All integrations

OK!Sign

DOCS & KNOWLEDGE · FILES & DOCS

Documents out for signature, their signed copies, form descriptors, and metadata in the account they connected.

Acts as the person, not as itself

Each user connects their own account. Every call carries both identities — the agent and the person it is acting for — so the agent can never reach past what that individual can already do.

Credentials never touch the agent

Tokens live in the vault and attach server-side at call time. The agent holds a session, not a secret, and revoking access does not mean rotating a key.

Every call on the record

Who asked, which agent acted, which action ran, and the verdict that let it through — one audit trail across every integration, not one per vendor.

What an agent can do

Each action is granted on its own. An agent allowed to read is not thereby allowed to write, and the scope beside each row is what the acting user must have connected for it to run at all.

oksign_delete_briefcase_removeWRITE

Remove a briefcase via DELETE /v1/briefcase/remove. Remove a briefcase and the bundling of its documents, so its signing session can no longer be used. IRREVERSIBLE, and there is no endpoint that restores it. Takes the BRIEFCASE's docid, not a bundled document's. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_delete_document_removeWRITE

Remove a document via DELETE /v1/document/remove. Permanently remove a document from the OK!Sign platform and free its storage. IRREVERSIBLE: OK!Sign publishes no endpoint that restores a removed document and removes nothing automatically, so the account grows until something calls this. REMOVING A DOCUMENT ALSO REMOVES ITS WEBHOOK EVENTS from the platform, so an error you have not read with 'List webhook notifications' is gone with it. Any signing URL already sent to a signer stops working. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_delete_editorexpress_removeWRITE

Remove an EditorExpress session via DELETE /v1/editorexpress/remove. Invalidate an EditorExpress session so its editor URL stops working. IRREVERSIBLE. Any field layout already saved from the editor stays on the document; only the session is destroyed. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_delete_emailattachment_removeWRITE

Remove an email attachment via DELETE /v1/emailattachment/remove. Remove a previously uploaded file from the account's email attachments. THIS ACTION CANNOT CURRENTLY SUCCEED, AND THE FAULT IS OK!SIGN'S. Measured 2026-09-24: called as documented (the x-oksign-attachid header, empty body) the endpoint answers "Missing parameter 'json'." -- a parameter its documentation never mentions. Supply any `json` parameter and it then answers "Invalid format x-oksign-attachid. Found: 'null'" EVEN THOUGH THE HEADER IS SET ON THE SAME REQUEST, so the header is not read at all. Six argument shapes were tried and every one answered 'null': the attachid in the header alone, header plus ?json=<id>, and ?json= carrying {attachid}, [{attachid}] and {id}, with a JSON request body as the sixth. The route itself is NOT the problem and is not missing -- a mistyped noun or verb (/v1/emailattachmentz/remove, /v1/emailattachment/removez) answers "Invalid {noun} and/or {verb}" while the real spelling reaches this handler, so it exists and is broken. It is also the only route in the API that skips OK!Sign's method check: a GET and a PUT reach the same handler a DELETE does. There is no combination that works and no workaround from this side. It is shipped rather than withheld so that the provider's own message reaches you if Betrust fixes it; until then, remove email attachments from the OK!Sign account interface. Reported to Matthew 2026-09-24. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_delete_signexpress_removeWRITE

Remove a SignExpress session via DELETE /v1/signexpress/remove. Invalidate a SignExpress session so its signing URL stops working. The way to withdraw a link that was sent to the wrong person. IRREVERSIBLE -- the session cannot be reinstated, though a new one can be created over the same documents. The documents themselves are untouched. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_get_audittrail_retrieveREAD

Get a document's audit trail via GET /v1/audittrail/retrieve. Retrieve the signed audit trail of a document: every operation performed on it, when, from which IP, with the document's SHA-256 over a stated byte range, plus an RSA signature over the trail itself so it can be shown to have not been edited. ALWAYS RETURNED AS JSON, AND THAT TAKES A PIN. OK!Sign's DEFAULT for this route is a PDF -- measured 2026-09-24, a call with no format header answered application/pdf, 137 KB -- and a PDF is unbounded bytes, which never enter a tool result. The header that selects JSON is `x-oksign-format`, which the connector pins; `accept` DOES NOT WORK and is not the channel, measured in both directions on 2026-09-24: `accept: application/json` still answered application/pdf, and `x-oksign-format: json` answered application/json whatever `accept` said. Neither header is an argument, so a caller cannot reach the PDF form. The JSON carries the same evidence, including the RSA `reasonSignature`. Download the PDF from the OK!Sign account if a counterparty needs that exact artefact. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_get_briefcase_retrieveREAD

