Dropbox Sign (HelloSign) Embedded API

{'$ref': './markdown/en/tags/embedded-tag-description.md'}

OpenAPI Specification

hellosign-embedded-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Dropbox Sign Account Embedded API
  description: Dropbox Sign v3 API
  termsOfService: https://www.hellosign.com/terms
  contact:
    email: apisupport@hellosign.com
  license:
    name: MIT
    url: https://opensource.org/licenses/MIT
  version: 3.0.0
servers:
- url: https://api.hellosign.com/v3
security:
- api_key: []
- oauth2:
  - account_access
  - signature_request_access
  - template_access
  - team_access
  - api_app_access
  - basic_account_info
  - request_signature
tags:
- name: Embedded
  description:
    $ref: ./markdown/en/tags/embedded-tag-description.md
paths:
  /embedded/edit_url/{template_id}:
    post:
      tags:
      - Embedded
      summary: Get Embedded Template Edit URL
      description: Retrieves an embedded object containing a template url that can be opened in an iFrame. Note that only templates created via the embedded template process are available to be edited with this endpoint.
      operationId: embeddedEditUrl
      parameters:
      - name: template_id
        in: path
        description: The id of the template to edit.
        required: true
        schema:
          type: string
        example: f57db65d3f933b5316d398057a36176831451a35
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/EmbeddedEditUrlRequest'
            examples:
              example:
                $ref: '#/components/examples/EmbeddedEditUrlRequest'
      responses:
        '200':
          description: successful operation
          headers:
            X-RateLimit-Limit:
              $ref: '#/components/headers/X-RateLimit-Limit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/X-RateLimit-Remaining'
            X-Ratelimit-Reset:
              $ref: '#/components/headers/X-Ratelimit-Reset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EmbeddedEditUrlResponse'
              examples:
                example:
                  $ref: '#/components/examples/EmbeddedEditUrlResponse'
        4XX:
          description: failed_operation
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                400_example:
                  $ref: '#/components/examples/Error400Response'
                401_example:
                  $ref: '#/components/examples/Error401Response'
                402_example:
                  $ref: '#/components/examples/Error402Response'
                403_example:
                  $ref: '#/components/examples/Error403Response'
                429_example:
                  $ref: '#/components/examples/Error429Response'
                404_example:
                  $ref: '#/components/examples/Error404Response'
                4XX_example:
                  $ref: '#/components/examples/Error4XXResponse'
      security:
      - api_key: []
      - oauth2:
        - template_access
      x-codeSamples:
      - lang: PHP
        label: PHP
        source:
          $ref: examples/EmbeddedEditUrlExample.php
      - lang: C#
        label: C#
        source:
          $ref: examples/EmbeddedEditUrlExample.cs
      - lang: TypeScript
        label: TypeScript
        source:
          $ref: examples/EmbeddedEditUrlExample.ts
      - lang: Java
        label: Java
        source:
          $ref: examples/EmbeddedEditUrlExample.java
      - lang: Ruby
        label: Ruby
        source:
          $ref: examples/EmbeddedEditUrlExample.rb
      - lang: Python
        label: Python
        source:
          $ref: examples/EmbeddedEditUrlExample.py
      - lang: cURL
        label: cURL
        source:
          $ref: examples/EmbeddedEditUrlExample.sh
      x-meta:
        seo:
          title: Get Embedded Template URL | iFrame | Dropbox Sign for Developers
          description: The Dropbox Sign API allows you to build custom integrations. To find out how to retrieve an embedded iFrame object containing a template url, click here.
  /embedded/sign_url/{signature_id}:
    get:
      tags:
      - Embedded
      summary: Get Embedded Sign URL
      description: Retrieves an embedded object containing a signature url that can be opened in an iFrame. Note that templates created via the embedded template process will only be accessible through the API.
      operationId: embeddedSignUrl
      parameters:
      - name: signature_id
        in: path
        description: The id of the signature to get a signature url for.
