Skip to main content
You can automate Flowsign with Zapier using Zapier’s own webhook and HTTP steps: trigger a Zap when a package completes, or create and send a package from another system through a Zap.

Receiving events

Create a webhook endpoint in Flowsign at Settings > Webhooks (my.flowsign.app/settings/webhooks), or with the API (see Webhooks).
  1. In your Zap, add Webhooks by Zapier as the trigger app and choose the Catch Hook event.
  2. Zapier gives you a catch URL. Paste it into the endpoint’s Endpoint URL field in Flowsign.
  3. Tick the events to subscribe to (for example Package completed) and save. Flowsign shows the endpoint’s signing secret once; store it.
The endpoint receives events for the packages in the workspace it was created in. Every delivery is a POST with four headers and a JSON body:
data differs per event. See Events for every event’s shape.

Verifying the signature

Skipping verification means your Zap acts on any unauthenticated POST to its catch URL, not just genuine Flowsign deliveries.
Build the signed content from the x-flowsign-timestamp header, a ., and the raw body. Compute its hex HMAC-SHA256 with the endpoint secret and accept the delivery when it matches any v1= entry in x-flowsign-signature and the timestamp is within 5 minutes of your clock (see Webhooks). The Catch Hook event parses the body into fields before your Zap sees it, so re-serialising those fields to JSON isn’t guaranteed to match the exact bytes Flowsign signed (whitespace and key order can differ). For verification that has to match byte-for-byte, use the Catch Raw Hook event instead, which passes the unparsed body and headers through. Add a Code by Zapier step (JavaScript) after the trigger:
Map inputData.rawBody, inputData.timestamp and inputData.signature from the raw hook’s body and its x-flowsign-timestamp and x-flowsign-signature headers, and inputData.secret from a Zapier storage value or environment-style input holding the endpoint secret. Follow with a Filter by Zapier step that only continues when valid is true.

Calling the API

Use Webhooks by Zapier’s Custom Request action for any Flowsign API call. Base URL: https://my.flowsign.app. Every request needs: Create the key at Settings > API keys in the workspace you want to act in; see Authentication.

List packages

Method GET, URL https://my.flowsign.app/api/v1/packages?status=IN_PROGRESS.

Create a package from a template

Method POST, URL https://my.flowsign.app/api/v1/packages/from-template, with a JSON body:
role must match one of the template’s role names and every role must be filled; fields keys must be merge fields the template asks the sender for. A mismatch returns 422 with the unknown or missing names in details. status is "draft" (default) or "sent", which sends immediately. externalId is optional and makes the call idempotent: retrying with the same value returns the existing package instead of creating a duplicate.
Creating requires the key’s role to have the send packages permission and Use access to templates. A key can use any template in its workspace; template sharing does not apply to keys. See Errors for the full status code list.

Plan and cost notes

The Flowsign API and webhooks are included in the Enterprise plan. Creating a webhook endpoint needs the manage webhooks permission. Webhooks by Zapier is a premium Zapier app, so both the Catch Hook trigger and the Custom Request action need a paid Zapier plan.