Certyneo (Preview)
Send documents for eIDAS-compliant electronic signature, create envelopes from templates, and trigger flows on signature events such as sent, signed, completed and declined.
This connector is available in the following products and regions:
| Service | Class | Regions |
|---|---|---|
| Copilot Studio | Premium | All Power Automate regions except the following: - US Government (GCC) - US Government (GCC High) - China Cloud operated by 21Vianet - US Department of Defense (DoD) |
| Logic Apps | Standard | All Logic Apps regions except the following: - Azure Government regions - Azure China regions - US Department of Defense (DoD) |
| Power Apps | Premium | All Power Apps regions except the following: - US Government (GCC) - US Government (GCC High) - China Cloud operated by 21Vianet - US Department of Defense (DoD) |
| Power Automate | Premium | All Power Automate regions except the following: - US Government (GCC) - US Government (GCC High) - China Cloud operated by 21Vianet - US Department of Defense (DoD) |
| Contact | |
|---|---|
| Name | Certyneo Support |
| URL | https://certyneo.com/fr/contact |
| support@certyneo.com |
| Connector Metadata | |
|---|---|
| Publisher | Certyneo |
| Website | https://certyneo.com |
| Privacy policy | https://certyneo.com/fr/legal/privacy |
| Categories | IT Operations;Productivity |
Certyneo
Certyneo is an eIDAS-compliant electronic signature service. This connector lets a flow send documents out for signature, react in real time when a signer acts, and file the signed PDF and its evidence file wherever the rest of the business keeps its records.
The typical flow is three steps: a document lands somewhere (a document library, a
mailbox, a form submission), the flow creates and sends an envelope, and a second
flow triggered by envelope.completed downloads the signed PDF and stores it.
Publisher
Certyneo
Prerequisites
You need a Certyneo account on a plan that includes API access. Free and Personal plans can create API keys and subscribe to events, but they only ever receive events for sandbox envelopes — see Known issues and limitations below.
How to get credentials
The connector authenticates with a Certyneo API key.
- Sign in to Certyneo and open Settings → API Keys.
- Create a key. Live keys start with
sk_live_, sandbox keys withsk_test_. - When the connector asks for the API key, paste the word
Bearer, a space, and then the key — for exampleBearer sk_live_abc123. Certyneo expects the wordBearerin front of the key, and a key pasted on its own is rejected with 401.
The key carries scopes. A key without envelopes:write cannot create or send, and
a key without webhooks:write cannot back the trigger. Grant the scopes the flow
actually needs.
Testing without emailing anyone
A sandbox key (sk_test_) exercises the whole pipeline without sending a single
invitation email. Nothing reaches a real inbox, which also means nobody can reach
the signing page from an email — so Create envelope and Send envelope
return an Access token for each recipient instead. Open
https://certyneo.com/sign/<access token> to sign the test envelope yourself.
Treat that token as a credential: anyone holding it can sign as that recipient. Don't log it, and don't drop it into a spreadsheet.
Supported operations
Trigger
When an envelope event occurs — fires on the events you select, backed by a real webhook rather than polling. Available events:
envelope.created, envelope.sent, envelope.completed, envelope.declined,
envelope.voided, envelope.expired, envelope.returned_to_sender,
envelope.resubmitted, recipient.signed, recipient.viewed,
recipient.approved.
Every payload carries Envelope ID, on both envelope and recipient events. That is the value to feed into the actions below.
Deliveries are signed with HMAC-SHA256 in the X-Certyneo-Signature header — a hex
digest of the raw JSON body, keyed with the subscription secret. Verify it before a
flow acts on the payload.
