npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@absolutejs/esign

v0.0.1

Published

Provider-neutral e-signature requests, sessions, status reconciliation, and webhook contracts

Readme

@absolutejs/esign

Provider-neutral electronic signing for Node.js and Bun. Own agreement versions, identities, permissions, persistence, and billing in your application; swap providers through the same signing contract.

The initial adapters are @absolutejs/esign-docusign and @absolutejs/esign-dropbox-sign. Install only the adapters you use. This package has no provider SDK, database, UI framework, or implicit network initialization.

Contract

  • createRequest: PDFs, signer identities, signature field placement, and an application reference.
  • getRequest: current provider state and individual signer status.
  • createSigningSession: short-lived access for a server-authorized signer already on that request.
  • downloadCompleted: completed PDF; separate audit certificate when supported.
  • cancelRequest: cancel the provider request.
  • verifyWebhook: verify the provider's authentication and return a reconciliation hint.
  • capabilities: embedded signing, ordered signing, cancellation, and separate audit downloads.

Signature fields use one-based pages and provider document coordinates (72 DPI). Document/signer IDs are local identifiers; persist the provider signer IDs returned by createRequest. Always authorize by your saved participant-to-provider-signer mapping, never a caller-supplied email or signer ID.

Account connections

linkedESignProvider(resolver, { ownerRef, provider, bindingId }, factory) accepts the existing @absolutejs/linked-providers resolver. It resolves the binding for that owner and supplies a fresh token callback to the adapter. The host stores and encrypts grants, refreshes tokens, and handles revocation. Provider OAuth helpers are also exported by each adapter; their caller must generate unpredictable state, bind it to the signed-in account, validate and consume it once, and persist tokens securely.

Durable workflow

  1. Save an immutable document revision and SHA-256 digest (documentDigest) before sending.
  2. Persist a creation operation before calling the provider. Do not automatically retry an ambiguous POST timeout; reconcile the operation before allowing another send.
  3. Save provider request and signer IDs against that revision. Do not change providers after a request is sent; cancel and create a new revision instead.
  4. Check ownership and recipient role before issuing a signing session.
  5. Verify callback authentication, deduplicate callback IDs, and call reconcileSignatureRequest using the saved request ID and reference. Callback bodies and browser return URLs never establish completion.
  6. Retrieve and persist the completed PDF and audit artifact when available. A completed request can precede PDF generation; retry artifact retrieval separately without re-sending.

Dropbox Sign's event hash authenticates event time and type, not every payload field. Re-fetching the saved request is mandatory. Preserve terminal state against out-of-order callbacks; an interrupted refresh must not erase a known completed state.

HTTP errors exclude vendor response bodies and access tokens. Creation POSTs are never automatically retried. All HTTP requests have bounded timeouts. Callback routes should enforce body-size limits and return each adapter's webhookAcknowledgement after durable processing.

Development

bun run build, bun run typecheck; adapter contract tests live in ../esign-adapters/test. Tests inject fetch and make no external requests. Live account and sandbox acceptance tests are required before enabling a provider for real agreements.