Documents
They sign it. You get the PDF.
Add a signature field to any form and a visitor draws or types their name. The submission becomes a branded PDF of every question and every answer. The document carries a token anybody can verify on a public page.
No per-signature price, no separate e-signature product and no counter that stops your month.
On every plan, including the free one
From your own code
One route that hands you the file
The same document the hosted page produces, behind a key and a scope. There is no second product to buy and no rendering service to run.
GET /v1/submissions/{id}/pdf
Authorization: Bearer <your key>
// 200, an opaque attachment
content-type: application/pdf
content-disposition: attachment
x-content-type-options: nosniffWhat you get
Six things that are true of every document
The signature field is a field like any other. Everything below follows from that rather than from a second product bolted on beside forms.
A signature field, drawn or typed
A pad that takes a stylus, a finger or a mouse through pointer events, at the resolution of the screen it is drawn on so the mark is not soft. Somebody who would rather type their name can. So can somebody using a keyboard alone.
A PDF of the whole submission
Every question and every answer, in the order they were asked, on your own colours. An unanswered question is reported as unanswered rather than skipped. An upload and a payment print what they are.
A certificate anybody can check
The document carries a signed token. A public page resolves it with no account, no cookie and no database lookup, so there is no id to guess at and nothing internal in the token.
A code on the page
The verify address is printed on the document as a code as well as a link, so a signed form on paper can be checked from a phone.
A link that expires
The PDF is minted on request behind a short-lived signed link on the private object path. It is not stored, so there is no bucket of stored documents sitting somewhere waiting to leak.
Scoped to your workspace and no other
The workspace comes from the API key and never from the request. A submission id from another workspace answers 404 rather than 403, so the route cannot be used to find out what exists.
The signature field
What a signature is, exactly
It is stored as an image on the same upload path every other file uses, with a tighter allowance. One store, one erasure path, one place a signature can be deleted from.
| What | Value |
|---|---|
| Formats accepted | PNG and JPEG only |
| Size ceiling | 256KB |
| Files per signature | One |
| Stored as | A private object with an ownership row, exactly like any other upload |
| Content type | Sniffed from the bytes rather than believed from the request |
| Erasure | Reached by erasing the contact, like every other answer they gave |
The certificate
Proof somebody can check without asking you
The token on the document is signed with a key whose public half we publish. The verify page reads the token, checks the signature against the published keys and says what it found. No account, no cookie and no lookup, so there is nothing to enumerate and nothing internal in the token to use as a key against anything else.
Every reason a token fails gets the same sentence, so somebody trying to forge one learns nothing about which half to fix. And the page teaches the reader what to compare against the document in their hand rather than only saying yes.
A token minted before a key rotation stays verifiable while both keys are published, so a document you handed a customer last quarter does not quietly stop checking out.
Where this stops
The PDF draws the scripts the standard fonts cover. A character outside them is laddered down and the document says on its own face that it happened, rather than dropping it silently. If your customers write in a script that needs its own font, read this paragraph twice before you rely on the document.
The notification email does not carry the PDF. It carries the answers. A signed link expires and an attachment resting in a mailbox does not, so the two are not interchangeable and we have not pretended they are.
A certificate is proof of what we recorded. It says this submission, this form version, at this time, unaltered since. It is not a legal opinion about whether the agreement binds anybody. No product can sell you that.
Put a signature on a form this afternoon
Drag the field onto any form, publish it and the next submission has a document behind it. No signed-document counter and no per-signature price.
No card to start. No trial clock. The free plan runs the whole loop.