Actions
| Action | What it does |
|---|---|
| List templates | Your saved envelope templates. Powers the template picker. |
| Create envelope | Creates a DRAFT envelope, from a template or from uploaded documents. |
| Send envelope | Dispatches a DRAFT envelope to its recipients. |
| Get envelope | Current status and recipient details. |
| List envelopes | Paginated list, filterable by status. |
| Upload document | Uploads a PDF or image and returns a document ID. |
| Download signed document | The signed PDF, certificate page included. |
| Download audit trail | The evidence file: who signed, when, from which IP, with which factors. |
| Delete draft envelope | Deletes an envelope that was never sent. |
Known issues and limitations
A sent envelope cannot be recalled from a flow. Delete draft envelope only accepts envelopes still in DRAFT — a flow that failed halfway, a wrong document. Once an envelope has gone out it returns 409, and there is no cancel operation in the API today.
recipient.signed fires before the signed PDF exists, including for the last
signer. Assembling and sealing the final document happens after that event, so a
flow that triggers on recipient.signed and immediately calls Download signed
document gets 409 every time. This is not a race you can win with a delay —
trigger on envelope.completed instead, which fires once the PDF is on disk.
Free and Personal plans receive sandbox events only. Both can create a subscription and the trigger will show as healthy, but live envelopes never reach it. If a trigger appears to do nothing on real traffic, check the plan before anything else.
Use a template or documents, never both. A template brings its own documents
and its own signature fields. When you build from uploaded documents instead, you
must also supply Fields — an envelope whose signer has nowhere to sign is
refused at send time with 409 signer_without_field, not at create time.
Prefer anchor text over coordinates. Placing a field by quoting a phrase from the document ("Signature du client") survives a layout change and needs no measuring. X and Y remain as a fallback so a field whose anchor is not found keeps a literal position instead of disappearing.
Uploads are capped at 50 MB per document.
A purged document returns 410, not 409. 409 means "not ready yet, come back
after envelope.completed". 410 means the signed document was deliberately deleted
under the retention policy and is never coming back. A retry loop should give up on
410.
Common errors and remedies
| Response | Cause | Remedy |
|---|---|---|
| 401 | Key missing, or pasted without Bearer in front |
Re-enter the connection as Bearer sk_live_... |
| 403 | The key lacks the scope for this operation | Re-issue the key with the scopes the flow needs |
| 409 on download | Envelope is not COMPLETED yet | Trigger on envelope.completed rather than polling |
| 409 on send | signer_without_field — a signer has no signature field |
Add Fields, or build from a template |
| 409 on delete | The envelope has already been sent | Sent envelopes cannot be deleted or recalled |
| 410 on download | The document was purged under the retention policy | Stop retrying; the file is gone |
Errors carry both a human-readable error message and a stable code. Branch on
code — the message can be reworded.
Support
- Documentation: https://certyneo.com/developers
- Webhook reference: https://certyneo.com/developers/webhooks
- Support: https://certyneo.com/support
Creating a connection
The connector supports the following authentication types:
| Default | Parameters for creating connection. | All regions | Not shareable |
Default
Applicable: All regions
Parameters for creating connection.
This is not shareable connection. If the power app is shared with another user, another user will be prompted to create new connection explicitly.
| Name | Type | Description | Required |
|---|---|---|---|
| API Key | securestring | The API Key for this api | True |
Actions
| Create envelope |
Create a new envelope in DRAFT status, either from a saved template or straight from documents you uploaded with "Upload document". Fill in exactly one of "Template" or "Documents". With documents, add "Fields" as well so each signer has somewhere to sign — the simplest way is to quote a phrase from the document in "Anchor text" instead of working out coordinates. IMPORTANT: this action only creates the envelope — no email is sent yet. Add the "Send envelope" action right after this one in your flow to actually dispatch it to recipients. |
| Delete draft envelope |
Delete an envelope that was never sent — a flow that failed halfway, a wrong document. DRAFT only: once an envelope has gone out, this returns an error and you cannot recall it from a flow. |
| Download audit trail |
Get the evidence file for a completed envelope — who signed, when, from which IP, with which authentication factors. Archive it alongside the signed PDF: it is what an eIDAS dispute turns on. |
| Download signed document |
Get the signed PDF, certificate page included. Only once the envelope is COMPLETED — before that it returns 409, so trigger on "Envelope completed" rather than polling. |
| Get envelope |
Get the current status and details of an envelope. |
| List envelopes |
Retrieve a paginated list of envelopes. |
| List templates |
Returns your saved envelope templates. Used to power the template picker on "Create envelope". |
| Send envelope |
Dispatch a DRAFT envelope to its recipients for signature — this is the step that actually sends the email. "Create envelope" only saves it as a draft; it does not send anything on its own. Always chain this action right after "Create envelope" in your flow, using the envelope ID it returned. |
| Upload document |
Upload a PDF or image (max 50 MB). Returns a document ID — pass it to "Create envelope" under "Documents". |
Create envelope
Create a new envelope in DRAFT status, either from a saved template or straight from documents you uploaded with "Upload document". Fill in exactly one of "Template" or "Documents". With documents, add "Fields" as well so each signer has somewhere to sign — the simplest way is to quote a phrase from the document in "Anchor text" instead of working out coordinates. IMPORTANT: this action only creates the envelope — no email is sent yet. Add the "Send envelope" action right after this one in your flow to actually dispatch it to recipients.
