> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flowsign.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Flowsign is one word with a lowercase s.
> The REST API base URL is https://my.flowsign.app and every endpoint lives under /api/v1.
> When answering API questions, cite the HTTP method and endpoint path.
> API access needs the Enterprise plan and an API key with the API access permission.

# Add documents to a package

> Adds documents to a DRAFT package and returns an upload URL for each. Requires canSendPackages.



## OpenAPI

````yaml /api-reference/openapi.json post /api/v1/packages/{packageId}/documents
openapi: 3.0.3
info:
  title: Flowsign API
  version: 1.0.0
  description: >-
    Public v1 API for Flowsign. Every endpoint is authenticated with a Bearer
    API key (prefix `fsk_`). Errors use `{ error, details? }`; success responses
    wrap payload data as `{ data }`.


    An organisation is divided into workspaces. A key is issued for one
    workspace and acts there on every request (see `GET /api/v1/workspaces`);
    `X-Workspace-Id` is optional and may only name that workspace. Packages,
    templates, contacts and members are scoped to the key's workspace.
servers:
  - url: https://my.flowsign.app
    description: Production
security:
  - ApiKey: []
paths:
  /api/v1/packages/{packageId}/documents:
    post:
      tags:
        - Packages
      summary: Add documents to a package
      description: >-
        Adds documents to a DRAFT package and returns an upload URL for each.
        Requires canSendPackages.
      operationId: postPackagesByPackageIdDocuments
      parameters:
        - schema:
            type: string
          required: true
          name: packageId
          in: path
        - schema:
            type: string
            description: >-
              The workspace the key was issued for, as returned by `GET
              /api/v1/workspaces`. Optional: omitting it acts in the key's
              workspace, and any other id is rejected with 401.
          required: false
          name: x-workspace-id
          in: header
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                documents:
                  type: array
                  items:
                    type: object
                    properties:
                      fileName:
                        type: string
                        minLength: 1
                        description: >-
                          The PDF's file name. The document's title is the name
                          without its extension, and the name also forms the
                          storage path.
                        example: Employment agreement.pdf
                      pageCount:
                        type: integer
                        minimum: 1
                        description: The number of pages in the PDF, at least 1.
                        example: 4
                      nonce:
                        type: string
                        minLength: 1
                        description: >-
                          A caller-chosen string echoed back on the matching
                          document in the response, so each upload URL can be
                          matched to its file.
                        example: doc-1
                    required:
                      - fileName
                      - pageCount
                      - nonce
                  minItems: 1
                  description: >-
                    The documents to add, in the order they should follow the
                    package's existing documents. At least one.
              required:
                - documents
      responses:
        '201':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: object
                    properties:
                      packageId:
                        type: string
                        description: The package the documents were added to.
                        example: cmg1p4k2a0003v9x0hq7d2e1s
                      documents:
                        type: array
                        items:
                          $ref: '#/components/schemas/UploadedDocument'
                        description: >-
                          One entry per document sent, in the same order, each
                          carrying the `nonce` it was sent with and the
                          `uploadUrl` to PUT its bytes to.
                    required:
                      - packageId
                      - documents
                required:
                  - data
        '400':
          description: The body is not valid JSON, or the package is not a DRAFT
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Missing or invalid API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '402':
          description: Caller's plan does not include this feature (publicApi / webhooks)
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: API key present but caller lacks the required permission
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: No package with that id is visible to the caller with edit access
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: >-
            Another member is editing the package in the app right now; try
            again once they are done
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '422':
          description: Request failed schema validation; details keyed by field
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Rate limit exceeded; see `Retry-After`
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    UploadedDocument:
      type: object
      properties:
        id:
          type: string
          description: The new document's id.
          example: cmg4v8q2k0003s7xhq1w8n5r7
        nonce:
          type: string
          description: The `nonce` given for this document in the request.
          example: doc-1
        filePath:
          type: string
          description: >-
            Where the file is stored once uploaded, under the workspace's
            prefix. Informational: upload through `uploadUrl`.
          example: >-
            cmf9x1a2b0000abcd1e2f3g4h/cmf9x1a2b0001abcd5i6j7k8l/packages/cmg4v8q2k0001s7xh3b9d2f6a/cmg4v8q2k0003s7xhq1w8n5r7-Employment
            agreement.pdf
        uploadUrl:
          type: string
          format: uri
          description: >-
            A single-use signed URL. PUT the file's bytes to it within two hours
            to attach the file.
          example: >-
            https://xyzcompany.supabase.co/storage/v1/object/upload/sign/pdf/cmf9x1a2b0000abcd1e2f3g4h/cmf9x1a2b0001abcd5i6j7k8l/packages/cmg4v8q2k0001s7xh3b9d2f6a/cmg4v8q2k0003s7xhq1w8n5r7-Employment%20agreement.pdf?token=eyJhbGciOiJIUzI1NiJ9.example
      required:
        - id
        - nonce
        - filePath
        - uploadUrl
      description: A document created by an upload request, with the URL its bytes go to.
    Error:
      type: object
      properties:
        error:
          type: string
          description: What went wrong, in plain words.
          example: 'Missing permission: canSendPackages'
        details:
          type: object
          additionalProperties:
            type: array
            items:
              type: string
          description: >-
            Validation problems keyed by field path. Present only on 422
            responses.
          example:
            recipients.0.email:
              - Invalid email
      required:
        - error
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      bearerFormat: fsk_*

````