        required: true
        schema:
          type: string
        example: 50e3542f738adfa7ddd4cbd4c00d2a8ab6e4194b
      responses:
        '200':
          description: successful operation
          headers:
            X-RateLimit-Limit:
              $ref: '#/components/headers/X-RateLimit-Limit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/X-RateLimit-Remaining'
            X-Ratelimit-Reset:
              $ref: '#/components/headers/X-Ratelimit-Reset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EmbeddedSignUrlResponse'
              examples:
                example:
                  $ref: '#/components/examples/EmbeddedSignUrlResponse'
        4XX:
          description: failed_operation
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
              examples:
                400_example:
                  $ref: '#/components/examples/Error400Response'
                401_example:
                  $ref: '#/components/examples/Error401Response'
                402_example:
                  $ref: '#/components/examples/Error402Response'
                403_example:
                  $ref: '#/components/examples/Error403Response'
                429_example:
                  $ref: '#/components/examples/Error429Response'
                404_example:
                  $ref: '#/components/examples/Error404Response'
                409_example:
                  $ref: '#/components/examples/Error409Response'
                4XX_example:
                  $ref: '#/components/examples/Error4XXResponse'
      security:
      - api_key: []
      - oauth2:
        - signature_request_access
      x-codeSamples:
      - lang: PHP
        label: PHP
        source:
          $ref: examples/EmbeddedSignUrlExample.php
      - lang: C#
        label: C#
        source:
          $ref: examples/EmbeddedSignUrlExample.cs
      - lang: TypeScript
        label: TypeScript
        source:
          $ref: examples/EmbeddedSignUrlExample.ts
      - lang: Java
        label: Java
        source:
          $ref: examples/EmbeddedSignUrlExample.java
      - lang: Ruby
        label: Ruby
        source:
          $ref: examples/EmbeddedSignUrlExample.rb
      - lang: Python
        label: Python
        source:
          $ref: examples/EmbeddedSignUrlExample.py
      - lang: cURL
        label: cURL
        source:
          $ref: examples/EmbeddedSignUrlExample.sh
      x-meta:
        seo:
          title: Get Embedded Sign URL | iFrame | Dropbox Sign for Developers
          description: The Dropbox Sign API allows you to build custom integrations. To find out how to retrieve an embedded iFrame object containing a signature url, click here.
components:
  schemas:
    EmbeddedSignUrlResponseEmbedded:
      description: An object that contains necessary information to set up embedded signing.
      properties:
        sign_url:
          description: A signature url that can be opened in an iFrame.
          type: string
        expires_at:
          description: The specific time that the the `sign_url` link expires, in epoch.
          type: integer
      type: object
      x-internal-class: true
    EmbeddedEditUrlResponseEmbedded:
      description: An embedded template object.
      properties:
        edit_url:
          description: A template url that can be opened in an iFrame.
          type: string
        expires_at:
          description: The specific time that the the `edit_url` link expires, in epoch.
          type: integer
      type: object
      x-internal-class: true
    EmbeddedEditUrlRequest:
      properties:
        allow_edit_ccs:
          description: This allows the requester to enable/disable to add or change CC roles when editing the template.
          type: boolean
          default: false
        cc_roles:
          description: The CC roles that must be assigned when using the template to send a signature request. To remove all CC roles, pass in a single role with no name. For use in a POST request.
          type: array
          items:
            type: string
        editor_options:
          $ref: '#/components/schemas/SubEditorOptions'
        force_signer_roles:
          description: Provide users the ability to review/edit the template signer roles.
          type: boolean
          default: false
        force_subject_message:
          description: Provide users the ability to review/edit the template subject and message.
          type: boolean
          default: false
        merge_fields:
          description: 'Add additional merge fields to the template, which can be used used to pre-fill data by passing values into signature requests made with that template.


            Remove all merge fields on the template by passing an empty array `[]`.'
          type: array
          items:
            $ref: '#/components/schemas/SubMergeField'
        preview_only:
          description: 'This allows the requester to enable the preview experience (i.e. does not allow the requester''s end user to add any additional fields via the editor).


