Skip to content

Releases: TurboDocx/SDK

Ruby SDK v0.8.0

Choose a tag to compare

@nicolasiscoding nicolasiscoding released this 07 Oct 02:37
476707f

TurboSign: embedded signing with identity verification

Sign inside your own app, and choose per recipient how the signer proves who they are.

  • TurboSign.createSigningUrl(documentId, { recipientId }) (or { externalId }) returns a signing URL to load in your app's iframe.
  • Per-recipient identity verification on sendSignature() and createSignatureReviewLink(), through identityVerification:
    • { mode: "otp", channel: "email" | "sms" }: the signer enters a one-time passcode before signing.
    • { mode: "external_idv", provider }: you verify the signer with your own identity provider, then pass identityAssertion to createSigningUrl.
    • { mode: "override", overrideIdentityVerification: true, reason }: the sender confirms the signer's identity, with a recorded reason.
    • Omit it and nothing changes: no step-up, same as before.
  • TurboSign.getEmbeddedSigningSettings() reads your organization's embedded signing settings (enabled, allowed embedding domains, which identity modes are allowed) so your app can adapt before it sends.

External identity and override recipients receive a single-use, short-lived signing URL. Passcode and unverified recipients keep the reusable link.

Embedded signing is enabled per organization, and SMS passcodes require a plan that includes them.

TurboSign: optional signer fields

Mark a field required: false and the signer can leave it blank and still finish. Fields are required by default, so existing integrations are unchanged.

TurboSign: conditional fields

Show or require a field only when another field has a given value (IF/THEN), in every SDK.

TurboSign: expiration read-back

The document status response now includes expiresAt when the document has an expiration date.

TurboQuote

  • Quote sends accept the same reminder and expiration settings as signature requests.
  • declineQuote no longer requires a reason.

Partner API

  • Organization display preferences, including allowDownloadBeforeSigning.

Maintenance

  • Dependency and security updates across the SDKs.

Available in the JavaScript/TypeScript, Python, PHP, Java, Go and Ruby SDKs.

Python SDK v0.8.0

Choose a tag to compare

@nicolasiscoding nicolasiscoding released this 07 Oct 02:37
476707f

TurboSign: embedded signing with identity verification

Sign inside your own app, and choose per recipient how the signer proves who they are.

  • TurboSign.createSigningUrl(documentId, { recipientId }) (or { externalId }) returns a signing URL to load in your app's iframe.
  • Per-recipient identity verification on sendSignature() and createSignatureReviewLink(), through identityVerification:
    • { mode: "otp", channel: "email" | "sms" }: the signer enters a one-time passcode before signing.
    • { mode: "external_idv", provider }: you verify the signer with your own identity provider, then pass identityAssertion to createSigningUrl.
    • { mode: "override", overrideIdentityVerification: true, reason }: the sender confirms the signer's identity, with a recorded reason.
    • Omit it and nothing changes: no step-up, same as before.
  • TurboSign.getEmbeddedSigningSettings() reads your organization's embedded signing settings (enabled, allowed embedding domains, which identity modes are allowed) so your app can adapt before it sends.

External identity and override recipients receive a single-use, short-lived signing URL. Passcode and unverified recipients keep the reusable link.

Embedded signing is enabled per organization, and SMS passcodes require a plan that includes them.

TurboSign: optional signer fields

Mark a field required: false and the signer can leave it blank and still finish. Fields are required by default, so existing integrations are unchanged.

TurboSign: conditional fields

Show or require a field only when another field has a given value (IF/THEN), in every SDK.

TurboSign: expiration read-back

The document status response now includes expiresAt when the document has an expiration date.

TurboQuote

  • Quote sends accept the same reminder and expiration settings as signature requests.
  • declineQuote no longer requires a reason.

Partner API

  • Organization display preferences, including allowDownloadBeforeSigning.

Maintenance

  • Dependency and security updates across the SDKs.

Available in the JavaScript/TypeScript, Python, PHP, Java, Go and Ruby SDKs.

PHP SDK v0.8.0

Choose a tag to compare

@nicolasiscoding nicolasiscoding released this 07 Oct 02:37
476707f

TurboSign: embedded signing with identity verification

Sign inside your own app, and choose per recipient how the signer proves who they are.