Get a briefcase via GET /v1/briefcase/retrieve. Read a briefcase back: the documents in it with their sizes and signature counts, its creation date, its source and its signers. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_get_contacts_retrieveREAD

List contacts via GET /v1/contacts/retrieve. List the account's whole address book: each contact's name, email, mobile, group and acting-as role. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_get_credits_retrieveREAD

Get the credit and storage balance via GET /v1/credits/retrieve. Report the account's remaining signing credits, the date they expire, the subscription type, the storage cap and how much of it is used. THE HONEST PLACE TO CHECK BEFORE A SIGNING CAMPAIGN, because nothing else reports it: no action in this integration consumes a credit, so a balance read here changes only when a human signs. OK!Sign lets the balance go NEGATIVE rather than block service -- documents can still be uploaded and signed on a negative balance -- so a positive number here is not a guarantee and a failure elsewhere is rarely about credits. `quantity` is credits, not documents: a single itsme signature costs 3. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_get_document_existsREAD

Check a document exists via GET /v1/document/exists. Answer whether a docid is still present on the platform, and if it is, its filename and whether it is a template. The cheapest way to tell a removed document from a mistyped docid. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_get_documents_activeREAD

List active documents via GET /v1/documents/active. List every document in the account that is still awaiting signature, with each one's docid, filename, creator, creation date, how many signatures it needs and how many it has. This is the action that turns a filename into the docid every other document action needs. RATE LIMITED TO ONE REQUEST EVERY THREE MINUTES by OK!Sign, which answers 429 on the second. It is a polling endpoint by design; poll a callback URL instead of this action if you need to know sooner. The `status` integer on each row is OK!Sign's own document state (1 active, 12 reusable, 14 template) and is not the envelope status. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_get_documents_signedREAD

List signed documents via GET /v1/documents/signed. List the documents signed inside a time window, newest state first, with the signed copy's docid and the credits each signer consumed. This is the polling alternative to receiving the callback URL when a document is completed. BOTH TIMESTAMPS ARE REQUIRED and OK!Sign answers 'Date cannot be null.' without them. RATE LIMITED TO ONE REQUEST EVERY THREE MINUTES, 429 on the second. The `creditsinfo` on each row is where a completed signature's credit charge appears -- it is the only place this integration can observe credit consumption, because no API call consumes one. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_get_editorexpress_retrieveREAD

Get an EditorExpress session via GET /v1/editorexpress/retrieve. Read an EditorExpress session back by its token: its documents, its options, its return URL and when it expires. THE REPLY NAMES YOUR ORGANIZATIONAL TOKEN in `orgtoken` -- see 'Get a SignExpress session' for why that is returned rather than withheld. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_get_email_templates_retrieveREAD

List email templates via GET /v1/email-templates/retrieve. List the account's email templates with their immutable ids, so a notification can name one instead of carrying its own body. A template id is assigned once and never changes, so it is safe to store. Templates are created in the OK!Sign interface; there is no API that creates one. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_get_formdesc_retrieveREAD

Get a form descriptor via GET /v1/formdesc/retrieve. Read back the form descriptor currently on a document, including any change made in the Document Editor after it was uploaded. The way to detect that a human moved or added a field. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_get_linkedlist_retrieveREAD

Link a source document to its signed copy via GET /v1/linkedlist/retrieve. Given the docid of either a source document or its signed copy, return the other one. Signing produces a NEW docid, so this is how a source document is followed to the signed result without having kept the callback. OK!Sign keeps this link for about 18 months after signing and then drops it. An empty object means either that the document has not been signed, that it was removed from the account, or that the link has aged out -- the reply does not distinguish them. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_get_metadata_retrieveREAD

Get document metadata (detailed) via GET /v1/metadata/retrieve. Retrieve the full metadata of a document: every signature box and form field with its position and completion state, the document's size, page count, last-modified time, lease expiry, and the signers defined on it. OK!SIGN MARKS THIS VERSION DEPRECATED in favour of the v2 form ('Get document metadata (summary)'), which is a different and much smaller shape rather than a newer spelling of this one -- measured 2026-09-24, v1 returns the per-field detail below and v2 returns a summary with a human-readable size. Both are shipped because neither is a superset of the other; prefer v2 unless you need field positions or completion state. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_get_metadata_retrieve_v2READ

