Receiving events
Create a webhook endpoint in Flowsign at Settings > Webhooks (my.flowsign.app/settings/webhooks), or with the API (see Webhooks).- In your scenario, add the Webhooks app’s Custom webhook module and create a new webhook.
- Make gives you a webhook URL. Paste it into the endpoint’s Endpoint URL field in Flowsign.
- Tick the events to subscribe to (for example Package completed) and save. Flowsign shows the endpoint’s signing secret once; store it.
POST with four headers and a JSON body:
data differs per event. See Events for every event’s shape.
Verifying the signature
The signature is a hex HMAC-SHA256 of thex-flowsign-timestamp header, a ., and the exact raw body, keyed with the endpoint secret (see Webhooks). Make’s Custom webhook module hands the scenario the parsed body, and re-serialising it isn’t guaranteed to reproduce the bytes Flowsign signed (whitespace and key order can differ), so a Make filter can’t verify the signature reliably.
Two practical options:
- Keep the webhook URL secret. Make generates it for this scenario only. Don’t share it, and if it leaks, create a new webhook in Make and update the endpoint’s Endpoint URL in Flowsign.
- Verify before Make. Point the Flowsign endpoint at a small HTTP endpoint you control (an Azure Function, AWS Lambda or Cloudflare Worker) that checks the signature and timestamp against the raw body, then forwards only valid deliveries to the Make webhook URL.
Calling the API
Use the HTTP app’s Make a request module for any Flowsign API call. Base URL:https://my.flowsign.app. Every request needs:
Create the key at Settings > API keys in the workspace you want to act in; see Authentication.
List packages
Method GET, URLhttps://my.flowsign.app/api/v1/packages?status=IN_PROGRESS.
Create a package from a template
Method POST, URLhttps://my.flowsign.app/api/v1/packages/from-template, body type Raw (JSON):
role must match one of the template’s role names and every role must be filled; fields keys must be merge fields the template asks the sender for. A mismatch returns 422 with the unknown or missing names in details. status is "draft" (default) or "sent", which sends immediately. externalId is optional and makes the call idempotent: retrying with the same value returns the existing package instead of creating a duplicate.