  • TurboSign.createSigningUrl(documentId, { recipientId }) (or { externalId }) returns a signing URL to load in your app's iframe.
  • Per-recipient identity verification on sendSignature() and createSignatureReviewLink(), through identityVerification:
    • { mode: "otp", channel: "email" | "sms" }: the signer enters a one-time passcode before signing.
    • { mode: "external_idv", provider }: you verify the signer with your own identity provider, then pass identityAssertion to createSigningUrl.
    • { mode: "override", overrideIdentityVerification: true, reason }: the sender confirms the signer's identity, with a recorded reason.
    • Omit it and nothing changes: no step-up, same as before.
  • TurboSign.getEmbeddedSigningSettings() reads your organization's embedded signing settings (enabled, allowed embedding domains, which identity modes are allowed) so your app can adapt before it sends.

External identity and override recipients receive a single-use, short-lived signing URL. Passcode and unverified recipients keep the reusable link.

Embedded signing is enabled per organization, and SMS passcodes require a plan that includes them.

TurboSign: optional signer fields

Mark a field required: false and the signer can leave it blank and still finish. Fields are required by default, so existing integrations are unchanged.

TurboSign: conditional fields

Show or require a field only when another field has a given value (IF/THEN), in every SDK.

TurboSign: expiration read-back

The document status response now includes expiresAt when the document has an expiration date.

TurboQuote

  • Quote sends accept the same reminder and expiration settings as signature requests.
  • declineQuote no longer requires a reason.

Partner API

  • Organization display preferences, including allowDownloadBeforeSigning.

Maintenance

  • Dependency and security updates across the SDKs.

Available in the JavaScript/TypeScript, Python, PHP, Java, Go and Ruby SDKs.

JS SDK v0.8.0

Choose a tag to compare

@nicolasiscoding nicolasiscoding released this 07 Oct 02:37
476707f

TurboSign: embedded signing with identity verification

Sign inside your own app, and choose per recipient how the signer proves who they are.

  • TurboSign.createSigningUrl(documentId, { recipientId }) (or { externalId }) returns a signing URL to load in your app's iframe.
  • Per-recipient identity verification on sendSignature() and createSignatureReviewLink(), through identityVerification:
    • { mode: "otp", channel: "email" | "sms" }: the signer enters a one-time passcode before signing.
    • { mode: "external_idv", provider }: you verify the signer with your own identity provider, then pass identityAssertion to createSigningUrl.
    • { mode: "override", overrideIdentityVerification: true, reason }: the sender confirms the signer's identity, with a recorded reason.
    • Omit it and nothing changes: no step-up, same as before.
  • TurboSign.getEmbeddedSigningSettings() reads your organization's embedded signing settings (enabled, allowed embedding domains, which identity modes are allowed) so your app can adapt before it sends.

External identity and override recipients receive a single-use, short-lived signing URL. Passcode and unverified recipients keep the reusable link.

Embedded signing is enabled per organization, and SMS passcodes require a plan that includes them.

TurboSign: optional signer fields

Mark a field required: false and the signer can leave it blank and still finish. Fields are required by default, so existing integrations are unchanged.

TurboSign: conditional fields

Show or require a field only when another field has a given value (IF/THEN), in every SDK.

TurboSign: expiration read-back

The document status response now includes expiresAt when the document has an expiration date.

TurboQuote

  • Quote sends accept the same reminder and expiration settings as signature requests.
  • declineQuote no longer requires a reason.

Partner API

  • Organization display preferences, including allowDownloadBeforeSigning.

Maintenance

  • Dependency and security updates across the SDKs.

Available in the JavaScript/TypeScript, Python, PHP, Java, Go and Ruby SDKs.

Java SDK v0.8.0

Choose a tag to compare

@nicolasiscoding nicolasiscoding released this 07 Oct 02:37
476707f

TurboSign: embedded signing with identity verification

Sign inside your own app, and choose per recipient how the signer proves who they are.

