Skip to main content
Certyneo
REST API — eIDAS

The electronic signature API for developers

Integrate eIDAS electronic signatures into your application: REST API, HMAC-signed webhooks, embedded iframe signing and free test keys, even on a free account.

Free test keys · 99.9% SLA (Business and Enterprise) · EU hosting

REST API + OpenAPI

Predictable endpoints, clean JSON, standard HTTP status codes. Downloadable OpenAPI specification to generate your own clients.

Reliable webhooks

5 attempts with increasing delays, HMAC SHA-256 signature, failed events replayable from the dashboard. No polling to code.

Native eIDAS compliance

Simple, advanced (SMS OTP) and qualified signatures, chosen per envelope with the signatureLevel field. A timestamped audit trail is attached to every signed document.

Hosted in the EU

Servers in Germany, France and Spain. Published rate limits per plan and X-RateLimit headers on every response. 99.9% SLA on Business and Enterprise.

Get started in three calls

Upload the PDF, create the envelope, send it: three HTTP requests are all it takes.

cURL — upload, create, send
# 1. Upload the PDF
curl https://certyneo.com/api/v1/documents \
  -H "Authorization: Bearer $CERTYNEO_API_KEY" \
  -F "file=@contrat.pdf"
# → { "id": "cm8doc...", "status": "READY", ... }

# 2. Create the envelope (draft)
curl https://certyneo.com/api/v1/envelopes \
  -H "Authorization: Bearer $CERTYNEO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "subject": "Contrat de prestation",
    "documentIds": ["cm8doc..."],
    "recipients": [{ "email": "client@example.com", "name": "Jane Doe" }]
  }'
# → { "id": "cm8env...", "status": "DRAFT", ... }

# 3. Send the invitations
curl -X POST https://certyneo.com/api/v1/envelopes/cm8env.../send \
  -H "Authorization: Bearer $CERTYNEO_API_KEY"

POST /documents returns the PDF's ID, POST /envelopes creates a draft with its signers, then POST /envelopes/:id/send sends the invitations. Progress then arrives by webhook.

Node.js — native fetch, no dependencies
// Node 18+ — native fetch, no dependency
import { readFile } from "node:fs/promises";

const API = "https://certyneo.com/api/v1";
const auth = { Authorization: `Bearer ${process.env.CERTYNEO_API_KEY}` };

// 1. Upload the PDF
const form = new FormData();
const pdf = new Blob([await readFile("contrat.pdf")], { type: "application/pdf" });
form.append("file", pdf, "contrat.pdf");
const doc = await (await fetch(`${API}/documents`, { method: "POST", headers: auth, body: form })).json();

// 2. Create the envelope (draft)
const envelope = await (await fetch(`${API}/envelopes`, {
  method: "POST",
  headers: { ...auth, "Content-Type": "application/json" },
  body: JSON.stringify({
    subject: "Contrat de prestation",
    documentIds: [doc.id],
    recipients: [{ email: "client@example.com", name: "Jane Doe" }],
  }),
})).json();

// 3. Send the invitations
await fetch(`${API}/envelopes/${envelope.id}/send`, { method: "POST", headers: auth });

No SDK needed: the API works with Node 18's native fetch or any HTTP client. The OpenAPI specification also lets you generate a typed client in your language.

Webhooks — react in real time

Envelope and recipient events, with a verifiable HMAC signature and automatic retry.

envelope.completed
{
  "id": "cm8f2h6a10004qr9k5p2wm3xt",
  "event": "envelope.completed",
  "data": {
    "envelopeId": "cm7x2k9p40001qz8h3f7bn2ld",
    "subject": "Contrat de prestation",
    "status": "COMPLETED",
    "completedAt": "2026-09-26T08:42:13.000Z",
    "recipientCount": 1,
    "recipients": [
      { "email": "client@example.com", "name": "Jane Doe", "role": "SIGNER", "status": "SIGNED" }
    ],
    "signedDocumentUrl": "https://storage.certyneo.com/signed/...pdf?X-Amz-Expires=604800&..."
  },
  "timestamp": "2026-09-26T08:42:13.521Z"
}
  • HMAC SHA-256 signature of each payload — verify authenticity server-side.
  • Automatic retry on a temporary failure: 5 attempts over roughly 1 h 20 with exponential backoff.
  • Failed events are listed in the dashboard and can be replayed in one click. After 5 consecutive failures, the endpoint is suspended and you are notified.
  • Up to 5 endpoints on Standard, 15 on Business and 50 on Business Pro, each subscribed to the events of your choice.

Why a dedicated API for electronic signature?

Integrating electronic signature into your product is not trivial. You need guarantees on legal compliance (eIDAS), technical reliability (webhooks that actually arrive), and data sovereignty (European hosting to avoid the Cloud Act). The Certyneo API covers all three.

Built by and for developers, it follows REST conventions: version in the URL (/api/v1), pagination with page and limit, JSON errors with a machine-readable code, and an OpenAPI specification to generate your clients. No SOAP, no XML, no surprises.

eIDAS compliance explained for developers

The eIDAS regulation defines three signature levels: simple (SES), advanced (AES) and qualified (QES). The Certyneo API lets you choose the level of each envelope with the signatureLevel field: SIMPLE (default), ADVANCED or QUALIFIED. A simple signature covers most everyday commercial contracts; QES is for when a law or a recipient requires equivalence with a handwritten signature.

