The basics
Authentication is one header, one step. The prefix is stored in clear so a leaked key is
greppable and traceable to an organisation; the secret is stored only as a hash, so nobody —
including us — can recover it. See Authentication.
The OpenAPI document is public, needs no key, is readable cross-origin from a browser, and is
generated from the running code — so it cannot describe an endpoint the API does not serve. The
reference on this site is rendered from it. Generate a client from it.
Documents are checked by the bytes, not the extension, so renaming a file changes nothing
either way. A Word
.docx is converted to PDF on our side, and the converted PDF is what fields
are placed on and what gets signed — your original is kept unchanged. Text tags survive that
render. The older .doc format is not accepted. Through the API a document travels
base64-encoded inside the JSON body, which is what sets the API’s ceiling in the table above,
whatever the document’s format or page count; the upload screen, which sends the file itself,
allows more.