  • TurboSign.createSigningUrl(documentId, { recipientId }) (or { externalId }) returns a signing URL to load in your app's iframe.
  • Per-recipient identity verification on sendSignature() and createSignatureReviewLink(), through identityVerification:
    • { mode: "otp", channel: "email" | "sms" }: the signer enters a one-time passcode before signing.
    • { mode: "external_idv", provider }: you verify the signer with your own identity provider, then pass identityAssertion to createSigningUrl.
    • { mode: "override", overrideIdentityVerification: true, reason }: the sender confirms the signer's identity, with a recorded reason.
    • Omit it and nothing changes: no step-up, same as before.
  • TurboSign.getEmbeddedSigningSettings() reads your organization's embedded signing settings (enabled, allowed embedding domains, which identity modes are allowed) so your app can adapt before it sends.

External identity and override recipients receive a single-use, short-lived signing URL. Passcode and unverified recipients keep the reusable link.

Embedded signing is enabled per organization, and SMS passcodes require a plan that includes them.

TurboSign: optional signer fields

Mark a field required: false and the signer can leave it blank and still finish. Fields are required by default, so existing integrations are unchanged.

TurboSign: conditional fields

Show or require a field only when another field has a given value (IF/THEN), in every SDK.

TurboSign: expiration read-back

The document status response now includes expiresAt when the document has an expiration date.

TurboQuote

  • Quote sends accept the same reminder and expiration settings as signature requests.
  • declineQuote no longer requires a reason.

Partner API

  • Organization display preferences, including allowDownloadBeforeSigning.

Maintenance

  • Dependency and security updates across the SDKs.

Available in the JavaScript/TypeScript, Python, PHP, Java, Go and Ruby SDKs.

Go SDK v0.8.0

Choose a tag to compare

@nicolasiscoding nicolasiscoding released this 07 Oct 02:37
476707f

TurboSign: embedded signing with identity verification

Sign inside your own app, and choose per recipient how the signer proves who they are.

  • TurboSign.createSigningUrl(documentId, { recipientId }) (or { externalId }) returns a signing URL to load in your app's iframe.
  • Per-recipient identity verification on sendSignature() and createSignatureReviewLink(), through identityVerification:
    • { mode: "otp", channel: "email" | "sms" }: the signer enters a one-time passcode before signing.
    • { mode: "external_idv", provider }: you verify the signer with your own identity provider, then pass identityAssertion to createSigningUrl.
    • { mode: "override", overrideIdentityVerification: true, reason }: the sender confirms the signer's identity, with a recorded reason.
    • Omit it and nothing changes: no step-up, same as before.
  • TurboSign.getEmbeddedSigningSettings() reads your organization's embedded signing settings (enabled, allowed embedding domains, which identity modes are allowed) so your app can adapt before it sends.

External identity and override recipients receive a single-use, short-lived signing URL. Passcode and unverified recipients keep the reusable link.

Embedded signing is enabled per organization, and SMS passcodes require a plan that includes them.

TurboSign: optional signer fields

Mark a field required: false and the signer can leave it blank and still finish. Fields are required by default, so existing integrations are unchanged.

TurboSign: conditional fields

Show or require a field only when another field has a given value (IF/THEN), in every SDK.

TurboSign: expiration read-back

The document status response now includes expiresAt when the document has an expiration date.

TurboQuote

  • Quote sends accept the same reminder and expiration settings as signature requests.
  • declineQuote no longer requires a reason.

Partner API

  • Organization display preferences, including allowDownloadBeforeSigning.

Maintenance

  • Dependency and security updates across the SDKs.

Available in the JavaScript/TypeScript, Python, PHP, Java, Go and Ruby SDKs.

Embed SDK v0.2.1

Choose a tag to compare

@nicolasiscoding nicolasiscoding released this 07 Oct 12:38
be2c940

README only: TurboDocx header and site link, and a developer-first reorganization (install, getting the embedUrl on your server, React <TurboSignForm> first, then the <turbosign-form> web component, the plain handler, and security notes). No code changes from 0.2.0.

npm install @turbodocx/embed

Closes #91.

