Sign a PDF with JavaScript
Send a document for signature from Node with fetch, no SDK and no dependencies.
Drop your document here and sign it now. PDF, Word and Excel all work: a .docx or .xlsx is laid out in your browser exactly as it was written, so there is nothing to convert first. Add a signature, a date, a company stamp or a watermark, then download it sealed. Free to start, no account, and the file is never uploaded to open it.
Create a document and get a signing link
One POST creates the document, places the fields and returns a signing URL for each signer. The key stays in the environment.
const res = await fetch("https://api.pdfverified.com/v1/documents", {
method: "POST",
headers: {
"Authorization": "Bearer " + process.env.PDFVERIFIED_API_KEY,
"Content-Type": "application/json",
},
body: JSON.stringify({
name: "Services agreement",
file_url: "https://example.com/agreement.pdf",
signers: [{ name: "Jane Doe", email: "jane@example.com", role: "client" }],
fields: [{ type: "signature", signer: "client", page: 3, x: 0.12, y: 0.68 }],
webhook_url: "https://example.com/hooks/pdfverified",
}),
});
const doc = await res.json();
console.log(doc.id, doc.signing_urls.client);What this ecosystem gets wrong first
- fetch is built into Node 18 and later, so there is nothing to install. On Node 16 you need undici or node-fetch, and that is the most common reason this snippet fails on an older runtime.
- Keep the key in the environment rather than in the repository, and keep this call on the server. A key that reaches the browser is a key anybody can read out of the network tab.
- The response carries a signing URL per signer. Send it yourself, or leave webhook_url set and let us email them and tell you when each one signs.
Handling the webhook
When a signer completes, we POST the document id, the completion time, the signer record and the SHA-256 fingerprint of the sealed file to your webhook_url. Verify the signature header against the raw request body before you trust any of it, and respond 2xx quickly: do the slow work afterwards, because a webhook that takes ten seconds to answer is a webhook that gets retried.
The fingerprint in that payload is the same value the public verification page checks against, so you can store it and let anybody confirm a document you hold is the one that was signed.
What you get back
- A sealed PDF, with the signature part of the page rather than an annotation some viewers skip
- An audit certificate naming each signer, the time, the address and which checks they passed
- A SHA-256 fingerprint, and a public verification URL that needs no account to open
- Optional company stamps with serial numbers, applied in the same call
The REST API is included on the Business plan at $15 a month rather than sold as an add-on, which is the part worth comparing: several of the platforms a developer evaluates price the API separately and considerably higher.