@classytic/esign-zoho
v0.1.0
Published
Zoho Sign hosted-signature provider adapter for @classytic/esign
Readme
@classytic/esign-zoho
Zoho Sign implementation of the provider-neutral HostedSignatureProvider
contract from @classytic/esign.
It owns only the vendor boundary: OAuth refresh, data-centre routing, envelope creation/submission, status normalization, recall, artifact downloads and HMAC webhook verification. Applications retain their own subject lifecycle and persist only the returned provider reference.
createAndSend is deliberately the text-tag path: the uploaded document must
contain Zoho Sign text tags that resolve to at least one signing field for every
signer. The adapter verifies the fields returned by document creation and refuses
to submit an un-signable draft. Arbitrary field placement and template-based
signing are separate workflows and must not be guessed with default coordinates.
import { createZohoSignProvider } from "@classytic/esign-zoho";
const provider = createZohoSignProvider({
clientId: process.env.ZOHO_SIGN_CLIENT_ID!,
clientSecret: process.env.ZOHO_SIGN_CLIENT_SECRET!,
refreshToken: process.env.ZOHO_SIGN_REFRESH_TOKEN!,
dataCenter: "eu",
});Production OAuth scopes should be limited to
ZohoSign.documents.CREATE, ZohoSign.documents.READ, and
ZohoSign.documents.UPDATE. Configure the callback in Zoho Sign with HMAC
enabled and verify the exact raw request bytes before parsing JSON.
Official contracts used by this adapter:
- https://www.zoho.com/sign/api/oauth.html
- https://www.zoho.com/sign/api/api-endpoint.html
- https://www.zoho.com/sign/api/document-managment/create-document.html
- https://www.zoho.com/sign/api/use-cases/sending-a-document-for-signature.html
- https://www.zoho.com/sign/api/document-managment/get-details-of-a-particular-document.html
- https://www.zoho.com/sign/api/document-managment/recall-document.html
- https://www.zoho.com/sign/api/document-managment/download-pdf.html
- https://help.zoho.com/portal/en/kb/zoho-sign/admin-guide/webhooks/articles/securing-zoho-sign-webhooks-with-hmac-authentication