Embed SDK v0.2.0

Choose a tag to compare

@nicolasiscoding nicolasiscoding released this 07 Oct 11:23
707f725

@turbodocx/embed v0.2.0: first public release

Drop the TurboSign signing experience into your own app. @turbodocx/embed frames a per-recipient embedUrl (from TurboSign.createEmbeddedSignature or TurboSign.createSigningUrl in the TurboDocx server SDKs), pins the message origin, and tells you when the signer finishes, so you don't hand-roll an iframe and a postMessage listener.

npm install @turbodocx/embed

Three ways to use it

  • React: <TurboSignForm> from @turbodocx/embed/react (React 18+ peer dependency).
    import { TurboSignForm } from '@turbodocx/embed/react';
    
    <TurboSignForm
      embedUrl={embedUrl}
      origin="https://app.turbodocx.com"
      onCompleted={({ documentId }) => markSigned(documentId)}
    />
  • Web component: <turbosign-form embed-url="..." origin="...">, no build step, emits a bubbling turbosign:completed event.
  • Plain handler: handleTurboSignMessage for your own iframe.

Secure by default

  • Fails closed: with no origin set, every message is ignored, so turbosign:completed can't be spoofed by another page.
  • Source pinning: only messages from its own iframe are accepted.
  • allowAnyOrigin exists for local development only.

What a completion tells you

documentId, status: "completed", event (signing_complete or already_signed), and scope: "recipient". On multi-signer documents, read the document status server-side or use the completed webhook for the whole document.

The signing page only renders on domains your organization admin has allow-listed under Allowed embedding domains (an empty list means framing is denied everywhere).

PY SDK v0.7.0

Choose a tag to compare

@nicolasiscoding nicolasiscoding released this 11 Aug 20:56

TurboSign — reminders and document expiration

sendReminder()

A standalone nudge for a document's outstanding signers (#61). Deliberately decoupled from the automatic schedule: it works even when reminders are disabled or the per-signer cap is spent, and it does not consume that cap.

const { results } = await TurboSign.sendReminder(documentId);
for (const r of results) console.log(`${r.recipientId}: ${r.status}`);

// or nudge specific signers
await TurboSign.sendReminder(documentId, [recipientId]);

Only signers at the current signing order are emailed; anyone else comes back as skipped with a reason rather than being silently dropped.

Per-document schedule and expiration

sendSignature() and createSignatureReviewLink() now accept reminder and expiration overrides. Omit a field to inherit the organization default.

await TurboSign.sendSignature({
  file, documentName, recipients, fields,
  remindersEnabled: true,
  reminderDelay: { value: 1, unit: 'days' },
  reminderInterval: { value: 2, unit: 'days' },
  maxReminders: 3,
  expirationEnabled: true,
  expireAfter: { value: 14, unit: 'days' },
  expirationWarning: { value: 3, unit: 'days' },
  expirationWarningInterval: { value: 1, unit: 'days' },
});

maxReminders: -1 means unlimited, 0 means none, and it never caps expiry warnings. expirationWarning: { value: 0 } disables warnings entirely.

Available in all six SDKs. Requires a backend that exposes the reminder and schedule endpoints.

Note on reminder counters

A manual sendReminder() stamps lastRemindedAt and increments the recipient's total email count, but deliberately leaves reminderCount untouched — that counter is the automatic cadence's cap budget. Code reading getRecipients() should not treat reminderCount: 0 as "never reminded".

PY SDK v0.6.2

Choose a tag to compare

@nicolasiscoding nicolasiscoding released this 11 Aug 18:53

TurboSign — per-recipient signing status

TurboSign.getRecipients(documentId) (#62) returns every recipient on a document with their signing status, alongside a pending/viewed/completed roll-up and per-recipient email delivery history.

const { recipients, summary, document } = await TurboSign.getRecipients(documentId);
console.log(`${summary.completed}/${summary.total} signed, sent by ${document.sentBy.name}`);
const waitingOn = recipients.filter((r) => r.status !== "completed");

Each recipient carries status, effectiveStatus (the raw status with the document's terminal state layered on, so a signer on a voided document reads voided), signedOn, signingOrder, and a delivery block with first/last sent timestamps, total emails, and reminder/warning counts.

Available in all six SDKs.

Requires the backend release that ships the endpoint (RapidDocxBackend v1.127.0).

Maintenance

  • java-sdk: maven-gpg-plugin 3.1.0 → 3.2.8.
  • Dev-scope advisory clearances for js-yaml and brace-expansion (#65).