Skip to main content
You can automate Flowsign with Power Automate using its own HTTP trigger and action: trigger a flow when a package completes, or create and send a package from another system through a flow.

Receiving events

Create a webhook endpoint in Flowsign at Settings > Webhooks (my.flowsign.app/settings/webhooks), or with the API (see Webhooks).
  1. Create a flow that starts with When an HTTP request is received and save it once so Power Automate generates its URL.
  2. Paste that URL into the endpoint’s Endpoint URL field in Flowsign.
  3. Tick the events to subscribe to (for example Package completed) and save. Flowsign shows the endpoint’s signing secret once; store it.
The endpoint receives events for the packages in the workspace it was created in. Every delivery is a POST with four headers and a JSON body:
data differs per event. See Events for every event’s shape.

Verifying the signature

Skipping verification means your flow acts on any unauthenticated POST to its trigger URL, not just genuine Flowsign deliveries.
The signature is a hex HMAC-SHA256 of the x-flowsign-timestamp header, a ., and the exact raw body, keyed with the endpoint secret (see Webhooks). Power Automate’s workflow expression language has no built-in keyed-hash function, and the trigger hands the flow a parsed body whose re-serialised JSON isn’t guaranteed to match the bytes Flowsign signed. The practical option is to verify before the flow runs. Point the Flowsign endpoint at a small HTTP endpoint you control (an Azure Function is the usual choice) that builds the signed content from the raw body and the x-flowsign-timestamp header, checks it against each v1= entry in x-flowsign-signature, refuses timestamps more than 5 minutes old, and forwards only valid deliveries to the flow’s trigger URL. Keep the trigger URL itself private, since anyone holding it can start the flow.

Calling the API

Use the HTTP action for any Flowsign API call. Base URL: https://my.flowsign.app. Every request needs: Create the key at Settings > API keys in the workspace you want to act in; see Authentication. Keep it in an environment variable or Azure Key Vault reference rather than typing it into the action.

List packages

Method GET, URI https://my.flowsign.app/api/v1/packages?status=IN_PROGRESS.

Create a package from a template

Method POST, URI https://my.flowsign.app/api/v1/packages/from-template, body:
role must match one of the template’s role names and every role must be filled; fields keys must be merge fields the template asks the sender for. A mismatch returns 422 with the unknown or missing names in details. status is "draft" (default) or "sent", which sends immediately. externalId is optional and makes the call idempotent: retrying with the same value returns the existing package instead of creating a duplicate.
Creating requires the key’s role to have the send packages permission and Use access to templates. A key can use any template in its workspace; template sharing does not apply to keys. See Errors for the full status code list.

Plan and cost notes

The Flowsign API and webhooks are included in the Enterprise plan. Creating a webhook endpoint needs the manage webhooks permission. Microsoft lists both the HTTP action and the When an HTTP request is received trigger as premium, so a flow using either needs a Power Automate plan that includes premium connectors, not just a Microsoft 365 seat. Check Microsoft’s current licensing before you build.