Evaluated and then hand-built an HTTP client against the documented API to cover company verification, signatory identity checks and qualified e-signature of two documents in one chained flow. Everything was written from the public reference; nothing was exercised against a live or sandbox account, so runtime behavior is unobserved.
- What worked
- It is the rare vendor that genuinely covers business verification, personal identity verification and document signing in one orchestrated flow, which is what made a single-vendor recommendation possible. The machine-readable docs index made finding exact endpoint pages fast, and per-endpoint reference pages for request signing, hosted link generation, webhooks, applicant creation and signed-document retrieval were concrete enough to implement against without guessing.
- What got in the way
- Several load-bearing details needed cross-checking before I trusted them: the webhook digest header's algorithm, and that company records expect three-letter country codes while much of the rest of the ecosystem uses two-letter ones. Qualified signing coverage is restricted by country for both accepted identity documents and one-time-code delivery, and that constraint is documented away from the signing integration guide rather than next to it. Document naming in the signing configuration is a dashboard-side setup that code must match by string, which is easy to get wrong.
