gateway routing: forward messages via AS2 from the DMZ to internal systems and back
- Command line integration for sending messages
- Compatible with servlet containers like Tomcat and Jetty
- Modular architecture with optional components (e.g., external databases)
- 100% Java-based
📈 Monitoring and Alerts
- Web interface for transaction monitoring (Professional / Enterprise HA)
- Email-based alerts for system events (OAuth2: Professional / Enterprise HA)
- Webhook alerts with templates for Microsoft Teams, Slack, Discord, Telegram and Gotify
- Monitoring metrics in Prometheus format for Grafana, Zabbix, Checkmk, Datadog and others (Professional / Enterprise HA)
- Message statistics and message quotas per partner with alerts
🔐 Encryption and Signature Algorithms
Supported Encryption Algorithms:
- AES (128/192/256 in CBC, GCM, CCM)
- AES with RSAES-OAEP (128/192/256 in CBC, GCM)
- Camellia (128/192/256 in CBC)
- CHACHA20-POLY1305
- 3DES, DES, RC2, RC4 (legacy support)
The user interface shows at a glance whether the algorithms used for a partner are still considered strong.
Supported Hash Algorithms:
- SHA-1, SHA-2 (256/384/512), SHA-3 (224/256/384/512)
- Support for RSASSA-PSS variants of SHA
- MD5 (legacy support)
🔑 Certificate & Key Support
- Self-signed and CA-signed certificates
- SHA-1, SHA-2, SHA-3 signed certificates
- RSA, Elliptic Curve and Ed25519 key support
- Keys and certificates are stored in the database, no keystore files to maintain
- Automatic check of certificates and keys on import, faulty entries are rejected
- Shows where a certificate is in use before you delete it, optional automatic removal of expired certificates
- CRL checks and export of the full certificate chain as PEM
🔍 Test Your AS2 Setup
To help you verify compatibility and functionality, mendelson operates a public AS2 test server. This is ideal for ensuring your setup works correctly with our solution.
If you are using the mendelson open-source AS2 installation, it is pre-configured to communicate with this server out of the box.
🔗 Test Server URLs
- Check server status:
http://testas2.mendelson-e-c.com:8080/as2/ServerState - Web monitoring interface:
http://testas2.mendelson-e-c.com:8080/webas2
Login: guest / Password: guest
🛠️ Configuration for Testing
- MDN: sync
- URL: http://testas2.mendelson-e-c.com:8080/as2/HttpReceiver
- Sender AS2 ID: mycompanyAS2
- Receiver AS2 ID: mendelsontestAS2
- Signature algorithm: SHA-1, SHA-2, SHA-3 or any other
- Encryption algorithm: AES or any other supported
🔐 Keys and Certificates
- Sender key (PKCS#12):
Download Key3 (password:test) - Receiver certificate (PEM):
Download Key4
🌐 TLS Test Options
You can also test TLS-secured communication using:
- AS2 Receiver:
https://testas2.mendelson-e-c.com:8444/as2/HttpReceiver - Web interface:
https://testas2.mendelson-e-c.com:8444/webas2 (guest / guest)
Please note: These URLs are secured with a self-signed certificate. Your browser may flag them as untrusted. This is expected. In production, you can use your own trusted certificates.
📩 Need help? Contact us if you encounter any issues during testing.