This document is generated by Apidog. Apidog: All-in-one workspace for API design, document, debug, test, mock
| Source | Event types |
|---|---|
| Envelope actions | envelope.created, envelope.updated, envelope.renamed, envelope.publish_scheduled, envelope.published, envelope.published_by_schedule, envelope.hold, envelope.cancelled, envelope.expired, envelope.signed, envelope.certificate_requested |
| Signer actions | signer.viewed, signer.approved, signer.rejected, signer.cancelled_by_mfa_error, signer.email_mfa_requested, signer.sms_mfa_requested, signer.whatsapp_mfa_requested, signer.pix_mfa_requested |
| Documents | document.published for each document when the envelope is published, and document.signed for each document when the envelope is signed |
{"v":"1","type":"document.signed","envelopeId":"696d0b7f-8e2f-4fb1-9605-72b197ee154d","documentId":"a3f5c1d2-7b8e-4c9a-9e1f-2d3c4b5a6e7f","actionId":"5e6f7a8b-9c0d-4e1f-8a2b-3c4d5e6f7a8b","occurredAt":"2026-10-11T10:43:12.345Z","sha256Original":"9f2c4a7e1b3d5f6a8c0e2b4d6f8a1c3e5b7d9f0a2c4e6b8d1f3a5c7e9b0d2f4a","sha256Signed":"1b3d5f7a9c2e4b6d8f0a3c5e7b9d1f2a4c6e8b0d3f5a7c9e1b2d4f6a8c0e3b5d","tsaTime":"2026-10-11T10:43:11.000Z","tsaAuthority":"Example Timestamp Authority","tsaSerial":"0c4f6a8e2b1d3f5a7c9e","salt":"e4c2a0b8d6f4e2c0a8b6d4f2e0c8a6b4d2f0e8c6a4b2d0f8e6c4a2b0d8f6e4c2"}| Field | Present in | Content |
|---|---|---|
v | all events | Format version, 1. |
type | all events | The event type, from the table above. |
envelopeId | all events | Envelope ID. |
signerId | signer events | Signer ID. |
documentId | document events | Document ID. |
actionId | all events | ID of the action that produced the event. |
occurredAt | all events | When the action happened, in UTC. |
sha256Original | document events | SHA-256 of the original file. |
sha256Signed | document.signed | SHA-256 of the signed file. |
tsaTime, tsaAuthority, tsaSerial | document.signed | The RFC 3161 timestamp embedded in the signed file. |
salt | all events | 32 random bytes, in hex. |
salt keeps anyone who knows an envelope's IDs from rebuilding one of its events and matching the hash.0x00 || entry)0x01 || left || right)0x00 || account root).| Path | Content |
|---|---|
manifest.json | The envelope's anchored events, with their batches, roots and status. |
events/NN-<type>.json | One event's JSON. |
events/NN-<type>.json.ots | Its OpenTimestamps proof. |
tsa/<batch>.tsr | The RFC 3161 timestamp of each batch root. |
README.txt | The verification steps. |
GET /v1/ecm/envelopes/{envelopeId}/anchors. The response lists the envelope's anchored events, oldest first:| Field | Content |
|---|---|
type, occurredAt | Event type and time. |
canonicalJson | The exact JSON that Signater hashed. |
entryHash | SHA-256 of canonicalJson. |
leafIndex, accountRoot | Position of the event in the account tree, and that tree's root. |
batchId, batchRoot | The batch and its root. |
status | pending until Bitcoin confirms the batch, anchored after. |
bitcoinBlockHeight, bitcoinBlockTimeUtc | The confirming block; null while pending. |
ots | The OpenTimestamps proof in base64; null until a calendar accepts the batch. |
batches lists each batch with its root, its RFC 3161 tsaToken in base64 and tsaTime. Events from the last 10 minutes appear after the next batch..json with the .ots of the same name. The manifest has no proof of its own.ots verify events/07-document.signed.json.ots with the OpenTimestamps client. The client checks the block against your own Bitcoin node.canonicalJson to a file as UTF-8 without changing a byte, decode ots from base64 into a file next to it, and verify the pair as above.accountRoot and then batchRoot, and ots info prints each step.openssl ts -reply -in tsa/<batch>.tsr -text.envelope.anchored. Signater sends it when an envelope's events enter a batch, minutes after they happen and before Bitcoin confirms the batch:{
"event_type": "envelope.anchored",
"envelope_id": "696d0b7f-8e2f-4fb1-9605-72b197ee154d",
"batch_id": "c1b9b3e2-4f5e-4a1f-9d6c-2f7e8a9b0c1d",
"account_root": "7d2e9b4c1a6f3e8d5b0c7a2f9e4d1b6c3a8f5e0d7b2c9a4f1e6d3b8c5a0f7e2d",
"account_id": "00cae3c2-8b7c-41b6-b934-6724808fe7f7",
"env": "production"
}account_root is final when it arrives. Write it to the chain you use, with your own key. All envelopes of your account in a batch share one account_root, so record it once per batch_id. An envelope with activity in several batches gets one delivery per batch.status.envelope.anchored requires the Enterprise plan and only fires in production. The delivery rules on the Webhooks page apply.envelope.anchored. Proofs recorded before the change stay valid, and the receipt and the anchors endpoint keep returning them.