Sign a PDF with Java
Send a document for signature from Java with the built-in HttpClient, no external dependency.
Drop your document here and sign it now. PDF, Word and Excel all work: a .docx or .xlsx is laid out in your browser exactly as it was written, so there is nothing to convert first. Add a signature, a date, a company stamp or a watermark, then download it sealed. Free to start, no account, and the file is never uploaded to open it.
Create a document and get a signing link
One POST creates the document, places the fields and returns a signing URL for each signer. The key stays in the environment.
HttpClient client = HttpClient.newHttpClient();
String body = """
{"name":"Services agreement",
"file_url":"https://example.com/agreement.pdf",
"signers":[{"name":"Jane Doe","email":"jane@example.com","role":"client"}],
"webhook_url":"https://example.com/hooks/pdfverified"}
""";
HttpRequest req = HttpRequest.newBuilder(URI.create("https://api.pdfverified.com/v1/documents"))
.header("Authorization", "Bearer " + System.getenv("PDFVERIFIED_API_KEY"))
.header("Content-Type", "application/json")
.timeout(Duration.ofSeconds(30))
.POST(HttpRequest.BodyPublishers.ofString(body))
.build();
HttpResponse<String> res = client.send(req, HttpResponse.BodyHandlers.ofString());
System.out.println(res.body());What this ecosystem gets wrong first
- java.net.http.HttpClient has been in the JDK since 11, so there is no reason to pull in OkHttp or Apache HttpClient for this. Text blocks (the triple-quoted string) need 15 or later.
- In Spring Boot, prefer RestClient or WebClient so you inherit the app’s timeouts, retries and observability rather than configuring them twice.
- HttpClient instances are meant to be reused. Creating one per request leaks connection pools, which shows up as file handle exhaustion under load rather than as an obvious error.
Handling the webhook
When a signer completes, we POST the document id, the completion time, the signer record and the SHA-256 fingerprint of the sealed file to your webhook_url. Verify the signature header against the raw request body before you trust any of it, and respond 2xx quickly: do the slow work afterwards, because a webhook that takes ten seconds to answer is a webhook that gets retried.
The fingerprint in that payload is the same value the public verification page checks against, so you can store it and let anybody confirm a document you hold is the one that was signed.
What you get back
- A sealed PDF, with the signature part of the page rather than an annotation some viewers skip
- An audit certificate naming each signer, the time, the address and which checks they passed
- A SHA-256 fingerprint, and a public verification URL that needs no account to open
- Optional company stamps with serial numbers, applied in the same call
The REST API is included on the Business plan at $15 a month rather than sold as an add-on, which is the part worth comparing: several of the platforms a developer evaluates price the API separately and considerably higher.