Check a public link's availability
Never creates anything. One generic 404 for every pre-verification failure — bad token, paused, expired, or never existed — so there is no oracle for probing which case it is. Unauthenticated, IP rate-limited.
View as Markdowncurl -X GET "https://example.com/public/links/string"{ "available": true, "name": "string", "pages": 0}Confirm a signing request is genuine
EAS-122. Resolves a verification code — printed in every signature-request email, independent of and never derivable from the recipient's actual signing token — to the minimal facts needed to recognize the request: who really sent it, which document, when, and its current status. Never returns document contents, field values, a file URL, or any recipient's email address. This confirms the request RECORD is genuine; it does not and cannot vouch that the sender is trustworthy or that their account hasn't been compromised. Unauthenticated, IP rate-limited tighter than the rest of the public surface (resolving a short code by exact match is the one public route here where guessing is realistic). An unknown code and a malformed one return the identical 404 — there is no way to distinguish "never issued" from "garbage input".
Start email verification for a visitor
Never creates a document — issues (or reissues) a one-time code to the given email. Rate-limited on two independent dimensions: by IP (the whole public-links surface) and by the normalized email address itself, so a distributed attack aimed at one target inbox isn't just an IP problem. One-submission-per-email (when the link has it on) is never checked here — only after the code is verified, so this endpoint can't be used as an email-enumeration oracle. Unauthenticated.