Khatm

For developers

Signing. Inside your workflows.

Create requests, guide signers and retrieve finalized documents. Your product stays in control while Khatm orchestrates the signing flow.

Get your Sandbox API key · Read documentation · OpenAPI specification

Five steps. One workflow.

From creating the request to retrieving the files, every step has a clear role. Explore the signing lifecycle.

  1. Create POST /v1/signature-requests Bring the PDF, signers and fields together in one request. A client reference connects it to your business flow.
  2. Activate POST /v1/signature-requests/{id}/activate Activate the request to obtain signing links. Place each URL in the right user journey.
  3. Sign URL Khatm signing experience The signer opens their link, reviews the document and completes the fields assigned to them.
  4. Webhook EVENT signature_request.completed Your application receives the completion event. Verify it before updating your workflow.
  5. Retrieve GET /v1/signature-requests/{id}/artifacts/{type} Retrieve the finalized document and its evidence, then attach them to the customer record.

Your product at the center. Signing orchestrated.

Keep your interface and business logic. The signing cycle fits into your application.

Structured requests

Upload the PDF, signers and fields in one idempotent request.

Signer journey

Activate the request and bring each secure signing URL into your product.

Business events

Sync your application when signers complete, requests finish or someone declines.

Downloadable artifacts

Retrieve the signed PDF, PDF evidence and JSON evidence through the API.

Readable from the first call.

Reuse a template, create, detect fields, activate, track and retrieve. Select a resource to see its response.

  • Reuse a template
  • Create a request
  • Detect fields
  • Activate the journey
  • Track its status
  • Retrieve artifacts

Your product stays in sync.

Every event carries a client reference and a state. Your application knows which record to advance.

  • HMAC-SHA256 signature over the raw body
  • Stable event ID to deduplicate retries
  • Timestamp to verify before processing the event

Build. Test. Then integrate.

Prepare your integration with fictitious data and explore the journey building blocks.

  • Sandbox API keys Create and revoke keys from your workspace.
  • Signing URLs One URL per signer, ready to embed in your product.
  • Signed webhooks Signed with HMAC-SHA256, with automatic retries.
  • Signed PDF The final PAdES-signed document, by API.
  • Evidence PDF A human-readable evidence report.
  • Evidence JSON The same evidence, structured for your systems.

Test environment. The certificate is self-signed and this is not a production trust service. Use fictitious data: files are deleted 10 days after upload, including unfinished requests.

From the first call to a signed document.

Start with your Sandbox keys, then find the examples in the documentation.