Sign a PDF with Ruby
Send a document for signature from Ruby or Rails, with the webhook handled by a background job.
Drop your document here and sign it now. PDF, Word and Excel all work: a .docx or .xlsx is laid out in your browser exactly as it was written, so there is nothing to convert first. Add a signature, a date, a company stamp or a watermark, then download it sealed. Free to start, no account, and the file is never uploaded to open it.
Create a document and get a signing link
One POST creates the document, places the fields and returns a signing URL for each signer. The key stays in the environment.
require "net/http"
require "json"
uri = URI("https://api.pdfverified.com/v1/documents")
req = Net::HTTP::Post.new(uri, {
"Authorization" => "Bearer #{ENV.fetch('PDFVERIFIED_API_KEY')}",
"Content-Type" => "application/json"
})
req.body = {
name: "Services agreement",
file_url: "https://example.com/agreement.pdf",
signers: [{ name: "Jane Doe", email: "jane@example.com", role: "client" }],
webhook_url: "https://example.com/hooks/pdfverified"
}.to_json
res = Net::HTTP.start(uri.hostname, uri.port, use_ssl: true, read_timeout: 30) { |http| http.request(req) }
doc = JSON.parse(res.body)
puts doc["id"]What this ecosystem gets wrong first
- ENV.fetch rather than ENV[] so a missing key fails at boot with a clear message instead of sending Bearer to the API and getting a puzzling 401.
- In Rails, do this from an ActiveJob rather than a controller. A signature request is exactly the kind of third-party call that should not be able to make your own request time out.
- Verify the webhook signature before trusting the payload, and remember that Rails will have parsed the body already: use request.raw_post for the HMAC, not the parsed params.
Handling the webhook
When a signer completes, we POST the document id, the completion time, the signer record and the SHA-256 fingerprint of the sealed file to your webhook_url. Verify the signature header against the raw request body before you trust any of it, and respond 2xx quickly: do the slow work afterwards, because a webhook that takes ten seconds to answer is a webhook that gets retried.
The fingerprint in that payload is the same value the public verification page checks against, so you can store it and let anybody confirm a document you hold is the one that was signed.
What you get back
- A sealed PDF, with the signature part of the page rather than an annotation some viewers skip
- An audit certificate naming each signer, the time, the address and which checks they passed
- A SHA-256 fingerprint, and a public verification URL that needs no account to open
- Optional company stamps with serial numbers, applied in the same call
The REST API is included on the Business plan at $15 a month rather than sold as an add-on, which is the part worth comparing: several of the platforms a developer evaluates price the API separately and considerably higher.