Parameters
| Name | Key | Required | Type | Description |
|---|---|---|---|---|
|
Subject
|
subject | True | string |
Envelope subject / title. |
|
Message
|
message | string |
Message shown to recipients. |
|
|
Template
|
templateId | string |
Pick a saved template. Use this OR "Documents", not both — a template brings its own documents and signature fields. |
|
|
Documents
|
documentIds | array of string |
Document IDs from "Upload document". Use this OR "Template", not both. When you use documents, add "Fields" too — an envelope whose signer has no signature field is refused at send time. |
|
|
Signer email
|
recipientEmail | True | string |
Must match one of the recipients above, exactly. |
|
Document number
|
documentIndex | integer |
Which document carries this field, counting from 0 in the order given above. Leave empty when there is only one document. |
|
|
Page
|
pageNumber | True | integer | |
|
Field type
|
fieldType | True | string | |
|
Anchor text (recommended)
|
anchorText | string |
Text to look for in the document — the field is placed next to it, so you don't need coordinates. Case-insensitive, and found even when the PDF splits the phrase across runs. Leave empty to use X/Y instead. |
|
|
Anchor placement
|
anchorPlacement | string |
Where to put the field relative to the anchor text. |
|
|
Anchor occurrence
|
anchorIndex | integer |
Which occurrence to use, counting from 0, when the anchor text appears several times. |
|
|
X
|
x | True | number |
Points from the left edge. Ignored when the anchor is found — kept as a fallback so the field never vanishes. |
|
Y
|
y | True | number |
Points from the TOP edge. Ignored when the anchor is found — kept as a fallback. |
|
Width
|
width | True | number | |
|
Height
|
height | True | number | |
|
Recipient email
|
True | string | ||
|
Recipient name
|
name | string | ||
|
Role
|
role | string | ||
|
status
|
status | string | ||
|
signedAt
|
signedAt | string | ||
|
Access token
|
accessToken | string |
Opens this recipient's signing page at https://certyneo.com/sign/<token>. In sandbox no invitation email goes out, so this is how you sign a test envelope yourself. Returned by "Create envelope" and "Send envelope" — not by "Get envelope", where it stays empty. Treat it as a credential: anyone holding it can sign as this recipient, so don't log it or drop it in a spreadsheet. |
|
|
Signature level
|
signatureLevel | string | ||
|
Expires at
|
expiresAt | date-time | ||
|
Category
|
category | string |
Business classification shown on the envelope list. Leave empty and Certyneo infers one from the subject. |
|
|
Tags
|
tags | array of string |
Free-form labels — project code, customer reference, internal status. Up to 10, each up to 40 characters. Lowercased and de-duplicated server-side. |
|
|
Language
|
locale | string |
Language of everything the signer sees: signing page, invitation, reminders, completion email. BCP-47 code, e.g. nl, nl-BE, en-GB, de, fr. Leave empty to inherit the language of the Certyneo account sending the envelope. An unsupported code is rejected with a 400. |
|
|
Redirect URL
|
redirectUrl | string |
Where the signer is sent after signing. Replaces the default Certyneo call-to-action with a single "Continue" button pointing here. Must start with https:// — anything else is rejected with a 400. |
|
|
Initials on every page
|
initialsOnEveryPage | boolean |
Automatically stamp the signer's initials at the bottom of every page of every document, in addition to any field you place yourself. No per-page setup needed — the signer fills their initials once and it applies everywhere. Skips a page where that signer already has a field (e.g. the signature on the last page). |
|
|
Workspace
|
workspaceId | string |
Create the envelope in a shared workspace so every member of that workspace can see and follow it up. Leave empty to keep it in your own account. You must own the workspace or be a member of it. |
Returns
- Body
- Envelope
Delete draft envelope
Delete an envelope that was never sent — a flow that failed halfway, a wrong document. DRAFT only: once an envelope has gone out, this returns an error and you cannot recall it from a flow.
