Receiving events
Create a webhook endpoint in Flowsign at Settings > Webhooks (my.flowsign.app/settings/webhooks), or with the API (see Webhooks).- In your Zap, add Webhooks by Zapier as the trigger app and choose the Catch Hook event.
- Zapier gives you a catch URL. Paste it into the endpoint’s Endpoint URL field in Flowsign.
- Tick the events to subscribe to (for example Package completed) and save. Flowsign shows the endpoint’s signing secret once; store it.
POST with four headers and a JSON body:
data differs per event. See Events for every event’s shape.
Verifying the signature
Build the signed content from thex-flowsign-timestamp header, a ., and the raw body. Compute its hex HMAC-SHA256 with the endpoint secret and accept the delivery when it matches any v1= entry in x-flowsign-signature and the timestamp is within 5 minutes of your clock (see Webhooks). The Catch Hook event parses the body into fields before your Zap sees it, so re-serialising those fields to JSON isn’t guaranteed to match the exact bytes Flowsign signed (whitespace and key order can differ). For verification that has to match byte-for-byte, use the Catch Raw Hook event instead, which passes the unparsed body and headers through.
Add a Code by Zapier step (JavaScript) after the trigger:
inputData.rawBody, inputData.timestamp and inputData.signature from the raw hook’s body and its x-flowsign-timestamp and x-flowsign-signature headers, and inputData.secret from a Zapier storage value or environment-style input holding the endpoint secret. Follow with a Filter by Zapier step that only continues when valid is true.
Calling the API
Use Webhooks by Zapier’s Custom Request action for any Flowsign API call. Base URL:https://my.flowsign.app. Every request needs:
Create the key at Settings > API keys in the workspace you want to act in; see Authentication.
List packages
Method GET, URLhttps://my.flowsign.app/api/v1/packages?status=IN_PROGRESS.
Create a package from a template
Method POST, URLhttps://my.flowsign.app/api/v1/packages/from-template, with a JSON body:
role must match one of the template’s role names and every role must be filled; fields keys must be merge fields the template asks the sender for. A mismatch returns 422 with the unknown or missing names in details. status is "draft" (default) or "sent", which sends immediately. externalId is optional and makes the call idempotent: retrying with the same value returns the existing package instead of creating a duplicate.

