Skip to main content

E-signature

The signing flow: turn a PDF into a sign document, place fields on it, invite recipients, collect their signatures over one-time links, and end with a completed, fingerprinted file.

The lifecycle​

StatusMeaning
DRAFTCreated, fields not yet finalized
PENDINGSent, waiting on the first recipient
IN_PROGRESSAt least one recipient has signed
COMPLETEDEvery signer is done — the fingerprint is computed
EXPIREDPassed expiryAt before completion
CANCELLEDThe owner cancelled it

1. Create​

POST /api/sign/create — the owner uploads a PDF (/sign/upload), which creates the SignDocument referencing one file, with a title, optional description, and an optional expiryAt (null = never expires).

2. Place fields​

POST /api/sign/{docId}/fields — in the builder (/sign/build/:docId) the owner drags fields onto pages. Each field has a type, a page, an x / y / width / height, and the recipient it belongs to:

Field type
SIGNATUREA drawn / typed / uploaded signature
INITIALSShort-form sign-off
DATEAuto-filled on signing
TEXTA free-text entry the recipient fills
CHECKBOXAn acknowledgement tick

3. Recipients and flow​

Each recipient has an email, a name, and a role:

RoleCan
SIGNERFill and sign their fields
APPROVERApprove without signing
VIEWERSee the document only

The signing flow is PARALLEL (everyone at once) or SEQUENTIAL (one at a time, in signingOrder).

4. Send​

POST /api/sign/{docId}/send emails every recipient their unique link. Each link carries a UUID signingToken; only a SHA-256 hash of it is stored (tokenHash), so a database leak doesn't hand out working links.

The public signing page​

/sign/:token — the recipient opens the link, no account needed:

StepEndpoint
Load the document + fieldsGET /api/public/sign/{token}
View the PDFGET /api/public/sign/{token}/pdf
Request an email OTPPOST /api/public/sign/{token}/otp/send
Confirm the OTPPOST /api/public/sign/{token}/otp/verify
Submit signature + field valuesPOST /api/public/sign/{token}/complete

The OTP is stored as a SHA-256 hash with an expiry and an attempt counter — it's a genuine second factor on the identity of the signer, not just a formality.

Track and manage​

ActionEndpoint
List / search sent documentsGET /api/sign/list · /api/sign/search
Check statusGET /api/sign/{docId}/status
Resend to one recipientPOST /api/sign/{docId}/recipients/{recipientId}/resend
CancelPOST /api/sign/{docId}/cancel
DeleteDELETE /api/sign/{docId}
Full audit trailGET /api/sign/{docId}/audit
Integrity checkGET /api/sign/{docId}/integrity

The tracking page (/sign/track) shows every document and where each recipient stands. See Document integrity & audit for what the audit and integrity endpoints return.

Hrida.ai is proprietary software of Zlabs Innovation. See the license for terms. © 2026 Zlabs Innovation.