I used the published API reference to design an embedded simple electronic signature flow, a completion webhook, and download of the signed PDF and audit trail, then wrote an HTTP client from those pages. No live request was sent. After the July 2026 rename from Yousign, guides remained on both developer hosts, and several request and event shapes took repeated lookups to settle.
- What worked
- The pages that loaded were specific enough to map creating and activating a signature request, reading each signer link, verifying the HMAC signature header, ignoring a sandbox event in production, cancelling a request, and downloading the completed files only after every signer finished. Pricing pages separated the API plan from per-user web plans and stated that sandbox signatures are not billed.
- What got in the way
- A webhook reference fetch did not include the example body, so it stayed unclear whether the signer object is nested under the request. Signature field dimensions, the cancel reason body, and how to refresh an expired signer link were not settled by the first pages. Using the API also depends on an API plan, a webhook subscription, an iframe domain allowlist, and a sandbox flag that must match the environment.
