> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flowsign.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Flowsign is one word with a lowercase s.
> The REST API base URL is https://my.flowsign.app and every endpoint lives under /api/v1.
> When answering API questions, cite the HTTP method and endpoint path.
> API access needs the Enterprise plan and an API key with the API access permission.

# Make

> Trigger Make scenarios from Flowsign events and create or send packages from a scenario.

You can automate Flowsign with Make using its own **Custom webhook** and **HTTP** modules: trigger a scenario when a package completes, or create and send a package from another system through a scenario.

## Receiving events

Create a webhook endpoint in Flowsign at **Settings > Webhooks** ([my.flowsign.app/settings/webhooks](https://my.flowsign.app/settings/webhooks)), or with the API (see [Webhooks](/webhooks/overview)).

1. In your scenario, add the **Webhooks** app's **Custom webhook** module and create a new webhook.
2. Make gives you a webhook URL. Paste it into the endpoint's **Endpoint URL** field in Flowsign.
3. Tick the events to subscribe to (for example **Package completed**) and save. Flowsign shows the endpoint's signing secret once; store it.

The endpoint receives events for the packages in the workspace it was created in.

Every delivery is a `POST` with four headers and a JSON body:

| Header                   | Value                                                                                                                                                                                            |
| ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `x-flowsign-event`       | The event name, for example `PACKAGE_COMPLETED`                                                                                                                                                  |
| `x-flowsign-delivery-id` | A stable id for this delivery; retries reuse it                                                                                                                                                  |
| `x-flowsign-timestamp`   | When this attempt was signed, in Unix seconds; every attempt gets a fresh one                                                                                                                    |
| `x-flowsign-signature`   | `v1=` followed by the hex HMAC-SHA256 of the timestamp, a `.`, and the raw body, keyed with the endpoint secret. During a secret rotation it carries one comma-separated `v1=` entry per secret. |

```json theme={null}
{
  "event": "PACKAGE_COMPLETED",
  "timestamp": "2026-09-17T03:40:11.000Z",
  "data": {
    "packageId": "pkg_9f3c2e",
    "packageTitle": "Employment agreement: Ana Reid",
    "completedAt": "2026-09-17T03:40:10.884Z",
    "metadata": { "employee_id": "E-1042" }
  }
}
```

`data` differs per event. See [Events](/webhooks/events) for every event's shape.

## Verifying the signature

<Warning>
  Skipping verification means your scenario acts on any unauthenticated `POST` to its webhook URL, not just genuine Flowsign deliveries.
</Warning>

The signature is a hex HMAC-SHA256 of the `x-flowsign-timestamp` header, a `.`, and the exact raw body, keyed with the endpoint secret (see [Webhooks](/webhooks/overview)). Make's **Custom webhook** module hands the scenario the parsed body, and re-serialising it isn't guaranteed to reproduce the bytes Flowsign signed (whitespace and key order can differ), so a Make filter can't verify the signature reliably.

Two practical options:

* **Keep the webhook URL secret.** Make generates it for this scenario only. Don't share it, and if it leaks, create a new webhook in Make and update the endpoint's **Endpoint URL** in Flowsign.
* **Verify before Make.** Point the Flowsign endpoint at a small HTTP endpoint you control (an Azure Function, AWS Lambda or Cloudflare Worker) that checks the signature and timestamp against the raw body, then forwards only valid deliveries to the Make webhook URL.

## Calling the API

Use the **HTTP** app's **Make a request** module for any Flowsign API call.

Base URL: `https://my.flowsign.app`. Every request needs:

| Header           | Value                                                                                                         |
| ---------------- | ------------------------------------------------------------------------------------------------------------- |
| `Authorization`  | `Bearer fsk_your_key_here`                                                                                    |
| `X-Workspace-Id` | Optional. A key always acts in the workspace it was issued for, and this header may only name that workspace. |

Create the key at **Settings > API keys** in the workspace you want to act in; see [Authentication](/api-reference/authentication).

### List packages

Method **GET**, URL `https://my.flowsign.app/api/v1/packages?status=IN_PROGRESS`.

```json theme={null}
{
  "data": {
    "packages": [
      {
        "id": "pkg_9f3c2e",
        "title": "Employment agreement: Ana Reid",
        "status": "IN_PROGRESS",
        "description": null,
        "recipients": [
          { "id": "cmg4v8q2k0002s7xh6k4m1p9c", "name": "Ana Reid", "email": "ana@example.com", "action": "Sign", "actionType": "SIGNER", "delivery": "EMAIL", "roleName": "Employee", "signed": false }
        ],
        "documentsCount": 1,
        "signingProgress": { "completed": 0, "total": 1 },
        "createdAt": "2026-09-17T01:12:44.000Z",
        "updatedAt": "2026-09-17T01:12:50.000Z",
        "expiresAt": null,
        "completedAt": null,
        "templateId": "tmpl_abc123",
        "metadata": { "employee_id": "E-1042" }
      }
    ],
    "totalCount": 1,
    "page": 1,
    "pageSize": 25
  }
}
```

### Create a package from a template

Method **POST**, URL `https://my.flowsign.app/api/v1/packages/from-template`, body type **Raw** (JSON):

```json theme={null}
{
  "templateId": "tmpl_abc123",
  "recipients": [
    { "role": "Employee", "name": "Ana Reid", "email": "ana@example.com" },
    { "role": "Manager", "name": "Ben Toa", "email": "ben@example.com" }
  ],
  "fields": { "start_date": "1 October 2026" },
  "externalId": "order_4471",
  "status": "sent"
}
```

`role` must match one of the template's role names and every role must be filled; `fields` keys must be merge fields the template asks the sender for. A mismatch returns `422` with the unknown or missing names in `details`. `status` is `"draft"` (default) or `"sent"`, which sends immediately. `externalId` is optional and makes the call idempotent: retrying with the same value returns the existing package instead of creating a duplicate.

```json theme={null}
{
  "data": {
    "id": "pkg_9f3c2e",
    "externalId": "order_4471",
    "status": "IN_PROGRESS",
    "recipients": [
      { "id": "cmg4v8q2k0002s7xh6k4m1p9c", "name": "Ana Reid", "email": "ana@example.com", "role": "Employee" },
      { "id": "cmg4v8q2k0003s7xh2b7r5d1w", "name": "Ben Toa", "email": "ben@example.com", "role": "Manager" }
    ]
  }
}
```

Creating requires the key's role to have the send packages permission and Use access to templates. A key can use any template in its workspace; template sharing does not apply to keys. See [Errors](/api-reference/errors) for the full status code list.

## Plan and cost notes

The Flowsign API and webhooks are included in the Enterprise plan. Creating a webhook endpoint needs the manage webhooks permission.

The **Custom webhook** and **HTTP** modules used here are part of Make's free core apps, with no premium gate.
