Zum Hauptinhalt springen
Certyneo
Öffentliche API v1

Integrieren Sie elektronische Signaturen in Ihren Tech-Stack

Versenden Sie Umschläge, verfolgen Sie Signaturen, empfangen Sie Webhooks. Einfache REST-API, OpenAPI 3.0, curl/Node/Python-Beispiele — alles, um Certyneo in wenigen Stunden an Ihr HRIS, CRM oder Geschäftssoftware anzubinden.

Schnelleinstieg

Drei Schritte: Erstellen Sie einen API-Schlüssel in den Einstellungen, kodieren Sie Ihr PDF in Base64, senden Sie es ab. Die Antwort enthält die `signUrl`, die Sie direkt mit dem Empfänger teilen können.

cURLbash
# 1. Upload the PDF (multipart) and capture the returned document id.
DOC_ID=$(curl -s -X POST https://certyneo.com/api/v1/documents \
  -H "Authorization: Bearer sk_live_xxxxxxxxxxxxxxxxxxxxxxxx" \
  -F "file=@contrat.pdf" | jq -r .id)

# 2. Create a DRAFT envelope referencing the uploaded document.
ENV_ID=$(curl -s -X POST https://certyneo.com/api/v1/envelopes \
  -H "Authorization: Bearer sk_live_xxxxxxxxxxxxxxxxxxxxxxxx" \
  -H "Content-Type: application/json" \
  -d "{
    \"subject\": \"Contrat de prestation\",
    \"documentIds\": [\"$DOC_ID\"],
    \"recipients\": [
      { \"email\": \"client@example.com\", \"name\": \"Marie Dubois\", \"role\": \"SIGNER\" }
    ]
  }" | jq -r .id)

# 3. Dispatch the envelope — this sends the invitation email/SMS.
curl -X POST https://certyneo.com/api/v1/envelopes/$ENV_ID/send \
  -H "Authorization: Bearer sk_live_xxxxxxxxxxxxxxxxxxxxxxxx"
JavaScript / Nodets
// npm install @certyneo/sdk  (or call fetch directly)
const auth = { Authorization: `Bearer ${process.env.CERTYNEO_API_KEY}` };

// 1. Upload the PDF (multipart).
const fd = new FormData();
fd.append("file", new Blob([pdfBuffer], { type: "application/pdf" }), "contrat.pdf");
const doc = await fetch("https://certyneo.com/api/v1/documents", {
  method: "POST", headers: auth, body: fd,
}).then((r) => r.json());

// 2. Create the DRAFT envelope.
const envelope = await fetch("https://certyneo.com/api/v1/envelopes", {
  method: "POST",
  headers: { ...auth, "Content-Type": "application/json" },
  body: JSON.stringify({
    subject: "Contrat de prestation",
    documentIds: [doc.id],
    recipients: [
      { email: "client@example.com", name: "Marie Dubois", role: "SIGNER" },
    ],
  }),
}).then((r) => r.json());

// 3. Dispatch — this triggers the invitation channel for every recipient.
await fetch(`https://certyneo.com/api/v1/envelopes/${envelope.id}/send`, {
  method: "POST", headers: auth,
});
console.log(envelope.id);
Pythonpython
import os, requests

auth = {"Authorization": f"Bearer {os.environ['CERTYNEO_API_KEY']}"}

# 1. Upload the PDF (multipart).
with open("contrat.pdf", "rb") as f:
    doc = requests.post(
        "https://certyneo.com/api/v1/documents",
        headers=auth,
        files={"file": ("contrat.pdf", f, "application/pdf")},
    ).json()

# 2. Create the DRAFT envelope.
envelope = requests.post(
    "https://certyneo.com/api/v1/envelopes",
    headers={**auth, "Content-Type": "application/json"},
    json={
        "subject": "Contrat de prestation",
        "documentIds": [doc["id"]],
        "recipients": [
            {"email": "client@example.com", "name": "Marie Dubois", "role": "SIGNER"},
        ],
    },
).json()

# 3. Dispatch — this triggers the invitation channel for every recipient.
requests.post(
    f"https://certyneo.com/api/v1/envelopes/{envelope['id']}/send",
    headers=auth,
)
print(envelope["id"])

Umschläge

Erstellung, Versand, Statusverfolgung, Stornierung. Ein Umschlag kann mehrere Dokumente und mehrere Unterzeichner enthalten (parallel oder sequenziell).

Webhooks

Empfangen Sie `envelope.created`, `envelope.completed`, `envelope.declined` an die URL Ihrer Wahl. HMAC SHA-256 bei jedem Payload zur Überprüfung des Ursprungs.

