# Signdeer API Integration
> Machine-readable implementation instructions for integrating eKYC, form filling, eSigning, document collection, case workflows, and webhooks into a website, WordPress site, mobile app, CRM, ERP, or internal service.

## Agent setup command
Use this instruction source when configuring Signdeer with Codex, Claude, or another coding agent:

set up signdeer - https://signdeer.com/api-documentation/llms.txt

This command points the coding agent to the implementation instructions. It does not grant access to an organization.
The downloadable contracts below are generated from the current application routes and webhook payload contract.

## Canonical documentation
- [API Integration](https://signdeer.com/api-documentation): Human-readable integration guide.
- [OpenAPI contract](https://signdeer.com/api-documentation/openapi.json): Server API paths and request/response schemas.
- [Webhook schema](https://signdeer.com/api-documentation/webhooks.json): Event envelope, headers, signatures, and event data.
- [TypeScript types](https://signdeer.com/api-documentation/types.ts): Copyable types for API and webhook payloads.
- [Postman collection](https://signdeer.com/api-documentation/postman.json): A ready-to-run server API collection.
- [Examples](https://signdeer.com/api-documentation/examples/quickstart.txt): Minimal curl and webhook receiver examples.
- [Signdeer llms.txt](https://signdeer.com/llms.txt): Agent instructions and product entry points.

## Choose one integration surface
1. Website or web application: load the published forms JavaScript SDK and mount it into a stable element.
2. WordPress: install the Signdeer Forms connector and use the [signdeer_forms] shortcode.
3. Android or iOS: use the Capacitor plugin for hybrid apps or the native mobile SDK when the native package is available.
4. Webhooks: receive case events over HTTPS and process the complete JSON event envelope.

## Agent implementation sequence
1. Inspect the host project and choose exactly one integration surface.
2. Use the demo organization and run one complete test journey before replacing demo values.
3. Install only the package or script required by the selected surface.
4. Add environment variables for server-side credentials and webhook secrets.
5. Add webhook signature verification, delivery deduplication, and queue handoff when webhooks are enabled.
6. Run the integration test, verify the response, and report any production steps that remain.

## Authentication boundaries
- Browser SDK: no organization API key; it opens the published customer journey.
- Server API: use Authorization: Bearer TOKEN from a server-side environment variable.
- Webhooks: use the endpoint secret only to verify X-Signdeer-Signature.
- Never copy server API keys, webhook secrets, or private partner keys into browser or mobile application code.

## Website integration contract
Use the current SDK URL shown in the API Integration guide. Mount SigndeerFormsEmbed after the host element exists and pass the Signdeer origin plus the organization slug. Pass p7k only when the integration has a partner key for attribution. Call embed.destroy() when the host page or component unmounts.

The website integration opens Signdeer’s published customer journey for form filling, uploads, eKYC, eSigning, payment, and submission. Do not rebuild that secure journey in the host website.

## Webhook contract
Configure an HTTPS POST endpoint that Signdeer can reach and subscribe only to the case events the receiving system uses. Verify the single X-Signdeer-Signature header as t=<unix_timestamp>,s=<hex_hmac> over timestamp.raw_body using HMAC-SHA256. Persist X-Signdeer-Delivery-Id before side effects, return a 2xx response quickly, and treat delivery as at-least-once.

Available organization case events: case.created, case.sent, case.form_submitted, case.ekyc_verified, case.correction_requested, case.signed, and case.completed.

Every webhook payload includes the event envelope, case, organization, party, subject, participants, forms, documents, signatures, generated file metadata, and event-specific data. Collections are always arrays. Empty arrays are valid state, not errors. Skip them safely and process each object when present. Binary document and PDF contents are not embedded in the webhook.

## Security rules
- Never place organization API keys, webhook secrets, or private partner keys in browser code.
- Treat customer URLs, case data, identity data, signatures, and document metadata as sensitive.
- Validate webhook signatures before parsing or enqueueing business work.
- Use idempotency for retries and X-Signdeer-Delivery-Id for webhook deduplication.
- Select the integration surface from the application architecture before writing code.

## Definition of complete
An integration is complete when the developer can load the correct SDK, run a real test journey, receive a case event, verify the webhook request, handle duplicate delivery, and document production secrets without exposing them to the browser or agent.
