Receiving events
Create a webhook endpoint in Flowsign at Settings > Webhooks (my.flowsign.app/settings/webhooks), or with the API (see Webhooks).- Add a Webhook node, set it to accept
POST, and activate the workflow so it gets a production URL. - Paste that URL into the endpoint’s Endpoint URL field in Flowsign.
- Tick the events to subscribe to (for example Package completed) and save. Flowsign shows the endpoint’s signing secret once; store it.
POST with four headers and a JSON body:
data differs per event. See Events for every event’s shape.
Verifying the signature
Build the signed content from thex-flowsign-timestamp header, a ., and the raw body. Compute its hex HMAC-SHA256 with the endpoint secret and accept the delivery when it matches any v1= entry in x-flowsign-signature and the timestamp is within 5 minutes of your clock (see Webhooks). n8n parses the body into JSON by default, and re-serialising it back to a string isn’t guaranteed to match the exact bytes Flowsign signed. In the Webhook node’s options, turn on Raw Body so the unparsed body is available at $json.rawBody on the production URL.
Add a Crypto node next, with Action set to Hmac, Type set to SHA256, Value set to {{ $json.headers["x-flowsign-timestamp"] }}.{{ $json.rawBody }}, Encoding set to hex, and the secret in its Crypto credential. Follow it with an IF node checking that the Webhook node’s x-flowsign-signature header contains v1= followed by the Crypto node’s output, and stop the workflow on the false branch. The IF node does not check the timestamp; use the Code node below when you want that too.
To do the same in a Code node instead:
Calling the API
Use the HTTP Request node for any Flowsign API call. Base URL:https://my.flowsign.app. Every request needs:
Create the key at Settings > API keys in the workspace you want to act in; see Authentication. Store it in an n8n credential (Header Auth, with
Authorization as the header name and Bearer fsk_your_key_here as the value) rather than pasting it into the node.
List packages
Method GET, URLhttps://my.flowsign.app/api/v1/packages?status=IN_PROGRESS.
Create a package from a template
Method POST, URLhttps://my.flowsign.app/api/v1/packages/from-template, body type JSON:
role must match one of the template’s role names and every role must be filled; fields keys must be merge fields the template asks the sender for. A mismatch returns 422 with the unknown or missing names in details. status is "draft" (default) or "sent", which sends immediately. externalId is optional and makes the call idempotent: retrying with the same value returns the existing package instead of creating a duplicate.

