Skip to main content
In this guide, you download the files of a document: the sealed PDF, the unsigned original, and the signing journal. Then you archive them automatically when a document is completed.

Before you begin

  • Store your API key in the SAJN_API_KEY environment variable. To create a key, go to workspace settings in the sajn app, then Utvecklare (Developer) > API-nycklar (API keys).
  • Have the ID of a document. To download the sealed PDF or the journal, the document must be COMPLETED.

Choose a file type

A document has up to three files:
  • SIGNED: the sealed PDF with every signature and the signing certificate. Ready when the document is COMPLETED and sealed.
  • ORIGINAL: the unsigned document. Ready in every status.
  • JOURNAL: the signing journal, a separate PDF with every party, their identity and signing method, and every event with its timestamp and IP address. Ready shortly after the document is COMPLETED.
To get one file, call GET /api/v1/documents/DOCUMENT_ID/files/TYPE. To see which files are ready, call GET /api/v1/documents/DOCUMENT_ID/files, which lists only the files that are ready, each with its own URL.

Download a file

1

Get a download URL

The endpoint returns a pre-signed URL, not the file. Request the URL:
Replace DOCUMENT_ID with the document ID. The response is similar to the following:
The URL is valid for 15 minutes, until expiresAt. Every URL that the API returns counts as a download: it’s recorded in the document’s audit log and fires the security.document_downloaded webhook event.
2

Fetch the file

Fetch the URL without the Authorization header, and save the response body:
Replace FILE_URL with the url from the previous step. The file is a PDF file. If the URL has expired, request a new one.

Archive documents when they’re completed

We recommend downloading each document as soon as it’s completed, so your archive doesn’t depend on polling. Subscribe a webhook endpoint to document.completed, which fires when the sealed PDF is ready, and download the files in the handler. The event’s data.object is the document, so data.object.id is the document ID. The following Express handler verifies the delivery’s signature, answers right away, and then archives the sealed PDF and the journal:
The handler reads the following environment variables:
  • SAJN_API_KEY: your API key.
  • SAJN_WEBHOOK_SECRET: the webhook’s whsec_ secret, returned when you create the webhook or rotate its secret.
The journal is generated after the sealed PDF, so in production, retry the JOURNAL download when it returns 409 INVALID_STATE. A delivery can arrive more than once. Deduplicate on the event’s id, or make the archive write idempotent, as the preceding example does by writing to a fixed filename. For more information, see Verify webhook signatures and Delivery and retries. To catch up on documents that completed while your endpoint was down, see Sync all completed documents nightly.

Handle errors

Branch on the error code:
  • 404 NOT_FOUND, with resource set to document: the document doesn’t exist, or your key can’t see it.
  • 409 INVALID_STATE: the file isn’t ready yet, for example SIGNED before the document is completed.
sajn generates the journal after it seals the document, so JOURNAL can return this error for a short time after document.completed. Retry it after a few seconds. For the error shape and every code, see Errors.

Next steps

Nightly sync

Archive every completed document on a schedule.

Signing certificate

Learn what the sealed PDF proves.

Webhooks

Get notified when a document is completed.

Get a document file

See the endpoint in the API reference.