> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flowsign.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Flowsign is one word with a lowercase s.
> The REST API base URL is https://my.flowsign.app and every endpoint lives under /api/v1.
> When answering API questions, cite the HTTP method and endpoint path.
> API access needs the Enterprise plan and an API key with the API access permission.

# Act on a package

> Sends, voids, pauses, resumes or transfers a package, as chosen by `action`. The permission required depends on the action.



## OpenAPI

````yaml /api-reference/openapi.json patch /api/v1/packages/{packageId}
openapi: 3.0.3
info:
  title: Flowsign API
  version: 1.0.0
  description: >-
    Public v1 API for Flowsign. Every endpoint is authenticated with a Bearer
    API key (prefix `fsk_`). Errors use `{ error, details? }`; success responses
    wrap payload data as `{ data }`.


    An organisation is divided into workspaces. A key is issued for one
    workspace and acts there on every request (see `GET /api/v1/workspaces`);
    `X-Workspace-Id` is optional and may only name that workspace. Packages,
    templates, contacts and members are scoped to the key's workspace.
servers:
  - url: https://my.flowsign.app
    description: Production
security:
  - ApiKey: []
paths:
  /api/v1/packages/{packageId}:
    patch:
      tags:
        - Packages
      summary: Act on a package
      description: >-
        Sends, voids, pauses, resumes or transfers a package, as chosen by
        `action`. The permission required depends on the action.
      operationId: patchPackagesByPackageId
      parameters:
        - schema:
            type: string
          required: true
          name: packageId
          in: path
        - schema:
            type: string
            description: >-
              The workspace the key was issued for, as returned by `GET
              /api/v1/workspaces`. Optional: omitting it acts in the key's
              workspace, and any other id is rejected with 401.
          required: false
          name: x-workspace-id
          in: header
      requestBody:
        required: true
        content:
          application/json:
            schema:
              oneOf:
                - type: object
                  properties:
                    action:
                      type: string
                      enum:
                        - send
                      description: >-
                        Send the draft to its recipients and start signing.
                        Every required custom field must be filled first, else
                        422. Requires canSendPackages.
                      example: send
                  required:
                    - action
                - type: object
                  properties:
                    action:
                      type: string
                      enum:
                        - void
                      description: >-
                        End the package early. Recipients are told and their
                        signing links stop working. Requires canVoidPackages.
                      example: void
                    reason:
                      type: string
                      maxLength: 500
                      description: >-
                        Why the package is being voided, up to 500 characters.
                        Kept on the package as `voidReason` and quoted in the
                        email to recipients.
                      example: The role has been withdrawn.
                  required:
                    - action
                - type: object
                  properties:
                    action:
                      type: string
                      enum:
                        - on_hold
                      description: >-
                        Pause an IN_PROGRESS package. Signing links stop working
                        until it is resumed. Requires canVoidPackages.
                      example: on_hold
                  required:
                    - action
                - type: object
                  properties:
                    action:
                      type: string
                      enum:
                        - resume
                      description: >-
                        Resume an ON_HOLD package. The expiry is pushed back by
                        the time spent on hold. Requires canVoidPackages.
                      example: resume
                  required:
                    - action
                - type: object
                  properties:
                    action:
                      type: string
                      enum:
                        - transfer
                      description: >-
                        Hand ownership of the package to another member.
                        Requires being the current owner or canTransferPackages.
                      example: transfer
                    newOwnerId:
                      type: string
                      minLength: 1
                      description: >-
                        The user id of the new owner: an active member of the
                        package's workspace, or the organisation's owner.
                      example: 8f1c2a4e-6b3d-4c9a-9e7f-2d5b1a3c4e6f
                  required:
                    - action
                    - newOwnerId
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    anyOf:
                      - type: object
                        properties:
                          id:
                            type: string
                            description: The package's id.
                            example: cmg4v8q2k0001s7xh3b9d2f6a
                          status:
                            allOf:
                              - $ref: '#/components/schemas/PackageStatus'
                              - description: >-
                                  The package's status after the action:
                                  IN_PROGRESS after send or resume, VOID after
                                  void, ON_HOLD after on_hold.
                        required:
                          - id
                          - status
                      - type: object
                        properties:
                          id:
                            type: string
                            description: The package's id.
                            example: cmg4v8q2k0001s7xh3b9d2f6a
                          newOwnerId:
                            type: string
                            description: The user id the package now belongs to.
                            example: 8f1c2a4e-6b3d-4c9a-9e7f-2d5b1a3c4e6f
                        required:
                          - id
                          - newOwnerId
                required:
                  - data
        '400':
          description: >-
            The body is not valid JSON; send on a package that is not a DRAFT,
            or whose workflow still has an unanswered sender question; transfer
            to a user who is not an active member of the package's workspace
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Missing or invalid API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '402':
          description: Caller's plan does not include this feature (publicApi / webhooks)
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: API key present but caller lacks the required permission
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: >-
            No package with that id that the caller can see at the access level
            the action needs
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: >-
            send while another member holds the package's edit lock, on a
            correction, on a workflow that cannot run as configured, or before
            every document's file has been uploaded; void on a package that has
            already ended; on_hold on a package that is not IN_PROGRESS; resume
            on a package that is not ON_HOLD
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '422':
          description: Request failed schema validation; details keyed by field
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Rate limit exceeded; see `Retry-After`
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    PackageStatus:
      type: string
      enum:
        - DRAFT
        - SCHEDULED
        - IN_PROGRESS
        - COMPLETED
        - DECLINED
        - ON_HOLD
        - VOID
      description: >-
        The package's status. DRAFT is not yet sent; SCHEDULED is queued to send
        at its scheduled time; IN_PROGRESS is out for signing; COMPLETED is
        signed by every signer; DECLINED is refused by a recipient; ON_HOLD is
        paused by the sender; VOID is ended early by the sender or at its
        expiry.
      example: IN_PROGRESS
    Error:
      type: object
      properties:
        error:
          type: string
          description: What went wrong, in plain words.
          example: 'Missing permission: canSendPackages'
        details:
          type: object
          additionalProperties:
            type: array
            items:
              type: string
          description: >-
            Validation problems keyed by field path. Present only on 422
            responses.
          example:
            recipients.0.email:
              - Invalid email
      required:
        - error
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      bearerFormat: fsk_*

````