            **NOTE:** This parameter overwrites `show_preview=true` (if set).'
          type: boolean
          default: false
        show_preview:
          description: This allows the requester to enable the editor/preview experience.
          type: boolean
          default: false
        show_progress_stepper:
          description: When only one step remains in the signature request process and this parameter is set to `false` then the progress stepper will be hidden.
          type: boolean
          default: true
        test_mode:
          description: Whether this is a test, locked templates will only be available for editing if this is set to `true`. Defaults to `false`.
          type: boolean
          default: false
      type: object
    SubMergeField:
      required:
      - name
      - type
      properties:
        name:
          description: The name of the merge field. Must be unique.
          type: string
        type:
          description: The type of merge field.
          type: string
          enum:
          - text
          - checkbox
          x-enumDescriptions:
            text: Sets merge [field type](/api/reference/constants/#field-types) to `text`.
            checkbox: Sets merge [field type](/api/reference/constants/#field-types) to `checkbox`.
      type: object
    ErrorResponseError:
      description: Contains information about an error that occurred.
      required:
      - error_msg
      - error_name
      properties:
        error_msg:
          description: Message describing an error.
          type: string
        error_path:
          description: Path at which an error occurred.
          type: string
        error_name:
          description: Name of the error. See the `x-error-codes` catalog in openapi file for a complete list of possible error codes with detailed information including HTTP status codes, causes, remediation steps, and retry guidance.
          type: string
      type: object
    SubEditorOptions:
      description: This allows the requester to specify editor options when a preparing a document
      properties:
        allow_edit_signers:
          description: Allows requesters to edit the list of signers
          type: boolean
          default: false
        allow_edit_documents:
          description: Allows requesters to edit documents, including delete and add
          type: boolean
          default: false
      type: object
    ErrorResponse:
      required:
      - error
      properties:
        error:
          $ref: '#/components/schemas/ErrorResponseError'
      type: object
    WarningResponse:
      description: A list of warnings.
      required:
      - warning_msg
      - warning_name
      properties:
        warning_msg:
          description: Warning message
          type: string
        warning_name:
          description: Warning name
          type: string
      type: object
    EmbeddedEditUrlResponse:
      required:
      - embedded
      properties:
        embedded:
          $ref: '#/components/schemas/EmbeddedEditUrlResponseEmbedded'
        warnings:
          description: A list of warnings.
          type: array
          items:
            $ref: '#/components/schemas/WarningResponse'
      type: object
      x-internal-class: true
    EmbeddedSignUrlResponse:
      required:
      - embedded
      properties:
        embedded:
          $ref: '#/components/schemas/EmbeddedSignUrlResponseEmbedded'
        warnings:
          description: A list of warnings.
          type: array
          items:
            $ref: '#/components/schemas/WarningResponse'
      type: object
      x-internal-class: true
  examples:
    Error401Response:
      summary: Error 401 unauthorized
      value:
        $ref: examples/json/Error401Response.json
    Error409Response:
      summary: Error 409 conflict
      value:
        $ref: examples/json/Error409Response.json
    Error400Response:
      summary: Error 400 bad_request
      value:
        $ref: examples/json/Error400Response.json
    Error402Response:
      summary: Error 402 payment_required
      value:
        $ref: examples/json/Error402Response.json
    Error4XXResponse:
      summary: Error 4XX failed_operation
      value:
        $ref: examples/json/Error4XXResponse.json
    Error404Response:
      summary: Error 404 not_found
      value:
        $ref: examples/json/Error404Response.json
    EmbeddedEditUrlResponse:
      summary: Embedded Edit URL
      value:
        $ref: examples/json/EmbeddedEditUrlResponse.json
    EmbeddedSignUrlResponse:
      summary: Embedded Sign URL
      value:
        $ref: examples/json/EmbeddedSignUrlResponse.json
    Error403Response:
      summary: Error 403 forbidden
      value:
        $ref: examples/json/Error403Response.json
    Error429Response:
      summary: Error 429 exceeded_rate
      value:
        $ref: examples/json/Error429Response.json
    EmbeddedEditUrlRequest:
      summary: Default Example
      value:
        $ref: examples/json/EmbeddedEditUrlRequest.json
  headers:
    X-Ratelimit-Reset:
      description: The Unix time at which the rate limit will reset to its maximum.
      schema:
        type: integer
        format: int64
        example: 1430170900
    X-RateLimit-Remaining:
      description: The number of requests remaining in the current rate limit window.
      schema:
        type: integer
        format: int32
        example: 99
    X-RateLimit-Limit:
      description: The maximum number of requests per hour that you can make.
      schema:
        type: integer
        format: int32
        example: 100
  securitySchemes:
    api_key:
      type: http
      description: 'Your API key can be used to make calls to the Dropbox Sign API. See [Authentication](/api/reference/authentication) for more information.

