Skip to main content
POST
Mint a short-lived, single-use URL for an embedded signer.

Authorizations

Authorization
string
header
required

Authorization: Bearer vsk_live_…. Chosen over a bespoke X-API-KEY header because every client, proxy and log-redaction rule already knows this one. What a key may DO is its scopes — see x-scopes at the root of this document and x-required-scope on each operation. The scope list is not written here because OpenAPI reserves a requirement’s scope array for oauth2 and openIdConnect and requires it to be empty for an http scheme.

Path Parameters

envelopeId
string<uuid>
required

The envelope, as returned by POST /api/v1/envelopes or POST /api/v1/envelopes/one-off. An envelope id.

Example:

"01960000-0000-4000-8000-0000000000e7"

recipientId
string<uuid>
required

The recipient’s id from that same response. ⚠️ Not the role name — a recipient has no natural key, because one person may hold two roles and two people may hold one. A recipient id.

Example:

"01960000-0000-4000-8000-000000000060"

Response

The URL and when it stops being redeemable. Not readable again from anywhere: only a digest is stored.

The minted URL.

url
string
required

Single use. The first GET spends it; a second, within the 10 minutes, renders a page that posts { action: "signing_url_invalid", reason: "used", can_remint: true } to your host page, and the remedy is to call this endpoint again. There is no endpoint that reads this value back — a credential readable twice is one stored somewhere readable, and we store only a digest.

expires_at
string<date-time>
required

ISO 8601, UTC. 10 minutes from minting, or the envelope’s own deadline if that is sooner. ⚠️ THIS IS THE LIFE OF THE URL, NOT OF THE SIGNING SESSION: a signer who opens it just before it expires gets a full session of 1 hour (or less, if the envelope’s deadline is sooner) from that moment. A host that reloads the iframe on this timer rather than only when the URL was never opened will interrupt somebody mid-signature.