Repository navigation
Releases: TurboDocx/SDK
Release list
Ruby SDK v0.8.0
TurboSign: embedded signing with identity verification
Sign inside your own app, and choose per recipient how the signer proves who they are.
TurboSign.createSigningUrl(documentId, { recipientId })(or{ externalId }) returns a signing URL to load in your app's iframe.- Per-recipient identity verification on
sendSignature()andcreateSignatureReviewLink(), throughidentityVerification:{ mode: "otp", channel: "email" | "sms" }: the signer enters a one-time passcode before signing.{ mode: "external_idv", provider }: you verify the signer with your own identity provider, then passidentityAssertiontocreateSigningUrl.{ mode: "override", overrideIdentityVerification: true, reason }: the sender confirms the signer's identity, with a recorded reason.- Omit it and nothing changes: no step-up, same as before.
TurboSign.getEmbeddedSigningSettings()reads your organization's embedded signing settings (enabled, allowed embedding domains, which identity modes are allowed) so your app can adapt before it sends.
External identity and override recipients receive a single-use, short-lived signing URL. Passcode and unverified recipients keep the reusable link.
Embedded signing is enabled per organization, and SMS passcodes require a plan that includes them.
TurboSign: optional signer fields
Mark a field required: false and the signer can leave it blank and still finish. Fields are required by default, so existing integrations are unchanged.
TurboSign: conditional fields
Show or require a field only when another field has a given value (IF/THEN), in every SDK.
TurboSign: expiration read-back
The document status response now includes expiresAt when the document has an expiration date.
TurboQuote
- Quote sends accept the same reminder and expiration settings as signature requests.
declineQuoteno longer requires a reason.
Partner API
- Organization display preferences, including
allowDownloadBeforeSigning.
Maintenance
- Dependency and security updates across the SDKs.
Available in the JavaScript/TypeScript, Python, PHP, Java, Go and Ruby SDKs.
Python SDK v0.8.0
TurboSign: embedded signing with identity verification
Sign inside your own app, and choose per recipient how the signer proves who they are.
TurboSign.createSigningUrl(documentId, { recipientId })(or{ externalId }) returns a signing URL to load in your app's iframe.- Per-recipient identity verification on
sendSignature()andcreateSignatureReviewLink(), throughidentityVerification:{ mode: "otp", channel: "email" | "sms" }: the signer enters a one-time passcode before signing.{ mode: "external_idv", provider }: you verify the signer with your own identity provider, then passidentityAssertiontocreateSigningUrl.{ mode: "override", overrideIdentityVerification: true, reason }: the sender confirms the signer's identity, with a recorded reason.- Omit it and nothing changes: no step-up, same as before.
TurboSign.getEmbeddedSigningSettings()reads your organization's embedded signing settings (enabled, allowed embedding domains, which identity modes are allowed) so your app can adapt before it sends.
External identity and override recipients receive a single-use, short-lived signing URL. Passcode and unverified recipients keep the reusable link.
Embedded signing is enabled per organization, and SMS passcodes require a plan that includes them.
TurboSign: optional signer fields
Mark a field required: false and the signer can leave it blank and still finish. Fields are required by default, so existing integrations are unchanged.
TurboSign: conditional fields
Show or require a field only when another field has a given value (IF/THEN), in every SDK.
TurboSign: expiration read-back
The document status response now includes expiresAt when the document has an expiration date.
TurboQuote
- Quote sends accept the same reminder and expiration settings as signature requests.
declineQuoteno longer requires a reason.
Partner API
- Organization display preferences, including
allowDownloadBeforeSigning.
Maintenance
- Dependency and security updates across the SDKs.
Available in the JavaScript/TypeScript, Python, PHP, Java, Go and Ruby SDKs.
PHP SDK v0.8.0
TurboSign: embedded signing with identity verification
Sign inside your own app, and choose per recipient how the signer proves who they are.
TurboSign.createSigningUrl(documentId, { recipientId })(or{ externalId }) returns a signing URL to load in your app's iframe.- Per-recipient identity verification on
sendSignature()andcreateSignatureReviewLink(), throughidentityVerification:{ mode: "otp", channel: "email" | "sms" }: the signer enters a one-time passcode before signing.{ mode: "external_idv", provider }: you verify the signer with your own identity provider, then passidentityAssertiontocreateSigningUrl.{ mode: "override", overrideIdentityVerification: true, reason }: the sender confirms the signer's identity, with a recorded reason.- Omit it and nothing changes: no step-up, same as before.
TurboSign.getEmbeddedSigningSettings()reads your organization's embedded signing settings (enabled, allowed embedding domains, which identity modes are allowed) so your app can adapt before it sends.
External identity and override recipients receive a single-use, short-lived signing URL. Passcode and unverified recipients keep the reusable link.
Embedded signing is enabled per organization, and SMS passcodes require a plan that includes them.
TurboSign: optional signer fields
Mark a field required: false and the signer can leave it blank and still finish. Fields are required by default, so existing integrations are unchanged.
TurboSign: conditional fields
Show or require a field only when another field has a given value (IF/THEN), in every SDK.
