E-signature and HRIS: connect Lucca to Certyneo
When you prepare an employment contract, an amendment or a certificate, the employees in your Lucca appear among the suggested signers, and their details — job title, start date, department — pre-fill your template's variables. You review every value before sending. The connector is read-only: Certyneo never writes to Lucca.
A Certyneo account and admin access to your Lucca are required. Included in every Certyneo plan at no extra cost. The connector is in beta: testing against a live Lucca is under way.
Why connect Lucca to Certyneo
The integration is for HR teams who keep their personnel records in Lucca and send documents for signature from Certyneo. It removes the double entry without moving your data.
Your employees suggested as signers
Type the first letters of a name when adding a recipient: employees from your Lucca appear next to your Certyneo contacts, with their work e-mail. Nothing is copied into your address book — the directory is read live.
Your HR templates pre-filled
A template that declares the lucca_* variables receives them filled at send time, from the record of the first signer found in Lucca. You can correct anything in the variables dialog before it goes out.
Read-only by design
Certyneo creates, changes and deletes nothing in Lucca. The application you declare only has read rights on the directory, job positions and departments.
Your documents stay in Certyneo
The PDFs, signed or not, and their eIDAS evidence package stay in Certyneo, hosted in the European Union. No document is sent to Lucca.
Which Lucca data pre-fills your templates
Declare these variables in a Certyneo template. At send time they are filled from the record of the first signer found in Lucca by e-mail address. A variable Lucca does not hold stays empty and you fill it in yourself.
| Template variable | What it takes from Lucca |
|---|---|
| {{lucca_first_name}} | The employee's first name, as it appears in their Lucca record. |
| {{lucca_last_name}} | Their last name. |
| {{lucca_email}} | Their work e-mail address. It is also the key that ties the signer to their Lucca record. |
| {{lucca_employee_number}} | Their employee number, useful on payroll documents and certificates. |
| {{lucca_job_title}} | Their job title, taken from their current position. |
| {{lucca_job_start_date}} | The start date of that position, as Lucca returns it. |
| {{lucca_department}} | The department they belong to. |
The job title, start date and department variables need the matching read rights in Lucca. If those are missing, everything else is still pre-filled.
Connect Lucca in 4 steps
Allow five minutes. You need a Certyneo account and admin access to your Lucca: the credentials are created in your own tenant, Certyneo has nothing to issue you.
- 1
Create an application in your Lucca
In Lucca, open Settings → Authentication, SSO and API, then create an application with read rights on employees, job positions and departments. Lucca gives you a client ID and a secret.
- 2
Open Settings → Integrations
In Certyneo, open Settings, then Integrations, and find the Lucca card.
- 3
Paste the address, the ID and the secret
Enter your Lucca address (acme.ilucca.net, for instance), the client ID and the secret, then connect. Certyneo checks all three with Lucca before storing them.
- 4
Declare the variables in a template
Add the lucca_* variables to the templates that need them. On the next send to an employee they arrive pre-filled and you only have to review them.
Security and compliance
The Lucca integration follows the same rules as the rest of Certyneo: encrypted credentials, rights kept to the strict minimum, full disconnection at any time.
- The client secret is encrypted with AES-256-GCM, never stored in clear text nor shown again.
- Certyneo writes nothing to Lucca: no document, no employee, no comment.
- The credentials are checked with Lucca before being stored, and your tenant address is validated: it alone receives the access tokens.
- On disconnection, Certyneo erases its credentials and the suggestions stop. You can also revoke the application in Lucca at any time.
Frequently asked questions
Which Certyneo plan includes the Lucca integration?
Every plan, including the free one, at no extra cost.
Which rights does the application need in Lucca?
Read access to employees, job positions and departments, nothing more. No write right is requested, and none is used.
Can Certyneo file the signed contract in the employee's record?
Not today: the Lucca API offers no way to drop a file there. The signed document and its evidence package stay in Certyneo, where you download or forward them. We will open that as soon as Lucca exposes it.
Which Lucca addresses are accepted?
Tenants on ilucca.net and ilucca.ch, the test and demo environments, and the sandboxes Lucca provides. Certyneo refuses any other address: it is the one that receives your access tokens.
What happens when a value is missing in Lucca?
The variable stays empty and you fill it in the variables dialog, before sending. A missing value never blocks a send.
How do I stop the integration?
On the Lucca card, click Disconnect: Certyneo erases its credentials, employees are no longer suggested and templates are no longer pre-filled. Envelopes already sent are unaffected.
What comes next
The connector deliberately starts read-only. What follows depends on what the Lucca API opens up, and on what the first HR teams ask us for.
The signed document in the personnel record
As soon as the Lucca API allows a file to be filed there, the signed document and its evidence package will join the employee's record.
A send triggered by a new hire
Preparing the contract as soon as an arrival is recorded in Lucca, instead of starting from an empty envelope in Certyneo.
Other HRIS
The next French HRIS will follow the same pattern if the demand is there. Tell us which one matters to you.
Other ways to connect Certyneo to your HR tools
The Lucca connector covers the directory and the pre-fill. For everything else — triggering a send from another tool, pushing a signature status into your HRIS — these three paths already exist.
Zapier and Make
Over 6,000 apps, no code: an “envelope signed” trigger can feed your HRIS, your payroll or your dashboard.
Real-time webhooks
Certyneo calls your system on every signature event — sent, viewed, signed, declined, expired — with a signed request.
REST API
Create envelopes, follow their status and fetch signed documents from your own code. The documentation is at certyneo.com/developers.
Learn more
Get your employees signing without re-typing
Connect your Lucca in five minutes, and keep control of every value before it goes out.