Sign a PDF with Flutter
Open a signing session from a Flutter app, in a web view or the system browser.
Drop your document here and sign it now. PDF, Word and Excel all work: a .docx or .xlsx is laid out in your browser exactly as it was written, so there is nothing to convert first. Add a signature, a date, a company stamp or a watermark, then download it sealed. Free to start, no account, and the file is never uploaded to open it.
Create a document and get a signing link
Flutter runs in the browser, so this half belongs on your server. What the browser receives is a signing URL, never the API key.
// Your backend creates the document and returns the signing URL.
final res = await http.post(
Uri.parse("https://your-app.example.com/api/agreements"),
headers: {"Authorization": "Bearer $userSessionToken"},
);
final signingUrl = jsonDecode(res.body)["signingUrl"] as String;
// Then open it. A web view keeps the person in your app.
await Navigator.of(context).push(MaterialPageRoute(
builder: (_) => Scaffold(
appBar: AppBar(title: const Text("Sign the agreement")),
body: WebViewWidget(controller: WebViewController()..loadRequest(Uri.parse(signingUrl))),
),
));What this ecosystem gets wrong first
- A compiled mobile app is not a safe place for an API key either. Anybody can unpack an APK, and strings in a binary are the first thing they look at, so the document is created by your backend as it is on the web.
- On iOS, drawing a signature inside a web view needs the view to receive touch events without the surrounding scroll view stealing them. If the signature pad feels dead, that is usually the cause rather than the page.
- The system browser is the more reliable choice when the flow includes an ID check, because camera permissions in an embedded web view differ between the two platforms and change between OS versions.
Handling the webhook
When a signer completes, we POST the document id, the completion time, the signer record and the SHA-256 fingerprint of the sealed file to your webhook_url. Verify the signature header against the raw request body before you trust any of it, and respond 2xx quickly: do the slow work afterwards, because a webhook that takes ten seconds to answer is a webhook that gets retried.
The fingerprint in that payload is the same value the public verification page checks against, so you can store it and let anybody confirm a document you hold is the one that was signed.
What you get back
- A sealed PDF, with the signature part of the page rather than an annotation some viewers skip
- An audit certificate naming each signer, the time, the address and which checks they passed
- A SHA-256 fingerprint, and a public verification URL that needs no account to open
- Optional company stamps with serial numbers, applied in the same call
The REST API is included on the Business plan at $15 a month rather than sold as an add-on, which is the part worth comparing: several of the platforms a developer evaluates price the API separately and considerably higher.