REST · CLI · MCP

Signing infrastructure that speaks API.

Upload a PDF, collect electronic signatures and verify every event. Built for product teams and the agents working beside them.

  • EU-region storage
  • Postpaid per signature
  • Sandbox is not billed
req_01K6Z…8A4 completed
Partner agreement.pdfEvidence chain verified
  1. document.readySHA-256 verified
  2. request.sent2 signers
  3. request.completedevidence sealed
7f83b1657ff1fc53b92d…SHA-256

One public contract.
Every interface.

The dashboard, CLI and MCP tools are clients of the same API. If a human can do it, an agent can automate it—with live and billable actions kept explicit.

  • JSON in snake_case, errors as problem+json
  • Every mutation accepts an Idempotency-Key
  • sl_test_ and sl_live_ keys, shown once
curl
curl https://app.signlayer.eu/api/v1/signing_requests \
  -H "Authorization: Bearer sl_test_…" \
  -H "Idempotency-Key: onboarding-0001" \
  -d '{ "document_id": "3b0c…", "subject": "Partner agreement",
       "signers": [{ "name": "Marit de Vries", "email": "marit@acme.dev" }] }'

# 201 Created · status "draft" · no email sent, not billed

Nothing happens by surprise.

Creation is side-effect free. Sending is an explicit, idempotent call. Each live signer invitation is billed once when sent.

01

Upload a PDF

A presigned upload, then a SHA-256 check. The digest is fixed before anyone signs.

POST /documents
02

Create a request

Signers and signature fields come from your API call. No email is sent and nothing is billed.

POST /signing_requests
03

Send explicitly

Signers get a hosted, mobile-first flow with the document, the requested action and consent.

POST /signing_requests/{id}/send
04

Collect the evidence

A completed PDF, a chained audit trail and a signed webhook to your endpoint.

GET /signing_requests/{id}/audit
State machine
draft→sent→viewed→completed
Terminal: declined · expired · cancelled

Evidence over claims.

Every completed request yields a verifiable PDF digest, a chronological audit trail and a downloadable evidence bundle.

Version 1 provides simple electronic signatures and tamper-evident evidence. It does not claim qualified electronic signatures or qualified trust-service status.

SHA-256 digests

Source, completed and evidence PDFs are hashed and stored immutably.

Chained audit trail

Every state change is an immutable event with its own ID and timestamp.

HMAC-SHA256

Webhooks are signed and retried with exponential backoff.

EU-first by default

Database in the EU, documents in eu-central-1.

An agent can set it up. A human approves once.

An agent can start account setup without an API key. The human approves one explicit browser step; approval creates only a workspace and sandbox key.

  1. Authorize and create a workspace
  2. Create a test key and store it in the app's secret manager
  3. Install the TypeScript SDK or CLI
  4. Register a webhook endpoint and receive its signing secret once
  5. Upload a sample PDF, create a request and send it in sandbox
  6. Verify the webhook signature and check the audit trail
  7. Report what remains for production: billing approval, live key, sending domain

Pay per signature request.

Each live signer invitation is billed when sent, whether it is signed, declined, cancelled or expires.

Sandbox

€0unlimited

Non-production requests with a watermark. Full API, CLI and MCP access.

Start in sandbox

Volume

Custom

For more than 1,000 live signature requests per billing month.

Discuss volume
Estimated monthly invoice€217.50Excluding VAT · billed when each signer invitation is sent
Signlayer_

Start in sandbox. Live credentials unlock once a workspace owner activates billing.

Start in sandbox Read the API contract