Receiving events
Create a webhook endpoint in Flowsign at Settings > Webhooks (my.flowsign.app/settings/webhooks), or with the API (see Webhooks).- Create a flow that starts with When an HTTP request is received and save it once so Power Automate generates its URL.
- Paste that URL into the endpoint’s Endpoint URL field in Flowsign.
- Tick the events to subscribe to (for example Package completed) and save. Flowsign shows the endpoint’s signing secret once; store it.
POST with four headers and a JSON body:
data differs per event. See Events for every event’s shape.
Verifying the signature
The signature is a hex HMAC-SHA256 of thex-flowsign-timestamp header, a ., and the exact raw body, keyed with the endpoint secret (see Webhooks). Power Automate’s workflow expression language has no built-in keyed-hash function, and the trigger hands the flow a parsed body whose re-serialised JSON isn’t guaranteed to match the bytes Flowsign signed.
The practical option is to verify before the flow runs. Point the Flowsign endpoint at a small HTTP endpoint you control (an Azure Function is the usual choice) that builds the signed content from the raw body and the x-flowsign-timestamp header, checks it against each v1= entry in x-flowsign-signature, refuses timestamps more than 5 minutes old, and forwards only valid deliveries to the flow’s trigger URL. Keep the trigger URL itself private, since anyone holding it can start the flow.
Calling the API
Use the HTTP action for any Flowsign API call. Base URL:https://my.flowsign.app. Every request needs:
Create the key at Settings > API keys in the workspace you want to act in; see Authentication. Keep it in an environment variable or Azure Key Vault reference rather than typing it into the action.
List packages
Method GET, URIhttps://my.flowsign.app/api/v1/packages?status=IN_PROGRESS.
Create a package from a template
Method POST, URIhttps://my.flowsign.app/api/v1/packages/from-template, body:
role must match one of the template’s role names and every role must be filled; fields keys must be merge fields the template asks the sender for. A mismatch returns 422 with the unknown or missing names in details. status is "draft" (default) or "sent", which sends immediately. externalId is optional and makes the call idempotent: retrying with the same value returns the existing package instead of creating a duplicate.

