HE SignsSign a more open world.
Developer center

Your application.
Your signing experience.

Prepare an agreement, guide every signer, and keep a verifiable copy. Bring HE Signs into your product with a clear, predictable integration.

Local development release. The database runtime includes personal accounts, MFA, team roles and a full sender workspace, plus email and embedded signing. Optional billing has been tested with fixtures. This page does not indicate that a public service is deployed. Hosting, provider acceptance, international rollout and independent launch review are tracked in the launch guide.

Three steps to a signed agreement

Start with a harmless sample PDF
01

Prepare once

Send a PDF, people, signing order, and assigned fields. Save an idempotency key before creating the agreement so a retry creates one agreement.

02

Choose the experience

Queue an email invitation or open a 15-minute signing session inside your own application. Enroll your application’s exact origin before embedding.

03

Confirm and keep the proof

Receive signed callbacks, confirm completion through your server, and download the proof kit. Each event has a stable ID for safe duplicate handling.

A small integration surface

Credentials stay on your server
Node.js · server

Create, invite, or embed

The same agreement supports email and an embedded signing experience.

import { HESigns } from './server.mjs';

const signs = new HESigns({
  apiKey: process.env.HE_SIGNS_API_KEY
});
const agreement = await signs.createEnvelope(
  preparedAgreement, savedIdempotencyKey
);

// Email is queued, then attempted by a worker.
await signs.invite(agreement.id, 0);

// Or open signing in your application.
const session = await signs.embeddedSession(
  agreement.id, {
    signer: 0,
    parent_origin: 'https://app.example.com'
  }
);
Get it right the first time

Answers that prevent surprises

Where does my API key go?

Keep it on your application server. The browser receives only a short-lived signing URL. Issue separate keys for each environment and grant only the scopes you need.

What if the same event arrives twice?

Verify the signature over the raw body and check its timestamp. Save the event ID with your own update in one transaction. Acknowledge only after that save succeeds.

Does “sent” mean it reached an inbox?

No. A queued delivery has not been attempted. A sent delivery means the mail server accepted it. Recipient inbox delivery is a separate fact.

Does the proof identify the person?

The proof binds document contents, field answers, and recorded actions. This release records private-link possession and, when required, email-code verification. Optional service certificates seal PDFs and configured RFC3161 authorities add timestamp evidence. It does not independently establish legal identity or provide a qualified signature.

What can I prepare?

Up to 10 PDFs totaling 8 MiB and 100 pages, 1–25 people, ordered, parallel or grouped signing, and up to 200 fields: signature, initials, full name, email, signing date, entered date, text, and checkbox. Add conditional answers, supporting-file requests and permitted delegation. Review automatic text or scanned-document placement before sending.

Built to recover

Database runtime capabilities

One committed result

Signing state, completed files, and outgoing events commit together. Concurrent signers coordinate through database locks.

Visible delivery failures

Workers retry with increasing delays. After eight attempts, the job remains available for inspection and deliberate replay.

Controlled access

Scoped, expiring credentials; immediate revocation; monthly usage limits; enrolled embed origins; and a durable event stream.