Who Dropbox Sign is
Dropbox Sign is Dropbox's electronic signature product, known as HelloSign before it took the Dropbox name. It sends, signs and manages agreements, and its API builds branded signing into a website or an app.
Dropbox Sign says its electronic signatures are legally binding in the United States, the European Union, the United Kingdom and many other countries. Businesses that want signing inside their own product use its API, which is why it is one of the electronic signature providers our merchant onboarding module connects to.
What it does in your platform
Merchant onboarding
Has each approved merchant sign their agreement inside your app. The module creates the signature request, opens the signing page at the right step and records the signed agreement when Dropbox Sign reports it.
How the connection works
One connector in the merchant onboarding module talks to the Dropbox Sign API through an API app. The API key stays in the platform's secrets; the app only receives a signing URL for this merchant.
The merchant is approved
Their checks pass, and the module prepares the agreement with the terms and limits set for them.
A request is created
The module creates an embedded signature request through the API app, with the agreement and the merchant's signer.
A signing URL is made
When the merchant reaches the signing step, the module fetches a signing URL. It is valid for 60 minutes and expires as soon as it is opened.
The merchant signs
The signing page opens embedded in your app or website, and the merchant signs without leaving it.
Events come back
Dropbox Sign sends events to the callback URL, each with an event hash the module checks with HMAC-SHA256 before it acts.
Ready to take payments
When every signer is done, the module records the agreement as signed and fetches the final document once Dropbox Sign reports it ready.
Next to other providers
Dropbox Sign sits in the module's electronic signature, next to DocuSign. The onboarding flow around the signing step belongs to the module, so it stays the same whichever provider runs it.
Adding DocuSign next to Dropbox Sign, or moving away from it later, does not change your app, and agreements already signed stay in the merchant's record with the provider that handled them.
When Dropbox Sign fits best
A strong fit when
- You want signing built into your own product through an API, with your branding.
- You want to test before going live: test mode covers almost every feature, with documents watermarked as not legally binding.
- Your teams already work with Dropbox.
Also worth a look
- DocuSign, if your organisation already signs its other contracts with it.
- A signature provider you already have a contract with: it becomes a connector too.
How we get you live
The contract
We help you get your Dropbox Sign account and contract in place, with an API app set up for embedded signing.
The approval
Dropbox Sign approves apps that use embedded signing before they go live. We prepare the approval with you while the flow runs in test mode.
The keys
The API key goes into your platform's secrets and nowhere else, and the same key verifies the hash on every event.
A full test run
The whole flow runs in test mode, where requests are not legally binding and documents are watermarked, before your first real merchant.