Parameters
| Name | Key | Required | Type | Description |
|---|---|---|---|---|
|
Envelope ID
|
id | True | string |
Identifier of the draft envelope to delete. |
Returns
- Body
- DeleteResult
Download audit trail
Get the evidence file for a completed envelope — who signed, when, from which IP, with which authentication factors. Archive it alongside the signed PDF: it is what an eIDAS dispute turns on.
Parameters
| Name | Key | Required | Type | Description |
|---|---|---|---|---|
|
Envelope ID
|
id | True | string |
Identifier of the envelope whose audit trail you want to download. |
Returns
- response
- binary
Download signed document
Get the signed PDF, certificate page included. Only once the envelope is COMPLETED — before that it returns 409, so trigger on "Envelope completed" rather than polling.
Parameters
| Name | Key | Required | Type | Description |
|---|---|---|---|---|
|
Envelope ID
|
id | True | string |
Identifier of the envelope whose signed document you want to download. |
Returns
- response
- binary
Get envelope
Get the current status and details of an envelope.
Parameters
| Name | Key | Required | Type | Description |
|---|---|---|---|---|
|
Envelope ID
|
id | True | string |
Identifier of the envelope to retrieve. |
Returns
- Body
- Envelope
List envelopes
Retrieve a paginated list of envelopes.
Parameters
| Name | Key | Required | Type | Description |
|---|---|---|---|---|
|
Page
|
page | integer |
Which page of results to return. Starts at 1. |
|
|
Page size
|
limit | integer |
How many envelopes to return per page. |
|
|
Status
|
status | string |
Return only the envelopes in this status. Leave empty to return every status. |
Returns
- Body
- EnvelopeList
List templates
Returns your saved envelope templates. Used to power the template picker on "Create envelope".
Returns
- Body
- TemplateList
Send envelope
Dispatch a DRAFT envelope to its recipients for signature — this is the step that actually sends the email. "Create envelope" only saves it as a draft; it does not send anything on its own. Always chain this action right after "Create envelope" in your flow, using the envelope ID it returned.
Parameters
| Name | Key | Required | Type | Description |
|---|---|---|---|---|
|
Envelope ID
|
id | True | string |
Identifier of the draft envelope to dispatch to its recipients. |
Returns
- Body
- Envelope
Upload document
Upload a PDF or image (max 50 MB). Returns a document ID — pass it to "Create envelope" under "Documents".
Parameters
| Name | Key | Required | Type | Description |
|---|---|---|---|---|
|
File
|
file | True | file |
The PDF or image to upload, 50 MB at most. |
|
Document name
|
name | string |
Name to file the document under. Defaults to the uploaded file's own name. |
Returns
- Body
- Document
Triggers
| When an envelope event occurs |
Triggers a flow every time one of the selected events happens on any of your envelopes (e.g. signed, completed, declined). Backed by a real-time webhook — no polling. |
When an envelope event occurs
Triggers a flow every time one of the selected events happens on any of your envelopes (e.g. signed, completed, declined). Backed by a real-time webhook — no polling.
Parameters
| Name | Key | Required | Type | Description |
|---|---|---|---|---|
|
Events
|
events | True | array of string |
Which envelope/recipient events should trigger this flow. |
Returns
Delivered signed with HMAC-SHA256 in the X-Certyneo-Signature header (hex digest of the raw JSON body, keyed with the subscription's secret). Verify it before trusting the payload in a flow that acts on it (see /developers/webhooks).