On the technical side, the advanced level automatically enables SMS OTP and requires a phone number for each signer. The audit trail is timestamped according to the RFC 3161 standard. QES relies on a qualified certificate issued by an EU qualified trust service provider. Everything is driven through the API.

Recommended integration architecture

The most common integration pattern follows this flow:

  • Your backend uploads the PDF (POST /api/v1/documents), creates the envelope as a draft (POST /api/v1/envelopes), then sends it (POST /api/v1/envelopes/:id/send).
  • The signer receives their invitation by email, or signs directly in your interface thanks to embedded iframe signing (POST /api/v1/envelopes/:id/embed-url, from the Standard plan).
  • Once signing is complete, Certyneo calls your webhook with the envelope.completed event.
  • You update your database and notify the user (email, in-app, etc.).

Free test keys

sk_test_ keys are available on every plan, including Free, and test envelopes do not count against your monthly quota. On the Free plan, they can only be sent to your own email address and are limited to 20 requests per hour; paid plans go from 200 to 1,000 requests per hour. Test data is deleted after 30 days. The first test key on a free account also unlocks one month of the Standard plan for free.

If you would rather not write code

Everything this API does can also be driven without a line of code, from a flow: create an envelope, send it, react to a signature, fetch the sealed PDF and its audit trail. The same foundation, with a visual designer instead of an HTTP client. See the Power Automate and Microsoft 365 integration.

Migrate from DocuSign or Yousign

If you already have a DocuSign or Yousign integration, the vocabulary is similar: envelopes → envelopes, recipients → recipients, status webhooks → webhooks. The DocuSign and Yousign to Certyneo migration guide details the steps, from exporting templates to switching over webhooks.

Migrating from Adobe Acrobat Sign (formerly EchoSign, then Adobe Sign)? The mapping is just as direct — agreements → envelopes, participants → recipients, webhooks → webhooks. Compare Certyneo and Adobe Acrobat Sign →

Electronic signature API pricing: where to buy a subscription?

No quote or purchase order is needed to buy an e-signature API subscription: test keys are free, your API key is generated from the dashboard, and production REST API access is included from the Standard plan at €19/month — webhooks included, with no fees per simple signature.

  • Standard — €19/month: 100 envelopes/month, REST API + webhooks, 10 users
  • Business — €39/month: 300 envelopes/month, bulk send, web forms
  • Business Pro — €99/month: 1,000 envelopes/month, high-throughput API (300 req/min), unlimited users

Qualified signatures (QES) are billed per signature and paid at send time: €9.90 per signature with a subscription, charged to the saved card once the QES included in Business and Business Pro are used up, and €14.90 without a subscription.

For large volumes or contractual commitments (SLA, dedicated DPA, annual invoicing), the Enterprise plan is arranged with the sales team. Either way, prices are public — compare them before committing.

Go further

FAQ — API

What is the API rate limit?

The limit applies to each key, per minute, depending on the plan: 60 requests on Standard, 120 on Business, 300 on Business Pro and 1,000 on Enterprise. Every response carries the X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset headers; beyond that, the API returns 429 with a Retry-After header.

How much does the API cost?

Test keys (sk_test_) are free on every plan. Production REST API access is included from the Standard plan at €19/month (100 envelopes/month), then Business at €39/month and Business Pro at €99/month with increasing quotas; qualified signatures (QES) are billed per signature, €9.90 with a subscription. For higher volumes, the Enterprise plan is arranged with the sales team.

Is there an SLA?

Yes: 99.9% monthly availability on the Business and Enterprise plans, with an invoice credit of 10 to 50% depending on the shortfall. Service status is published continuously on the Certyneo status page.

What authentication do you use?

An API key in the Authorization header (Bearer sk_live_… or sk_test_…). Keys are created and revoked from the dashboard, with immediate effect. For a third-party application acting on behalf of your users, OAuth 2.0 is available with the authorization code flow and PKCE.

How do you verify the HMAC signature of a webhook?

Every webhook carries an X-Certyneo-Signature header: the hex-encoded HMAC SHA-256 of the raw request body, computed with your endpoint's secret. Recompute it server-side on the unmodified body and compare in constant time (crypto.timingSafeEqual in Node, hmac.compare_digest in Python).

Is there an official SDK?

Not published yet. The API can be called directly over HTTP from any language, and the OpenAPI specification lets you generate a typed client with openapi-generator or an equivalent tool. Without code, Certyneo is also available on Make, n8n, Postman and RapidAPI.

Can I test without paying?

Yes: create a free account and generate an sk_test_ key from the dashboard. The first test key on a free account also unlocks one month of the Standard plan for free. The Postman collection lets you chain your first calls without writing any code.

How much does the EchoSign API (now Adobe Acrobat Sign) cost?

EchoSign was acquired by Adobe in 2011 and renamed Adobe Sign, then Adobe Acrobat Sign: the API still exists, but its pricing is not public and requires an enterprise quote from Adobe's sales team, usually in tiers of annual transactions. Certyneo, by contrast, displays its prices: production API access is included from the Standard plan at €19/month, subscribed online with no quote, with free test keys to evaluate the API before you pay.

Ready to integrate electronic signatures?

Free test keys, OpenAPI specification, signed webhooks. Get started now.