Skip to main content

autosignly

Python client for the Autosignly API - eIDAS electronic signatures and document workflows.

Not published yet. This package is being built. Install from source for now.

Install

pip install autosignly

Requires Python 3.10 or newer.

Quickstart

from autosignly import AutosignlyClient, Signer

with AutosignlyClient(api_key="api_key_...", api_secret="api_sct_...") as client:
    document_id = client.upload_and_sign(
        pdf=open("contract.pdf", "rb").read(),
        document_name="Consulting agreement",
        signers=[
            Signer(
                first_name="Anna",
                last_name="Nowak",
                email="anna@example.com",
                country="PL",
            )
        ],
    )
    print(document_id)

The key and secret decide which environment you are working in. Every environment, production or sandbox, has its own pair, so pointing a script at the sandbox is a matter of swapping credentials.

The secret must stay on your server. It must never be shipped to a browser or a mobile app.

Reading documents

document = client.get_document(document_id)
print(document.status, [s.email for s in document.signers])

for summary in client.iter_documents(status="SIGNED"):
    print(summary.id, summary.name)

Both listing calls take tag_id as well. Several tags narrow the result — a document has to carry all of them — and a tag that does not exist gives an empty page rather than an error:

page = client.list_documents(tag_id=["contracts", "2026"], status="SIGNED")

Downloading the file

A document carries a short-lived link to its file. The link expires, so fetch the document again for a fresh one rather than storing it.

document = client.get_document(document_id)
print(document.file_url)

pdf = client.download_document(document_id)
open("signed.pdf", "wb").write(pdf)

A document that is still being signed can be downloaded as well - it then carries only the signatures collected so far.

Attachments

Files attached to a document are converted to PDF and merged into it when it is sent for signing, behind an index page listing each one with its checksum — so a single signature covers the document and everything attached to it.

Attachments can only be added before the document is sent, so upload it first and send it afterwards instead of using upload_and_sign:

document_id = client.upload_pdf(
    pdf=open("protocol.pdf", "rb").read(),
    document_name="Handover protocol",
)

attachment = client.add_attachment(
    document_id,
    content=open("site-photo.jpg", "rb").read(),
    file_name="site-photo.jpg",
)
print(attachment.order_index, attachment.sha256)

for existing in client.list_attachments(document_id):
    print(existing.file_name, existing.page_count)

client.send_for_signing(document_id, signers=[signer])

An attachment can be dropped again while the document is still unsent:

client.delete_attachment(document_id, attachment.id)

PDF, JPEG and PNG are accepted, recognised from the content rather than the file name. Attachments merge in the order they were added, and can only be changed before the document is sent for signing.

Tags

tag = client.create_tag("contracts")
client.set_document_tags(document_id, tag_ids=[tag.id], names=["2026"])

Setting tags replaces the whole set: tags left out are removed, and names that do not exist yet are added to the company tag pool.

Verifying webhooks

Autosignly signs every delivery. Check the signature against the raw request body, before parsing it - re-serialising the JSON changes the bytes and the signature will not match.

from autosignly import webhooks

webhooks.verify(
    request.body,
    request.headers["X-Webhook-Signature"],
    webhook_key,
    request.headers["X-Webhook-Timestamp"],
)

The signature covers the timestamp as well as the body, and a delivery older than five minutes is rejected even when its signature matches, so a captured request cannot be replayed later.

While a webhook key is being rotated a delivery carries several signatures; it is accepted when any of them matches, so rotation needs no change on your side.

verify raises InvalidSignatureError on a mismatch; webhooks.is_valid(...) returns a boolean instead.

Errors

Every failure raises a subclass of AutosignlyError carrying the HTTP status and the error type returned by the API.

from autosignly import AutosignlyError, NotFoundError

try:
    client.get_document("does-not-exist")
except NotFoundError:
    ...
except AutosignlyError as error:
    print(error.status_code, error.error_type, error.error_id)

Connection problems and server errors are retried automatically, with an exponential backoff and jitter. Client errors are not retried, since repeating a rejected request cannot change its outcome.

Rate limits are retried too, honouring the delay the API asks for. When that delay is longer than a minute the call fails instead of blocking your thread, and RateLimitError.retry_after tells you how long to wait.

The client does not implement a circuit breaker. It runs inside your process, on calls you asked for, so refusing to even attempt one would be surprising - and your own infrastructure is the right place for that policy. Pass your own http_client if you want to add one.

Links

License

Apache-2.0

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

autosignly-0.1.2.tar.gz (16.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

autosignly-0.1.2-py3-none-any.whl (14.6 kB view details)

Uploaded Python 3

File details

Details for the file autosignly-0.1.2.tar.gz.

File metadata

  • Download URL: autosignly-0.1.2.tar.gz
  • Upload date:
  • Size: 16.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for autosignly-0.1.2.tar.gz
Algorithm Hash digest
SHA256 a10220dce56423dfd33ab9e9b9a3e64cdc64e9dec2a4119e93ca83db06ae5f28
MD5 a8bc8347160dd5185ca3e95e9cf6a02f
BLAKE2b-256 f3bf364ccb7593938adbcea90267b75fd2c5911fecc4ef5edb76d90d836180d7

See more details on using hashes here.

Provenance

The following attestation bundles were made for autosignly-0.1.2.tar.gz:

Publisher: publish-python.yml on 16it-pl/autosignly-sdk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file autosignly-0.1.2-py3-none-any.whl.

File metadata

  • Download URL: autosignly-0.1.2-py3-none-any.whl
  • Upload date:
  • Size: 14.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for autosignly-0.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 3e056ffa1033873124b43be3401250190de12819d6f5e0929c47971ec3d892af
MD5 b50ce10331b4d21a332f978d5be523e7
BLAKE2b-256 1107bf6bfb51fef841256a173b2a2fe2ac70fac5d11a6489e5d83d5772f15eac

See more details on using hashes here.

Provenance

The following attestation bundles were made for autosignly-0.1.2-py3-none-any.whl:

Publisher: publish-python.yml on 16it-pl/autosignly-sdk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.1.4

2 files

0.1.3

2 files

This release

0.1.2 This release

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page