Get document metadata (summary) via GET /v2/metadata/retrieve. Retrieve a document's summary metadata: filename, human-readable size, how many signatures it requires and how many are valid, its fields and its signers. The current version of the metadata service, and the only operation in the whole API served under /v2. THE ONLY /v2 ROUTE OK!SIGN SERVES. Measured 2026-09-24: /v2 answers for `metadata/retrieve` and returns an EMPTY BODY for any other noun, while /v3 answers "Only 'v1' version supported." -- so the version segment is not a general API version and nothing else can be reached by changing it. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_get_signexpress_retrieveREAD

Get a SignExpress session via GET /v1/signexpress/retrieve. Read a SignExpress session back by its token: which documents it covers, its signer, its validity period, its return and callback URLs and when it expires. THE REPLY NAMES YOUR ORGANIZATIONAL TOKEN in `orgtoken`. That is the third part of the credential you pasted, and it is returned deliberately rather than withheld: OK!Sign treats it as a namespace label, not a secret -- it sends it in the clear as &orgtoken= on every callback -- and it is useless without the account number and authentication token. The full credential triple IS withheld wherever it appears. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_get_users_retrieveREAD

List account users via GET /v1/users/retrieve. List every user (teammember) on the OK!Sign account with their name, email, role, language, status and immutable signerid. The signerid is what a form descriptor references to make a teammember countersign a document. THIS RETURNS EVERY USER ON THE ACCOUNT, including their email addresses, whichever organizational token the key carries -- the credential is account-wide and there is no narrower form of it. A signerid is immutable once assigned. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_get_webhooks_retrieveREAD

List webhook notifications via GET /v1/webhooks/retrieve. List the notification delivery events OK!Sign recorded in a time window -- which email or SMS was blocked, bounced or deferred, to whom, and why. The polling alternative to receiving them on a webhook URL. BOTH TIMESTAMPS ARE REQUIRED ('Date cannot be null.' without them). RATE LIMITED TO ONE REQUEST EVERY THREE MINUTES, 429 on the second. AN EVENT IS LOST WHEN ITS DOCUMENT IS REMOVED, so read this before 'Remove a document', not after. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_post_briefcase_createWRITE

Create a briefcase via POST /v1/briefcase/create. Bundle several already-uploaded documents into one briefcase so a signer signs the whole set in a single session instead of once per document. Returns the briefcase's own docid. THE BRIEFCASE GETS ITS OWN DOCID, returned as a TOP-LEVEL `docid` field beside `status` rather than inside `reason` -- one of the few replies in this API shaped that way. Use that docid with the briefcase actions, not the docids you bundled. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_post_contacts_removeWRITE

Remove contacts via POST /v1/contacts/remove. Remove contacts from the account's address book by name and email. Returns how many were removed. DESTRUCTIVE ON A POST, WHICH IS THE PROVIDER'S CHOICE OF VERB, not a classification mistake -- OK!Sign serves this as POST /v1/contacts/remove and Agentic Fabriq marks it destructive on what it does, not on its method. IRREVERSIBLE: there is no undo, and a removed contact must be re-added with 'Add or update contacts'. Documents already signed are unaffected. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_post_contacts_uploadWRITE

Add or update contacts via POST /v1/contacts/upload. Add contacts to the account's address book, or update the ones whose email already exists. Returns how many were written. Contacts are what the EditorExpress signer picker offers. SETTING `clean` TO TRUE REPLACES THE ENTIRE ADDRESS BOOK with just the contacts in this call -- every other contact in the account is dropped. Omit it to merge, which is what you almost always want. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_post_editorexpress_createWRITE

Create an EditorExpress session via POST /v1/editorexpress/create. Mint a time-limited URL onto the OK!Sign document editor so a person can place the signature boxes and choose the signers themselves, instead of your application computing field coordinates. Returns the session token and the URL. EITHER THIS CALL OR THE ORGANIZATIONAL TOKEN MUST DEFINE A RETURN URL, or the call is refused -- set one here, or once for the whole key with 'Update the API key's callback URLs'. THE REPLY CARRIES A BEARER EDITOR URL: whoever holds it can edit the document's fields. AN ATTACHMENT CANNOT BE ADDED AFTER A FORM DESCRIPTOR EXISTS on the same document (measured 2026-09-24). EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_post_formdesc_uploadWRITE