        ✅ Supported by Try it console (calls sent in `test_mode` only).'
      scheme: basic
    oauth2:
      type: http
      description: 'You can use an Access Token issued through an OAuth flow to send calls to the Dropbox Sign API from your app. The access scopes required by this endpoint are listed in the gray box above. See [Authentication](/api/reference/authentication) for more information.

        ❌ **Not supported** by Try it console.'
      bearerFormat: JWT
      scheme: bearer
externalDocs:
  description: Legacy API Reference
  url: https://app.hellosign.com/api/reference
x-webhooks:
  accountCallback:
    post:
      summary: Account Callbacks
      operationId: accountUpdateEventCallback
      description:
        $ref: ./markdown/en/descriptions/account-callback-description.md
      tags:
      - Callbacks and Events
      x-meta:
        seo:
          title: Account Callbacks | API Documentation | Dropbox Sign for Developers
          description: The Dropbox Sign API allows you to build with a wide range of tools. To find out how to consume Dropbox Sign Events at the account level, click here.
      x-fern-audiences:
      - events
      requestBody:
        description: "**Account Callback Payloads --**\n      Events that are reported at the Account level through the the *Account callback URL* defined in your [API settings](https://app.hellosign.com/home/myAccount#api). The *Account callback URL* can also be updated by calling [Update Account](/api/reference/operation/accountUpdate) and passing a `callback_url`."
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/EventCallbackPayload'
            examples:
              signature_request_viewed_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestViewed'
              signature_request_signed_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestSigned'
              signature_request_signer_removed_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestSignerRemoved'
              signature_request_downloadable_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestDownloadable'
              signature_request_sent_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestSent'
              signature_request_all_signed_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestAllSigned'
              signature_request_invalid_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestInvalid'
              signature_request_email_bounce_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestEmailBounce'
              signature_request_remind_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestRemind'
              signature_request_incomplete_qes_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestIncompleteQes'
              signature_request_destroyed_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestDestroyed'
              signature_request_canceled_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestCanceled'
              signature_request_declined_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestDeclined'
              signature_request_expired_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestExpired'
              signature_request_reassigned_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestReassigned'
              signature_request_prepared_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestPrepared'
              account_confirmed_example:
                $ref: '#/components/examples/EventCallbackAccountConfirmed'
              unknown_error_example:
                $ref: '#/components/examples/EventCallbackUnknownError'
              file_error_example:
                $ref: '#/components/examples/EventCallbackFileError'
              template_created_example:
                $ref: '#/components/examples/EventCallbackTemplateCreated'
              template_error_example:
                $ref: '#/components/examples/EventCallbackTemplateError'
              sign_url_invalid_example:
                $ref: '#/components/examples/EventCallbackSignUrlInvalid'
              callback_test_example:
                $ref: '#/components/examples/EventCallbackCallbackTest'
      responses:
        200:
          $ref: '#/components/responses/EventCallbackResponse'
  appCallback:
    post:
      summary: App Callbacks
      operationId: apiAppCreateEventCallback
      description:
        $ref: ./markdown/en/descriptions/api-app-callback-description.md
      tags:
      - Callbacks and Events
      x-meta:
        seo:
          title: App Callbacks | API Documentation | Dropbox Sign for Developers
          description: The Dropbox Sign API allows you to build with a wide range of tools. To find out how to consume Dropbox Sign Events at the App level, click here.
      x-fern-audiences:
      - events
      requestBody:
        description: '**API App Callback Payloads --**

          Events that are reported at the API App level through the *Event callback URL* defined in your [API settings](https://app.hellosign.com/home/myAccount#api) for a specific app. The *Event callback URL* can also be updated by calling [Update API App](/api/reference/operation/apiAppUpdate) and passing a `callback_url`.'
