LendKey Webhooks API

Endpoints for receiving DocuSign webhook notifications

OpenAPI Specification

lendkey-webhooks-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: LendKey E-Sign API (via Kong Gateway) Application Contracts Webhooks API
  version: 0.1
  description: "# LendKey E-Sign API - Kong Gateway Documentation\n\n## Overview\n\nThe LendKey E-Sign API provides endpoints for creating and managing electronic signature contracts using DocuSign.\nThis API is accessed through Kong Gateway, which handles authentication via OAuth2.\n\n## Authentication\n\nAll requests to this API require OAuth2 authentication through Kong Gateway.\n\n### Step 1: Get OAuth2 Token\n\nBefore calling any endpoint, you must obtain an access token:\n\n**Production Environment:**\n```bash\ncurl -X POST https://api.lendkey.com/esign/oauth2/token \\\n  -d \"grant_type=client_credentials\" \\\n  -d \"client_id=YOUR_CLIENT_ID\" \\\n  -d \"client_secret=YOUR_CLIENT_SECRET\"\n```\n\n**Response:**\n```json\n{\n  \"access_token\": \"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...\",\n  \"token_type\": \"bearer\",\n  \"expires_in\": 7200\n}\n```\n\n### Step 2: Use Token in API Calls\n\nInclude the access token in the `Authorization` header:\n```\nAuthorization: Bearer YOUR_ACCESS_TOKEN\n```\n\n**Token Lifetime:** 2 hours (7200 seconds)\n\n## Base URLs (Kong Gateway)\n\n| Environment | Kong Base URL | Backend Kubernetes Service |\n|------------|---------------|---------------------------|\n| **Production** | `https://api.lendkey.com/esign` | `main-esign-kotlin.ci.lkeyprod.com` |\n\n## How Kong Routes Requests\n\nWhen you call Kong:\n```\nhttps://api.lendkey.com/esign/applications\n```\n\nKong:\n1. Validates your OAuth2 token\n2. Strips the `/esign` prefix\n3. Forwards to: `http://main-esign-kotlin.ci.lkeyprod.com/applications`\n\nYou don't need to manage any backend authentication - Kong handles everything!\n\n## Getting Started\n\n1. **Get Credentials:** Contact your Kong admin or use the Kong Developer Portal\n2. **Get Token:** Use the OAuth2 token endpoint for your environment\n3. **Call API:** Use the token in the Authorization header\n4. **Refresh:** Get a new token every 2 hours\n"
  contact:
    name: LendKey Platform Team
    url: https://lendkey.com
servers:
- url: https://api.lendkey.com/esign
  description: Production Environment
security:
- oauth2: []
tags:
- name: Webhooks
  description: Endpoints for receiving DocuSign webhook notifications
paths:
  /webhooks/docusign:
    post:
      summary: Handle DocuSign Webhook
      description: 'Receives webhook notifications from DocuSign Connect when envelope events occur.

        The endpoint validates the envelope exists in the system, stores the status update,

        and extracts/stores signer data when envelope is completed.


        **Events handled:**

        - Envelope is sent

        - Envelope is delivered to recipients

        - Envelope is signed/completed

        - Envelope is declined

        - Envelope is voided

        - Recipient events


        **Kong Route:** `/webhooks/docusign`

        **Backend:** `/webhooks/docusign`

        '
      tags:
      - Webhooks
      operationId: handleDocuSignWebhook
      security: []
      parameters:
      - name: X-DocuSign-Signature-1
        in: header
        required: false
        schema:
          type: string
        description: HMAC signature for verification (optional)
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              additionalProperties: true
              description: DocuSign webhook payload
      responses:
        '200':
          description: Webhook processed successfully
        '400':
          description: Bad request (invalid payload)
        '404':
          description: Envelope not found in system
        '500':
          description: Internal server error
  /webhooks/docusign/health:
    get:
      summary: Webhook Health Check
      description: 'Simple endpoint to verify the webhook URL is accessible (for DocuSign Connect verification).


        **Kong Route:** `/webhooks/docusign/health`

        **Backend:** `/webhooks/docusign/health`

        '
      tags:
      - Webhooks
      operationId: webhookHealthCheck
      security: []
      responses:
        '200':
          description: Webhook endpoint is healthy
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: string
                    example: ok
                  service:
                    type: string
                    example: docusign-webhook
components:
  securitySchemes:
    oauth2:
      type: oauth2
      description: OAuth2 client credentials flow via Kong Gateway
      flows:
        clientCredentials:
          tokenUrl: /oauth2/token
          scopes: {}