- Body
- WebhookEventPayload
Definitions
DeleteResult
| Name | Path | Type | Description |
|---|---|---|---|
|
Success
|
success | boolean |
True when the resource was deleted. |
Pagination
| Name | Path | Type | Description |
|---|---|---|---|
|
total
|
total | integer | |
|
page
|
page | integer | |
|
pageSize
|
pageSize | integer | |
|
pages
|
pages | integer |
Template
| Name | Path | Type | Description |
|---|---|---|---|
|
id
|
id | string | |
|
name
|
name | string | |
|
description
|
description | string | |
|
signerCount
|
signerCount | integer | |
|
documentCount
|
documentCount | integer |
TemplateList
| Name | Path | Type | Description |
|---|---|---|---|
|
data
|
data | array of Template | |
|
pagination
|
pagination | Pagination |
Recipient
| Name | Path | Type | Description |
|---|---|---|---|
|
Recipient email
|
string | ||
|
Recipient name
|
name | string | |
|
Role
|
role | string | |
|
status
|
status | string | |
|
signedAt
|
signedAt | string | |
|
Access token
|
accessToken | string |
Opens this recipient's signing page at https://certyneo.com/sign/<token>. In sandbox no invitation email goes out, so this is how you sign a test envelope yourself. Returned by "Create envelope" and "Send envelope" — not by "Get envelope", where it stays empty. Treat it as a credential: anyone holding it can sign as this recipient, so don't log it or drop it in a spreadsheet. |
Document
| Name | Path | Type | Description |
|---|---|---|---|
|
id
|
id | string | |
|
name
|
name | string | |
|
mimeType
|
mimeType | string | |
|
size
|
size | integer | |
|
status
|
status | string |
Envelope
| Name | Path | Type | Description |
|---|---|---|---|
|
id
|
id | string | |
|
subject
|
subject | string | |
|
message
|
message | string | |
|
status
|
status | string | |
|
signatureLevel
|
signatureLevel | string | |
|
recipients
|
recipients | array of Recipient | |
|
expiresAt
|
expiresAt | string | |
|
createdAt
|
createdAt | string | |
|
completedAt
|
completedAt | string |
EnvelopeList
| Name | Path | Type | Description |
|---|---|---|---|
|
data
|
data | array of Envelope | |
|
pagination
|
pagination | Pagination |
WebhookEventPayload
Delivered signed with HMAC-SHA256 in the X-Certyneo-Signature header (hex digest of the raw JSON body, keyed with the subscription's secret). Verify it before trusting the payload in a flow that acts on it (see /developers/webhooks).
| Name | Path | Type | Description |
|---|---|---|---|
|
event
|
event | string | |
|
timestamp
|
timestamp | date-time | |
|
Envelope ID
|
data.envelopeId | string |
Always present. Feed it into "Get envelope" or "Download signed document". |
|
Subject
|
data.subject | string |
Present on envelope events only. |
|
Status
|
data.status | string | |
|
Signature level
|
data.signatureLevel | string |
Present on envelope.completed and recipient.signed. |
|
Advanced signature signers with a personal key
|
data.aesSignerCount | integer |
envelope.completed on an ADVANCED envelope only. |
|
Advanced signature certificate serial
|
data.aesCertificateSerial | string |
recipient.signed, when the signer signed with a personal advanced-signature key. |
|
Advanced signature certificate SHA256
|
data.aesCertificateSha256 | string |
recipient.signed, when the signer signed with a personal advanced-signature key. |
|
Advanced signature manifest SHA256
|
data.aesManifestSha256 | string |
recipient.signed, when the signer signed with a personal advanced-signature key. |
|
Advanced signature timestamped
|
data.aesTimestamped | boolean |
recipient.signed, when the signer signed with a personal advanced-signature key. |
|
Recipient count
|
data.recipientCount | integer |
Present on envelope events only. |
|
Signed count
|
data.signedCount | integer |
Present on envelope events only. |
|
Recipient ID
|
data.recipientId | string |
Present on recipient events only. |
|
Recipient email
|
data.email | string |
Present on recipient events only. |
|
Recipient name
|
data.name | string |
Present on recipient events only. |
|
Recipient role
|
data.role | string |
Present on recipient events only. |
|
Signed at
|
data.signedAt | date-time |
Present on recipient events only. |
|
Viewed at
|
data.viewedAt | date-time |
Present on recipient events only. |
binary
This is the basic data type 'binary'.