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/EventCallbackPayload'
            examples:
              signature_request_viewed_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestViewed'
              signature_request_signed_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestSigned'
              signature_request_signer_removed_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestSignerRemoved'
              signature_request_downloadable_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestDownloadable'
              signature_request_sent_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestSent'
              signature_request_all_signed_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestAllSigned'
              signature_request_invalid_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestInvalid'
              signature_request_email_bounce_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestEmailBounce'
              signature_request_remind_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestRemind'
              signature_request_incomplete_qes_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestIncompleteQes'
              signature_request_destroyed_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestDestroyed'
              signature_request_canceled_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestCanceled'
              signature_request_declined_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestDeclined'
              signature_request_expired_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestExpired'
              signature_request_reassigned_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestReassigned'
              signature_request_prepared_example:
                $ref: '#/components/examples/EventCallbackSignatureRequestPrepared'
              account_confirmed_example:
                $ref: '#/components/examples/EventCallbackAccountConfirmed'
              unknown_error_example:
                $ref: '#/components/examples/EventCallbackUnknownError'
              file_error_example:
                $ref: '#/components/examples/EventCallbackFileError'
              template_created_example:
                $ref: '#/components/examples/EventCallbackTemplateCreated'
              template_error_example:
                $ref: '#/components/examples/EventCallbackTemplateError'
              sign_url_invalid_example:
                $ref: '#/components/examples/EventCallbackSignUrlInvalid'
              callback_test_example:
                $ref: '#/components/examples/EventCallbackCallbackTest'
      responses:
        200:
          $ref: '#/components/responses/EventCallbackResponse'
x-error-codes:
  bad_request:
    http_status: 400
    summary: The request contained invalid or malformed parameters.
    cause: A parameter failed validation, or the request body was malformed.
    remediation: Inspect error_msg and error_path, correct the offending parameter, and resend.
    retryable: 'no'
  unauthorized:
    http_status: 401
    summary: The credentials supplied are missing or invalid.
    cause: Missing, malformed, or invalid API key or OAuth access token.
    remediation: Verify the API key or OAuth token and the Authorization header, then retry.
    retryable: 'no'
  payment_required:
    http_status: 402
    summary: The account must be credited or upgraded to perform this action.
    cause: The action requires a paid plan, additional quota, or API credits.
    remediation: Upgrade the plan or add the required credits/quota, then retry.
    retryable: 'no'
  forbidden:
    http_status: 403
    summary: The action is not allowed for these credentials or in the current context.
    cause: The authenticated account lacks access to the resource or operation.
    remediation: Confirm the account has access to the resource and the required permissions.
    retryable: 'no'
  not_found:
    http_status: 404
    summary: Nothing matches the requested resource.
    cause: The resource id does not exist or is not visible to this account.
    remediation: Verify the id and that the resource belongs to the authenticated account.
    retryable: 'no'
  conflict:
    http_status: 409
    summary: The request was well-formed but conflicts with the current state.
    cause: The target resource is in a state incompatible with the request (e.g. a signature request is still being set up).
    remediation: Wait briefly and retry, or listen for a callback event confirming the resource is ready.
    retryable: conditional
  exceeded_rate:
    http_status: 429
    summary: Your account's API request rate limit has been exceeded.
    cause: Too many requests were sent within the rate-limit window for this request type.
    remediation: Pace requests using the X-RateLimit-* response headers and retry after the window resets.
    retryable: 'yes'
    backoff: Honor X-Ratelimit-Reset (Unix epoch); otherwise exponential backoff with jitter. No Retry-After header is sent.
  unknown:
    http_status: 500
    summary: An unexpected error occurred.
    cause: An unhandled server-side error, or a status code without a more specific error_name.
    remediation: Retry transient failures; if it persists, contact support with the request details.
    retryable: conditional
    backoff: For transient 5xx, retry with exponential backoff; otherwise do not retry.
  team_invite_failed:
    http_status: 403
    summary: The team invitation could not be completed.
    cause: The invitee already belongs to a team, or the invite is otherwise not permitted.
    remediation: Confirm the invitee is not already on a team before inviting.
    retryable: 'no'
  max_faxes:
    http_status: 429
    summary: Too many fax transmissions are currently pending or transmitting.
    cause: The account has reached the limit of concurrent in-flight fax transmissions.
    remediation: Wait for outstanding transmissions to complete, then retry.
    retryable: 'yes'
    backoff: Retry with exponential backoff once pending transmissions clear.
