Documents

They sign it. You get the PDF.

Add a signature field to any form and a visitor draws or types their name. The submission becomes a branded PDF of every question and every answer. The document carries a token anybody can verify on a public page.

No per-signature price, no separate e-signature product and no counter that stops your month.

On every plan, including the free one

From your own code

One route that hands you the file

The same document the hosted page produces, behind a key and a scope. There is no second product to buy and no rendering service to run.

Fetch a submission as a PDF
GET /v1/submissions/{id}/pdf
Authorization: Bearer <your key>

// 200, an opaque attachment
content-type: application/pdf
content-disposition: attachment
x-content-type-options: nosniff

What you get

Six things that are true of every document

The signature field is a field like any other. Everything below follows from that rather than from a second product bolted on beside forms.

  • A signature field, drawn or typed

    A pad that takes a stylus, a finger or a mouse through pointer events, at the resolution of the screen it is drawn on so the mark is not soft. Somebody who would rather type their name can. So can somebody using a keyboard alone.

  • A PDF of the whole submission

    Every question and every answer, in the order they were asked, on your own colours. An unanswered question is reported as unanswered rather than skipped. An upload and a payment print what they are.

  • A certificate anybody can check

    The document carries a signed token. A public page resolves it with no account, no cookie and no database lookup, so there is no id to guess at and nothing internal in the token.

  • A code on the page

    The verify address is printed on the document as a code as well as a link, so a signed form on paper can be checked from a phone.

  • A link that expires

    The PDF is minted on request behind a short-lived signed link on the private object path. It is not stored, so there is no bucket of stored documents sitting somewhere waiting to leak.

  • Scoped to your workspace and no other

    The workspace comes from the API key and never from the request. A submission id from another workspace answers 404 rather than 403, so the route cannot be used to find out what exists.

The signature field

What a signature is, exactly

It is stored as an image on the same upload path every other file uses, with a tighter allowance. One store, one erasure path, one place a signature can be deleted from.

How a signature answer is stored
WhatValue
Formats acceptedPNG and JPEG only
Size ceiling256KB
Files per signatureOne
Stored asA private object with an ownership row, exactly like any other upload
Content typeSniffed from the bytes rather than believed from the request
ErasureReached by erasing the contact, like every other answer they gave

The certificate

Proof somebody can check without asking you

The token on the document is signed with a key whose public half we publish. The verify page reads the token, checks the signature against the published keys and says what it found. No account, no cookie and no lookup, so there is nothing to enumerate and nothing internal in the token to use as a key against anything else.

Every reason a token fails gets the same sentence, so somebody trying to forge one learns nothing about which half to fix. And the page teaches the reader what to compare against the document in their hand rather than only saying yes.

A token minted before a key rotation stays verifiable while both keys are published, so a document you handed a customer last quarter does not quietly stop checking out.

Where this stops

The PDF draws the scripts the standard fonts cover. A character outside them is laddered down and the document says on its own face that it happened, rather than dropping it silently. If your customers write in a script that needs its own font, read this paragraph twice before you rely on the document.

The notification email does not carry the PDF. It carries the answers. A signed link expires and an attachment resting in a mailbox does not, so the two are not interchangeable and we have not pretended they are.

A certificate is proof of what we recorded. It says this submission, this form version, at this time, unaltered since. It is not a legal opinion about whether the agreement binds anybody. No product can sell you that.

Put a signature on a form this afternoon

Drag the field onto any form, publish it and the next submission has a document behind it. No signed-document counter and no per-signature price.

No card to start. No trial clock. The free plan runs the whole loop.