In-person signing (owner session)
Records a signature for a signer on the owner's device — self-sign or hand-the-device signing. External signers use their tokenized link instead. Requires a PNG data-URL signature; targets the given recipientId or the first unsigned signer; enforces sequential order; zero-signer documents cannot complete. Completion triggers the same finalize path as remote signing (stamped final PDF + certificate + emails).
View as MarkdownAuthorization
bearer In: header
Path Parameters
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/v1/documents/string/sign" \ -H "Content-Type: application/json" \ -d '{ "signature": "string" }'{ "document": { "id": "string", "name": "string", "url": "string", "status": "string", "created": "2019-08-24T14:15:22Z", "modified": "2019-08-24T14:15:22Z", "size": 0, "pages": 0, "templateId": "string", "hasFile": true, "hasFinalFile": true, "signingMode": "string", "message": "string", "sentAt": "2019-08-24T14:15:22Z", "completedAt": "2019-08-24T14:15:22Z", "voidedAt": "2019-08-24T14:15:22Z", "voidReason": "string", "visibility": "string", "ownerId": "string", "requiresNotarization": true, "notaryState": "string", "recipients": [ { "id": "string", "name": "string", "email": "string", "role": "string", "status": "string", "orderIndex": 0, "signedAt": "2019-08-24T14:15:22Z", "viewedAt": "2019-08-24T14:15:22Z", "declinedAt": "2019-08-24T14:15:22Z", "declineReason": "string", "hasAccessCode": true, "signature": "string" } ], "fields": [ { "id": "string", "type": "signature", "x": 0, "y": 0, "width": 0, "height": 0, "page": 0, "required": true, "label": "string", "value": "string", "recipientId": "string" } ] }}Void a draft or pending document
Status becomes "cancelled", every signing token is invalidated immediately, unsigned recipients are notified by email, and the void (with reason) is audited.
Full audit trail
Every lifecycle event in order — created, file_attached, sent, viewed, field_filled, signed, declined, reminded, voided, renamed, completed — with actor, IP, user agent, and the per-document SHA-256 hash chain.