English
Yousign — event
Starts the workflow when Yousign reports an event: a signed request, a decline, an expiry. The signed body lands in data.yousign. Deliveries Yousign sends again are deduplicated on event_id.
The Yousign — event trigger starts the workflow when Yousign reports an event on the workflow's URL: a request signed by everyone, a decline, an expiry. The event that matters most is signature_request.done ("Request signed by everyone", the default): it is when the signed document and the audit trail become downloadable.
Three guarantees distinguish it from the generic Webhook received trigger:
- Origin is proven. Yousign signs each body (
x-yousign-signature-256header, HMAC-SHA256 of the raw body). The signature is checked against the "Webhook signing key" of the Yousign connection before anything is written. - Redeliveries are absorbed. Yousign retries failed deliveries with the same
event_id; a redelivery starts no second run. - Sorting happens first. Only the ticked events start a run; the others are acknowledged and dropped.
The run has no triggering email: nodes that act on the triggering email (reply in the thread, Move, Flag) cannot be used after this trigger, and the editor reports them as a blocking error. Send still works when you choose the sending mailbox on the node.
To set it up:
- Add the trigger, choose the Yousign connection and the events, then publish. The URL
<PUBLIC_BASE_URL>/hooks/wf/<token>is issued on the first publication and returned only once;POST /api/v1/workflows/<id>/webhookissues a new one (the previous one stops working). - Create the subscription on the Yousign side, pointing at that URL: either with the Yousign node, resource "Webhook", operation "Create a subscription", or by hand in the Yousign app. Creating a subscription by API requires a production key, even to listen to the sandbox, and is not allowed during the Yousign trial period.
- Paste the subscription's secret key into the "Webhook signing key" field of the Yousign connection.
- Use "Subscription (diagnostics)" on the node to check that a subscription points at this workflow's URL, in the right environment.
At a glance
- Type:
trigger.yousign· version 1 - Category: Triggers
- Kind: Trigger — starts a run
- Effect: No external effect (
none) — nothing is written outside Mankomail; safe to replay - Needs a carrier email: No
- Connection: Yousign
- Outputs:
main
Connection
This node needs a Yousign connection.
Parameters
connection
Yousign connection — The Yousign connection to use. Create it once in Connections; its key never appears in the workflow.
- Type: Connection (
credential) - Required: Yes
- Default:
""(empty)
events
Events — What starts this workflow. Nothing ticked = everything Yousign sends to this URL, that is the events of all your requests. “Request signed by everyone” is the one that matters: that is when the signed document and the audit trail become downloadable.
- Type: Several choices (
multiOptions) - Required: No
- Default:
["signature_request.done"] - Options:
signature_request.done— Request signed by everyonesignature_request.activated— Request sentsignature_request.declined— Request declined by a signersignature_request.rejected— Request rejected by an approversignature_request.approved— Request approvedsignature_request.expired— Request expiredsignature_request.canceled— Request cancelledsignature_request.reminder_executed— Reminder sentsigner.done— A signer has signedsigner.link_opened— A signer opened their linksigner.declined— A signer declinedsigner.notified— A signer was notifiedsigner.notification_delivery_failed— A signer’s email did not arrivesigner.error— Error on a signerapprover.approved— An approver approvedapprover.rejected— An approver rejectedcontact.created— Contact created
webhook
Subscription (diagnostics) — Informational: it is there to check that a subscription does point at this workflow’s URL, with the right environment. The list never shows the signing key.
- Type: Remote resource (
resourceLocator) - Required: No
- Ways to choose: pick from a list, type an ID (
yousign.webhook) - Listed with the connection in:
connection
Outputs
main— Taken by every run started by a Yousign event whose signature is valid and that passed the event filter.
Data produced
What this node adds to the run data, and how to read it in an expression. <step> stands for the step key: the node name turned into an identifier (see Data and expressions).
{{ data.yousign }}—object. The JSON body of the event, exactly as Yousign sent and signed it.{{ data.yousign.event_name }}—string. The event, e.g.signature_request.done.{{ data.yousign.event_id }}—string. The delivery identifier. A redelivery carries the same value and starts no second run.{{ data.yousign.data.signature_request.id }}—string. The signature request concerned. Pass it to the Yousign node to download the signed document or the audit trail.{{ data.yousign.data.signature_request.external_id }}—string. The correlation key set when the request was created: the way back to your case or the original email thread.
Example
When a fee agreement is signed by everyone, file it and tell the lawyer. The trigger keeps events on "Request signed by everyone". On each completed request, a run starts on the main port; a Yousign node downloads the signed document of {{ data.yousign.data.signature_request.id }}, and a Table lookup on {{ data.yousign.data.signature_request.external_id }} finds the case it belongs to.
Tips
- Without the signing key, nothing gets through. If the connection's "Webhook signing key" is empty or wrong, every delivery is refused with
404and no run is created. The reason is only written to the server logs. - Responses.
202with{ "executionId" }when a run is created;202with no body for an event you did not tick or a delivery already processed;404for an unknown token, an unpublished workflow or an invalid signature, always the same answer. The other rules of the URL (POSTonly, JSON body up to 256 KB, 300 calls per minute per IP) are those of Webhook received. - Nothing ticked means every event Yousign sends to this URL, that is the events of all your requests. A single request with three signers produces about ten events.
- Back to the original thread. There is no triggering email: to answer in the thread the request came from, set an
external_idwhen creating the request and use it to find your case again. - Untrusted content. The body comes from outside: treat its text as data, never as instructions for an AI node.
- A workflow has at most one Yousign — event trigger, and only the published version receives events.