Sign a Task for Non-Member Users

Non-DottedSign members are allowed to sign tasks within DottedSign (referred to as Quick Sign) and related operations, such as reading tasks, adding signatures, and more. To accomplish these actions, users can authenticate using a JWT code (only for non-member users) when requesting the corresponding API, instead of an access token. The following APIs are allowed to be authenticated using a JWT code:

Obtain the JWT code

The JWT code is carried by the share link of a task. Request the Get the Share Link API for the signer, then read the code query parameter out of the returned share_link:

https://www.dottedsign.com/task?code=eyJhbGciOiJIUzUxMiJ9...
                                     ^--- this is the JWT code

Send that value in the Code request header of the APIs listed above. The code is not returned as a separate field of the response, and codes taken from anywhere else, such as the signing link in a notification email, are not supported.

Only signers without a DottedSign account can be authenticated via a JWT code

If the signer already has a DottedSign account, every request authenticated via a JWT code is rejected with the login_required (401_030) error, no matter how the quick sign setting is configured. Such a signer has to sign in first, either by requesting the APIs with an access_token, or by opening the share link in a browser and signing in there.

Ensure that non-member users have given their consent

Before initiating any operations using the JWT code, it is crucial to ensure that signers have read and agreed to the terms of service and privacy policy. Once confirmed, request the Consent to quick sign API to obtain a verify_token. Both the JWT code and the verify_token are required for subsequent operations. The request body (or query parameters) is as follows:

Request Body

{
  "verify_info": {
    "verify_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c"
  }
}

Query Parameters

task_id=37126&verify_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c

Moreover, it is necessary to ensure that subsequent API requests adhere to the following conditions:

  • The requesting IP address remains consistent.
  • The signer refrained from accessing the task through any alternative methods, such as a web browser, following consent.

Did this page help you?