Sign a PDF with Angular
Embed signing in Angular, sanitising the URL and keeping the key on your backend.
Drop your document here and sign it now. PDF, Word and Excel all work: a .docx or .xlsx is laid out in your browser exactly as it was written, so there is nothing to convert first. Add a signature, a date, a company stamp or a watermark, then download it sealed. Free to start, no account, and the file is never uploaded to open it.
Create a document and get a signing link
Angular runs in the browser, so this half belongs on your server. What the browser receives is a signing URL, never the API key.
@Component({
selector: "app-sign",
template: `<iframe *ngIf="url" [src]="url" title="Sign the agreement"></iframe>`,
})
export class SignComponent implements OnInit {
url?: SafeResourceUrl;
constructor(private http: HttpClient, private sanitizer: DomSanitizer) {}
ngOnInit() {
// Your backend creates the document; the browser only receives a URL.
this.http.post<{ signingUrl: string }>("/api/agreements", {}).subscribe((r) => {
this.url = this.sanitizer.bypassSecurityTrustResourceUrl(r.signingUrl);
});
}
}What this ecosystem gets wrong first
- Angular refuses to bind an arbitrary URL into an iframe src, which is a feature rather than an obstacle. bypassSecurityTrustResourceUrl is the deliberate opt-out, and it is only safe because the URL came from your own backend.
- Do not put the API key in environment.ts. That file is bundled and shipped, and "environment" in Angular means build-time configuration, not a server secret.
- HttpClient returns a cold observable, so nothing happens until you subscribe. A create call that appears not to fire is almost always a missing subscribe.
Handling the webhook
When a signer completes, we POST the document id, the completion time, the signer record and the SHA-256 fingerprint of the sealed file to your webhook_url. Verify the signature header against the raw request body before you trust any of it, and respond 2xx quickly: do the slow work afterwards, because a webhook that takes ten seconds to answer is a webhook that gets retried.
The fingerprint in that payload is the same value the public verification page checks against, so you can store it and let anybody confirm a document you hold is the one that was signed.
What you get back
- A sealed PDF, with the signature part of the page rather than an annotation some viewers skip
- An audit certificate naming each signer, the time, the address and which checks they passed
- A SHA-256 fingerprint, and a public verification URL that needs no account to open
- Optional company stamps with serial numbers, applied in the same call
The REST API is included on the Business plan at $15 a month rather than sold as an add-on, which is the part worth comparing: several of the platforms a developer evaluates price the API separately and considerably higher.