Skip to the content

Developers

The API

A REST API described by an OpenAPI 3.1 file, with scoped keys, idempotent writes and signed webhooks.

Keys and scopes

Make a key under Settings, Developers. Each key carries only the scopes you give it. Send it as a bearer token. A test key only ever touches test documents.

Safe to retry

Writes take an Idempotency-Key header; sending the same key again returns the first answer instead of doing the work twice.

Webhooks

Subscribe an address to document events (sent, signed, completed, declined, voided, expired). Each call is signed in the Standard Webhooks way so you can verify it came from Docustay. Failed calls are retried, every attempt is logged, and you can send any delivery again from the console.

Files

The OpenAPI file is at /api/v1/openapi.json, an interactive reference is at /api/v1/docs, and a Postman collection is in the documentation.

Limits and errors

Requests are rate-limited, and every error has a stable kind and a readable message. See Errors and limits in the docs.

Read the full reference

Guides, the quickstart and the complete reference are in the documentation.

The Developer settings screen with API keys and webhook endpoints
The Developer settings screen with API keys and webhook endpoints

What it covers

Send a document from a template, list and read documents and templates, download the signed copy, read the audit log as CSV, send a reminder, void a document, start an embedded signing session, make a template from HTML or a file, and read reports and teams.

Keys and scopes

Keys have two scopes: documents:read and documents:write. A key can only carry scopes its creator holds. A request with a missing or wrong key or scope gets the same 401 answer, so nothing tells a guesser which half was right.

Writes you can safely retry

Requests that create a document or a template (send, make a template from HTML or from a file) need an Idempotency-Key header. Repeating a request with the same key and body returns the first answer instead of acting again, so a timeout never means two emails.

Lists and errors

Lists take limit and cursor. Errors have one shape with a kind, a message, a request id and a retryable flag. The documentation page on errors and limits has the full table.

List executed documents

curl "https://docustay.app/api/v1/documents?state=executed&limit=20" \
  -H "Authorization: Bearer $DOCUSTAY_KEY"

Keep reading