  invalid_recipient:
    http_status: 400
    summary: The recipient (fax number or email address) is invalid.
    cause: A recipient value did not pass validation.
    remediation: Correct the recipient value and resend.
    retryable: 'no'
  signature_request_cancel_failed:
    http_status: 400
    summary: The signature request could not be cancelled.
    cause: The caller is not the requester, or the request is already fully executed/closed.
    remediation: Only the requester can cancel, and only before the request is fully executed.
    retryable: 'no'
  signature_request_remove_failed:
    http_status: 400
    summary: Access to the signature request could not be removed.
    cause: The signature request has not yet been fully executed, so access cannot be revoked.
    remediation: Wait until all parties have signed, or call /signature_request/cancel to cancel incomplete requests instead.
    retryable: 'no'
  maintenance:
    http_status: 503
    summary: The request could not be completed because the site is under maintenance.
    cause: The API is in a scheduled maintenance window.
    remediation: Retry once the maintenance window ends.
    retryable: 'yes'
    backoff: Retry later with exponential backoff.
  method_not_supported:
    http_status: 405
    summary: The HTTP method is not supported for this endpoint.
    cause: The request used a verb the endpoint does not accept.
    remediation: Use the HTTP method documented for the endpoint.
    retryable: 'no'
  invalid_reminder:
    http_status: 400
    summary: The signature request reminder was invalid.
    cause: A reminder was attempted against an ineligible request (e.g. embedded, closed, or expired).
    remediation: Only send reminders for eligible (non-embedded, open) signature requests.
    retryable: 'no'
  unavailable:
    http_status: 503
    summary: The service is temporarily unavailable.
    cause: A downstream dependency or the service itself is temporarily unavailable.
    remediation: Retry later with exponential backoff.
    retryable: 'yes'
    backoff: Retry later with exponential backoff and jitter.
  unprocessable_entity:
    http_status: 422
    summary: The request was understood but the target entity cannot be processed.
    cause: The resource is still being processed, or it is in an error state.
    remediation: If the resource is still processing, wait and retry; if it is in an error state, recreate/resend it instead of retrying.
    retryable: conditional
    backoff: If still processing, retry with exponential backoff; if in an error state, do not retry.
  signature_request_expired:
    http_status:
    - 400
    - 403
    summary: The signature request has expired.
    cause: The operation targets a request whose expiration has passed. Most endpoints return 400; final-copy/download endpoints return 403.
    remediation: The request can no longer be acted upon; create a new signature request.
    retryable: 'no'
  deleted:
    http_status: 410
    summary: The request was cancelled or deleted.
    cause: The resource has been cancelled or removed and is no longer available.
    remediation: Do not retry; the resource is permanently gone.
    retryable: 'no'
x-oauth-error-codes:
  invalid_grant:
    http_status:
    - 400
    - 401
    summary: The OAuth grant (authorization code or refresh token) is invalid or expired.
    cause: The code/token was already used, expired, or does not match the client.
    remediation: Re-initiate the OAuth flow to obtain a fresh authorization code.
    retryable: 'no'
  invalid_client:
    http_status: 400
    summary: The OAuth client credentials are invalid.
    cause: The client_id or client_secret is unrecognized or incorrect.
    remediation: Verify the client_id and client_secret from the API app settings.
    retryable: 'no'
  invalid_request:
    http_status: 400
    summary: The OAuth request is malformed or missing required parameters.
    cause: A required parameter is missing, or the request format is invalid.
    remediation: Check the request against the OAuth token endpoint documentation.
    retryable: 'no'
  unauthorized_client:
    http_status:
    - 401
    - 403
    summary: The OAuth client is not authorized to perform this action.
    cause: The app has not been approved, or the action is outside the granted scopes.
    remediation: Ensure the app is approved and the required scopes are granted.
    retryable: 'no'
  unsupported_grant_type:
    http_status: 400
    summary: The grant type is not supported.
    cause: The grant_type parameter value is not recognized.
    remediation: Use authorization_code or refresh_token as the grant_type.
    retryable: 'no'
  payment_required:
    http_status: 402
    summary: The account req

# --- truncated at 32 KB (35 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/hellosign/refs/heads/main/openapi/hellosign-embedded-api-openapi.yml