TurboSign: expiration read-back
The document status response now includes expiresAt when the document has an expiration date.
TurboQuote
- Quote sends accept the same reminder and expiration settings as signature requests.
declineQuoteno longer requires a reason.
Partner API
- Organization display preferences, including
allowDownloadBeforeSigning.
Maintenance
- Dependency and security updates across the SDKs.
Available in the JavaScript/TypeScript, Python, PHP, Java, Go and Ruby SDKs.
JS SDK v0.8.0
TurboSign: embedded signing with identity verification
Sign inside your own app, and choose per recipient how the signer proves who they are.
TurboSign.createSigningUrl(documentId, { recipientId })(or{ externalId }) returns a signing URL to load in your app's iframe.- Per-recipient identity verification on
sendSignature()andcreateSignatureReviewLink(), throughidentityVerification:{ mode: "otp", channel: "email" | "sms" }: the signer enters a one-time passcode before signing.{ mode: "external_idv", provider }: you verify the signer with your own identity provider, then passidentityAssertiontocreateSigningUrl.{ mode: "override", overrideIdentityVerification: true, reason }: the sender confirms the signer's identity, with a recorded reason.- Omit it and nothing changes: no step-up, same as before.
TurboSign.getEmbeddedSigningSettings()reads your organization's embedded signing settings (enabled, allowed embedding domains, which identity modes are allowed) so your app can adapt before it sends.
External identity and override recipients receive a single-use, short-lived signing URL. Passcode and unverified recipients keep the reusable link.
Embedded signing is enabled per organization, and SMS passcodes require a plan that includes them.
TurboSign: optional signer fields
Mark a field required: false and the signer can leave it blank and still finish. Fields are required by default, so existing integrations are unchanged.
TurboSign: conditional fields
Show or require a field only when another field has a given value (IF/THEN), in every SDK.
TurboSign: expiration read-back
The document status response now includes expiresAt when the document has an expiration date.
TurboQuote
- Quote sends accept the same reminder and expiration settings as signature requests.
declineQuoteno longer requires a reason.
Partner API
- Organization display preferences, including
allowDownloadBeforeSigning.
Maintenance
- Dependency and security updates across the SDKs.
Available in the JavaScript/TypeScript, Python, PHP, Java, Go and Ruby SDKs.
Java SDK v0.8.0
TurboSign: embedded signing with identity verification
Sign inside your own app, and choose per recipient how the signer proves who they are.
TurboSign.createSigningUrl(documentId, { recipientId })(or{ externalId }) returns a signing URL to load in your app's iframe.- Per-recipient identity verification on
sendSignature()andcreateSignatureReviewLink(), throughidentityVerification:{ mode: "otp", channel: "email" | "sms" }: the signer enters a one-time passcode before signing.{ mode: "external_idv", provider }: you verify the signer with your own identity provider, then passidentityAssertiontocreateSigningUrl.{ mode: "override", overrideIdentityVerification: true, reason }: the sender confirms the signer's identity, with a recorded reason.- Omit it and nothing changes: no step-up, same as before.
TurboSign.getEmbeddedSigningSettings()reads your organization's embedded signing settings (enabled, allowed embedding domains, which identity modes are allowed) so your app can adapt before it sends.
External identity and override recipients receive a single-use, short-lived signing URL. Passcode and unverified recipients keep the reusable link.
Embedded signing is enabled per organization, and SMS passcodes require a plan that includes them.
TurboSign: optional signer fields
Mark a field required: false and the signer can leave it blank and still finish. Fields are required by default, so existing integrations are unchanged.
TurboSign: conditional fields
Show or require a field only when another field has a given value (IF/THEN), in every SDK.
TurboSign: expiration read-back
The document status response now includes expiresAt when the document has an expiration date.
TurboQuote
- Quote sends accept the same reminder and expiration settings as signature requests.
declineQuoteno longer requires a reason.
Partner API
- Organization display preferences, including
allowDownloadBeforeSigning.
Maintenance
- Dependency and security updates across the SDKs.
Available in the JavaScript/TypeScript, Python, PHP, Java, Go and Ruby SDKs.
Go SDK v0.8.0
TurboSign: embedded signing with identity verification
Sign inside your own app, and choose per recipient how the signer proves who they are.
TurboSign.createSigningUrl(documentId, { recipientId })(or{ externalId }) returns a signing URL to load in your app's iframe.- Per-recipient identity verification on
sendSignature()andcreateSignatureReviewLink(), throughidentityVerification:{ mode: "otp", channel: "email" | "sms" }: the signer enters a one-time passcode before signing.{ mode: "external_idv", provider }: you verify the signer with your own identity provider, then passidentityAssertiontocreateSigningUrl.{ mode: "override", overrideIdentityVerification: true, reason }: the sender confirms the signer's identity, with a recorded reason.- Omit it and nothing changes: no step-up, same as before.
TurboSign.getEmbeddedSigningSettings()reads your organization's embedded signing settings (enabled, allowed embedding domains, which identity modes are allowed) so your app can adapt before it sends.
External identity and override recipients receive a single-use, short-lived signing URL. Passcode and unverified recipients keep the reusable link.