Upload a form descriptor via POST /v1/formdesc/upload. Lay a form descriptor over an uploaded document: the signature boxes and form fields, where each one sits, which signer owns it and which signing methods that box offers. THIS IS THE ACTION THAT RETURNS THE SIGNING URLS -- one per signer, in `reason`, each to be sent to its signer. A DESCRIPTOR IS IMMUTABLE, AND THIS ACTION RUNS ONCE PER DOCUMENT. Measured 2026-09-24: a second call on the same docid is refused with "A descriptor is immutable. Please remove the document first (document/remove service) and re-upload document and descriptor." There is no replace and no partial edit -- changing the field layout means removing the document and starting again, which also means the docid changes and any signing URL already sent stops working. A human CAN still move fields in the Document Editor afterwards; read the result back with 'Get a form descriptor'. THE REPLY CARRIES BEARER SIGNING URLS. Each url in `reason` lets whoever holds it sign as that signer, with no further authentication -- that is the design, and sending them is the point of this action. They are NOT withheld by Agentic Fabriq, because doing so would leave this action with no output; treat them as you would a password reset link. UPLOAD THE DOCUMENT FIRST: the docid must already exist. THE DESCRIPTOR CAN BE COPIED FROM THE UI -- open the document in the Document Editor, place the fields, and use the API button to copy the exact JSON. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_post_notifications_uploadWRITE

Upload notifications via POST /v1/notifications/upload. Define the emails and/or SMS messages OK!Sign sends to tell signers a document is ready, including reminders and repeats. OK!Sign appends the signing link to the message itself. A FREE OK!SIGN ACCOUNT MAY SEND ONLY 20 API-TRIGGERED EMAILS in total; past that the messages stop and this action is the one that stops working. Delivery failures do not surface here -- read them with 'List webhook notifications', or receive them on the webhook URL. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_post_orgtokeninfo_updateWRITE

Update the API key's callback URLs via POST /v1/orgtokeninfo/update. Set the default callback, return and webhook URLs for the organizational token this connection's credential carries. Every session and briefcase created with this key falls back to these when it does not name its own. THIS CHANGES SHARED CONFIGURATION, NOT THIS CONNECTION'S. The three URLs belong to the ORGANIZATIONAL TOKEN inside the OK!Sign account, so every other integration, script or person using a key with the same organizational token is redirected too, immediately. ALL THREE FIELDS ARE REQUIRED and the call replaces all three -- there is no partial update and no API that reads the current values back, so record them from the OK!Sign API Console before overwriting them. Setting a return URL here is also the account-wide way to satisfy 'Create an EditorExpress session', which refuses to run without one. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api
oksign_post_signexpress_createWRITE

Create a SignExpress session via POST /v1/signexpress/create. Mint a time-limited signing URL for one named signer over one or more prepared documents, for face-to-face signing or to embed in your own application. Returns the session token and the URL. UPLOAD A FORM DESCRIPTOR FIRST. Without one the call is refused with 'Empty or invalid FormDescriptor (missing signerurls)' and '<signerid> not found in signerurls' -- measured 2026-09-24, and it is the most likely way this action fails. THE REPLY CARRIES A BEARER SIGNING URL: whoever holds it can sign as that signer. It is the output of the action and is not withheld. EVERY OK!SIGN FAILURE IS HTTP 200 AT THE PROVIDER: the reference states "The return code is always 200", and a missing credential, a bad credential, an unknown route, a wrong method and a rejected argument all answer 200 with a FAILED body (measured 2026-09-24). Agentic Fabriq reads the body's "status" field and answers with a real 4xx instead -- 401 for a credential problem, 402 for exhausted credits, 404 for an unknown route, 405 for a wrong method, 400 otherwise -- so the status you see here is ours, derived from the body, and never the provider's. CREDITS ARE BILLED WHEN A SIGNER SIGNS, NOT WHEN THIS ACTION RUNS: measured 2026-09-24 across every operation in this integration, the account balance never moved. The charge lands per signer at signature time and depends on the method chosen there (itsme is 3 credits), so calling these actions is free and only a completed signature is not.

api

Put OK!Sign behind one governed endpoint.

Same permissions, same audit trail, whatever else you connect next.