Upload a file to a file-upload field (EAS-110)
One active upload per field — a second upload to the same field replaces the first. Requires the same signing state PublicComplete does: pending document, before the deadline, this recipient's turn (sequential mode), not yet signed or declined. The field must be assigned to the caller's recipient/group slot and be of type "file". Content is validated by its actual bytes, never the multipart Content-Type or filename — narrower per-field allowedTypes/maxSizeBytes (DocumentField.config) can restrict this further than the system default (PDF, JPEG, PNG; 25 MB).
View as MarkdownPath Parameters
Request Body
multipart/form-data
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/public/signing/string/fields/string/upload" \ -F file="string"{ "upload": { "id": "string", "fieldId": "string", "name": "string", "size": 0, "contentType": "string", "status": "uploaded" }}Recipient download URL
Presigned URL for the recipient — the final artifact once completed, else the original.
Confirm a signing request is genuine
EAS-122. Resolves a verification code — printed in every signature-request email, independent of and never derivable from the recipient's actual signing token — to the minimal facts needed to recognize the request: who really sent it, which document, when, and its current status. Never returns document contents, field values, a file URL, or any recipient's email address. This confirms the request RECORD is genuine; it does not and cannot vouch that the sender is trustworthy or that their account hasn't been compromised. Unauthenticated, IP rate-limited tighter than the rest of the public surface (resolving a short code by exact match is the one public route here where guessing is realistic). An unknown code and a malformed one return the identical 404 — there is no way to distinguish "never issued" from "garbage input".