Skip to main content
You can automate Flowsign with n8n using its own Webhook and HTTP Request nodes: trigger a workflow when a package completes, or create and send a package from another system through a workflow.

Receiving events

Create a webhook endpoint in Flowsign at Settings > Webhooks (my.flowsign.app/settings/webhooks), or with the API (see Webhooks).
  1. Add a Webhook node, set it to accept POST, and activate the workflow so it gets a production URL.
  2. Paste that URL into the endpoint’s Endpoint URL field in Flowsign.
  3. Tick the events to subscribe to (for example Package completed) and save. Flowsign shows the endpoint’s signing secret once; store it.
The endpoint receives events for the packages in the workspace it was created in. Every delivery is a POST with four headers and a JSON body:
data differs per event. See Events for every event’s shape.

Verifying the signature

Skipping verification means your workflow acts on any unauthenticated POST to its webhook URL, not just genuine Flowsign deliveries.
Build the signed content from the x-flowsign-timestamp header, a ., and the raw body. Compute its hex HMAC-SHA256 with the endpoint secret and accept the delivery when it matches any v1= entry in x-flowsign-signature and the timestamp is within 5 minutes of your clock (see Webhooks). n8n parses the body into JSON by default, and re-serialising it back to a string isn’t guaranteed to match the exact bytes Flowsign signed. In the Webhook node’s options, turn on Raw Body so the unparsed body is available at $json.rawBody on the production URL. Add a Crypto node next, with Action set to Hmac, Type set to SHA256, Value set to {{ $json.headers["x-flowsign-timestamp"] }}.{{ $json.rawBody }}, Encoding set to hex, and the secret in its Crypto credential. Follow it with an IF node checking that the Webhook node’s x-flowsign-signature header contains v1= followed by the Crypto node’s output, and stop the workflow on the false branch. The IF node does not check the timestamp; use the Code node below when you want that too. To do the same in a Code node instead:

Calling the API

Use the HTTP Request node for any Flowsign API call. Base URL: https://my.flowsign.app. Every request needs: Create the key at Settings > API keys in the workspace you want to act in; see Authentication. Store it in an n8n credential (Header Auth, with Authorization as the header name and Bearer fsk_your_key_here as the value) rather than pasting it into the node.

List packages

Method GET, URL https://my.flowsign.app/api/v1/packages?status=IN_PROGRESS.

Create a package from a template

Method POST, URL https://my.flowsign.app/api/v1/packages/from-template, body type JSON:
role must match one of the template’s role names and every role must be filled; fields keys must be merge fields the template asks the sender for. A mismatch returns 422 with the unknown or missing names in details. status is "draft" (default) or "sent", which sends immediately. externalId is optional and makes the call idempotent: retrying with the same value returns the existing package instead of creating a duplicate.
Creating requires the key’s role to have the send packages permission and Use access to templates. A key can use any template in its workspace; template sharing does not apply to keys. See Errors for the full status code list.

Plan and cost notes

The Flowsign API and webhooks are included in the Enterprise plan. Creating a webhook endpoint needs the manage webhooks permission. The Webhook, HTTP Request and Crypto nodes are core n8n nodes with no premium gate, on n8n Cloud or self-hosted.