Einfache Authentifizierung

Bearer Token. Ein Schlüssel pro Umgebung (Test/Produktion). Sofort widerrufbar. Limit 100 Anfragen/Min/Schlüssel, Burst von 200, saubere 429-Antwort mit Retry-After-Header.

Verfügbare Endpoints

12 Routen, die den gesamten Zyklus abdecken: Umschläge, Dokumente, Webhooks, API-Schlüssel. Alle Routen akzeptieren einen Bearer Token und geben JSON zurück.

MethodPathDescription
GET/api/v1/account/meIdentity of the authenticated caller (id, email, plan) — scope-less credential probe
POST/api/v1/documentsUpload a PDF (multipart) — returns document id
GET/api/v1/documentsList documents
GET/api/v1/documents/{id}Fetch document metadata
DELETE/api/v1/documents/{id}Delete document
GET/api/v1/envelopesList envelopes (filter with ?status= and ?limit=)
POST/api/v1/envelopesCreate envelope (status: DRAFT)
GET/api/v1/envelopes/{id}Fetch envelope state
PATCH/api/v1/envelopes/{id}Update DRAFT envelope
DELETE/api/v1/envelopes/{id}Void / delete DRAFT envelope
POST/api/v1/envelopes/{id}/sendDispatch DRAFT — sends invitations
GET/api/v1/envelopes/{id}/audit-trailDownload eIDAS audit-trail PDF
GET/api/v1/envelopes/{id}/signed-documentDownload signed PDF (once COMPLETED)
GET/api/v1/templatesList reusable envelope templates
GET/api/v1/webhooksList webhooks
POST/api/v1/webhooksRegister webhook — returns the signing secret once
GET/api/v1/webhooks/{id}Fetch webhook subscription
PATCH/api/v1/webhooks/{id}Update url / events / active state
DELETE/api/v1/webhooks/{id}Unregister
POST/api/v1/sealsApply a qualified electronic seal to a document
GET/api/v1/seals/{id}Fetch seal status
GET/api/v1/seals/{id}/certificateDownload the seal certificate
GET/api/v1/keysList API keys
POST/api/v1/keysCreate API key — the secret is shown once
PATCH/api/v1/keys/{id}Rename / revoke key
DELETE/api/v1/keys/{id}Delete key
GET/api/v1/billing/usageCurrent period usage and projected cost
GET/api/v1/statusService status
GET/api/v1/openapiMachine-readable OpenAPI specification

Authentifizierung

Jeder Aufruf trägt einen API-Schlüssel im Authorization-Header. Schlüssel werden über Einstellungen → API-Schlüssel generiert und nur einmal angezeigt.

HTTPhttp
GET /api/v1/account/me HTTP/1.1
Host: certyneo.com
Authorization: Bearer sk_live_xxxxxxxxxxxxxxxxxxxxxxxx

# 200 OK
{ "data": { "id": "usr_…", "email": "you@example.com", "plan": "BUSINESS", "environment": "live" } }
  • Format: sk_live_… in der Produktion, sk_test_… für die Sandbox. Header: Authorization: Bearer <Schlüssel>.
  • Bereiche: envelopes, documents, webhooks, seals — im Lese- (:read) oder Schreibmodus (:write). Schreiben impliziert Lesen; der Bereich * gewährt alle Rechte.
  • sk_test_-Schlüssel erstellen Ressourcen in der Sandbox, ausgeschlossen von Kontingent und Abrechnung.
  • Fehler: 401 ungültiger Schlüssel, 403 unzureichender Bereich, 429 Ratengrenze überschritten, 402 monatliches Kontingent erreicht.

Form der Antworten

Ein wichtiger Punkt vor dem Schreiben Ihres Clients: Sammlungen sind in einem data-Objekt gekapselt, während einzelne Ressourcen flach zurückgegeben werden. Das Lesen von response.data.data auf einer einzelnen Ressource gibt daher undefined zurück.

Sammlung — gekapseltjson
// GET /api/v1/envelopes
// Collections are WRAPPED in a "data" array.
{
  "data": [
    { "id": "env_abc123", "subject": "Contrat", "status": "SENT" }
  ]
}
Einzelne Ressource — flachjson
// GET /api/v1/envelopes/{id}
// Single resources are returned FLAT — no "data" envelope.
{
  "id": "env_abc123",
  "subject": "Contrat",
  "status": "COMPLETED",
  "recipients": [ /* … */ ]
}

Durchsatzbegrenzungen

Die Limits garantieren stabilen Service für alle Kunden. Wenn Sie mehr benötigen, kontaktieren Sie uns.

  • 100 Anfragen pro Minute pro API-Schlüssel
  • Burst toleriert bis zu 200 Anfragen in weniger als 10s
  • 429-Antwort mit Retry-After-Header, der die Verzögerung in Sekunden angibt