Embedded signing is enabled per organization, and SMS passcodes require a plan that includes them.
TurboSign: optional signer fields
Mark a field required: false and the signer can leave it blank and still finish. Fields are required by default, so existing integrations are unchanged.
TurboSign: conditional fields
Show or require a field only when another field has a given value (IF/THEN), in every SDK.
TurboSign: expiration read-back
The document status response now includes expiresAt when the document has an expiration date.
TurboQuote
- Quote sends accept the same reminder and expiration settings as signature requests.
declineQuoteno longer requires a reason.
Partner API
- Organization display preferences, including
allowDownloadBeforeSigning.
Maintenance
- Dependency and security updates across the SDKs.
Available in the JavaScript/TypeScript, Python, PHP, Java, Go and Ruby SDKs.
Embed SDK v0.2.1
README only: TurboDocx header and site link, and a developer-first reorganization (install, getting the embedUrl on your server, React <TurboSignForm> first, then the <turbosign-form> web component, the plain handler, and security notes). No code changes from 0.2.0.
npm install @turbodocx/embedCloses #91.
Embed SDK v0.2.0
@turbodocx/embed v0.2.0: first public release
Drop the TurboSign signing experience into your own app. @turbodocx/embed frames a per-recipient embedUrl (from TurboSign.createEmbeddedSignature or TurboSign.createSigningUrl in the TurboDocx server SDKs), pins the message origin, and tells you when the signer finishes, so you don't hand-roll an iframe and a postMessage listener.
npm install @turbodocx/embedThree ways to use it
- React:
<TurboSignForm>from@turbodocx/embed/react(React 18+ peer dependency).import { TurboSignForm } from '@turbodocx/embed/react'; <TurboSignForm embedUrl={embedUrl} origin="https://app.turbodocx.com" onCompleted={({ documentId }) => markSigned(documentId)} />
- Web component:
<turbosign-form embed-url="..." origin="...">, no build step, emits a bubblingturbosign:completedevent. - Plain handler:
handleTurboSignMessagefor your own iframe.
Secure by default
- Fails closed: with no
originset, every message is ignored, soturbosign:completedcan't be spoofed by another page. - Source pinning: only messages from its own iframe are accepted.
allowAnyOriginexists for local development only.
What a completion tells you
documentId, status: "completed", event (signing_complete or already_signed), and scope: "recipient". On multi-signer documents, read the document status server-side or use the completed webhook for the whole document.
The signing page only renders on domains your organization admin has allow-listed under Allowed embedding domains (an empty list means framing is denied everywhere).
PY SDK v0.7.0
TurboSign — reminders and document expiration
sendReminder()
A standalone nudge for a document's outstanding signers (#61). Deliberately decoupled from the automatic schedule: it works even when reminders are disabled or the per-signer cap is spent, and it does not consume that cap.
const { results } = await TurboSign.sendReminder(documentId);
for (const r of results) console.log(`${r.recipientId}: ${r.status}`);
// or nudge specific signers
await TurboSign.sendReminder(documentId, [recipientId]);Only signers at the current signing order are emailed; anyone else comes back as skipped with a reason rather than being silently dropped.
Per-document schedule and expiration
sendSignature() and createSignatureReviewLink() now accept reminder and expiration overrides. Omit a field to inherit the organization default.
await TurboSign.sendSignature({
file, documentName, recipients, fields,
remindersEnabled: true,
reminderDelay: { value: 1, unit: 'days' },
reminderInterval: { value: 2, unit: 'days' },
maxReminders: 3,
expirationEnabled: true,
expireAfter: { value: 14, unit: 'days' },
expirationWarning: { value: 3, unit: 'days' },
expirationWarningInterval: { value: 1, unit: 'days' },
});maxReminders: -1 means unlimited, 0 means none, and it never caps expiry warnings. expirationWarning: { value: 0 } disables warnings entirely.
Available in all six SDKs. Requires a backend that exposes the reminder and schedule endpoints.
Note on reminder counters
A manual sendReminder() stamps lastRemindedAt and increments the recipient's total email count, but deliberately leaves reminderCount untouched — that counter is the automatic cadence's cap budget. Code reading getRecipients() should not treat reminderCount: 0 as "never reminded".
PY SDK v0.6.2
TurboSign — per-recipient signing status
TurboSign.getRecipients(documentId) (#62) returns every recipient on a document with their signing status, alongside a pending/viewed/completed roll-up and per-recipient email delivery history.
const { recipients, summary, document } = await TurboSign.getRecipients(documentId);
console.log(`${summary.completed}/${summary.total} signed, sent by ${document.sentBy.name}`);
const waitingOn = recipients.filter((r) => r.status !== "completed");Each recipient carries status, effectiveStatus (the raw status with the document's terminal state layered on, so a signer on a voided document reads voided), signedOn, signingOrder, and a delivery block with first/last sent timestamps, total emails, and reminder/warning counts.
Available in all six SDKs.
Requires the backend release that ships the endpoint (RapidDocxBackend v1.127.0).
Maintenance
java-sdk: maven-gpg-plugin 3.1.0 → 3.2.8.- Dev-scope advisory clearances for js-yaml and brace-expansion (#65).