Certyneo (Preview)

Send documents for eIDAS-compliant electronic signature, create envelopes from templates, and trigger flows on signature events such as sent, signed, completed and declined.

This connector is available in the following products and regions:

Service Class Regions
Copilot Studio Premium All Power Automate regions except the following:
     -   US Government (GCC)
     -   US Government (GCC High)
     -   China Cloud operated by 21Vianet
     -   US Department of Defense (DoD)
Logic Apps Standard All Logic Apps regions except the following:
     -   Azure Government regions
     -   Azure China regions
     -   US Department of Defense (DoD)
Power Apps Premium All Power Apps regions except the following:
     -   US Government (GCC)
     -   US Government (GCC High)
     -   China Cloud operated by 21Vianet
     -   US Department of Defense (DoD)
Power Automate Premium All Power Automate regions except the following:
     -   US Government (GCC)
     -   US Government (GCC High)
     -   China Cloud operated by 21Vianet
     -   US Department of Defense (DoD)
Contact
Name Certyneo Support
URL https://certyneo.com/fr/contact
Email support@certyneo.com
Connector Metadata
Publisher Certyneo
Website https://certyneo.com
Privacy policy https://certyneo.com/fr/legal/privacy
Categories IT Operations;Productivity

Certyneo

Certyneo is an eIDAS-compliant electronic signature service. This connector lets a flow send documents out for signature, react in real time when a signer acts, and file the signed PDF and its evidence file wherever the rest of the business keeps its records.

The typical flow is three steps: a document lands somewhere (a document library, a mailbox, a form submission), the flow creates and sends an envelope, and a second flow triggered by envelope.completed downloads the signed PDF and stores it.

Publisher

Certyneo

Prerequisites

You need a Certyneo account on a plan that includes API access. Free and Personal plans can create API keys and subscribe to events, but they only ever receive events for sandbox envelopes — see Known issues and limitations below.

How to get credentials

The connector authenticates with a Certyneo API key.

  1. Sign in to Certyneo and open Settings → API Keys.
  2. Create a key. Live keys start with sk_live_, sandbox keys with sk_test_.
  3. When the connector asks for the API key, paste the word Bearer, a space, and then the key — for example Bearer sk_live_abc123. Certyneo expects the word Bearer in front of the key, and a key pasted on its own is rejected with 401.

The key carries scopes. A key without envelopes:write cannot create or send, and a key without webhooks:write cannot back the trigger. Grant the scopes the flow actually needs.

Testing without emailing anyone

A sandbox key (sk_test_) exercises the whole pipeline without sending a single invitation email. Nothing reaches a real inbox, which also means nobody can reach the signing page from an email — so Create envelope and Send envelope return an Access token for each recipient instead. Open https://certyneo.com/sign/<access token> to sign the test envelope yourself.

Treat that token as a credential: anyone holding it can sign as that recipient. Don't log it, and don't drop it into a spreadsheet.

Supported operations

Trigger

When an envelope event occurs — fires on the events you select, backed by a real webhook rather than polling. Available events:

envelope.created, envelope.sent, envelope.completed, envelope.declined, envelope.voided, envelope.expired, envelope.returned_to_sender, envelope.resubmitted, recipient.signed, recipient.viewed, recipient.approved.

Every payload carries Envelope ID, on both envelope and recipient events. That is the value to feed into the actions below.

Deliveries are signed with HMAC-SHA256 in the X-Certyneo-Signature header — a hex digest of the raw JSON body, keyed with the subscription secret. Verify it before a flow acts on the payload.

Actions

Action What it does
List templates Your saved envelope templates. Powers the template picker.
Create envelope Creates a DRAFT envelope, from a template or from uploaded documents.
Send envelope Dispatches a DRAFT envelope to its recipients.
Get envelope Current status and recipient details.
List envelopes Paginated list, filterable by status.
Upload document Uploads a PDF or image and returns a document ID.
Download signed document The signed PDF, certificate page included.
Download audit trail The evidence file: who signed, when, from which IP, with which factors.
Delete draft envelope Deletes an envelope that was never sent.

Known issues and limitations

A sent envelope cannot be recalled from a flow. Delete draft envelope only accepts envelopes still in DRAFT — a flow that failed halfway, a wrong document. Once an envelope has gone out it returns 409, and there is no cancel operation in the API today.

recipient.signed fires before the signed PDF exists, including for the last signer. Assembling and sealing the final document happens after that event, so a flow that triggers on recipient.signed and immediately calls Download signed document gets 409 every time. This is not a race you can win with a delay — trigger on envelope.completed instead, which fires once the PDF is on disk.

Free and Personal plans receive sandbox events only. Both can create a subscription and the trigger will show as healthy, but live envelopes never reach it. If a trigger appears to do nothing on real traffic, check the plan before anything else.

Use a template or documents, never both. A template brings its own documents and its own signature fields. When you build from uploaded documents instead, you must also supply Fields — an envelope whose signer has nowhere to sign is refused at send time with 409 signer_without_field, not at create time.

Prefer anchor text over coordinates. Placing a field by quoting a phrase from the document ("Signature du client") survives a layout change and needs no measuring. X and Y remain as a fallback so a field whose anchor is not found keeps a literal position instead of disappearing.

Uploads are capped at 50 MB per document.

A purged document returns 410, not 409. 409 means "not ready yet, come back after envelope.completed". 410 means the signed document was deliberately deleted under the retention policy and is never coming back. A retry loop should give up on 410.

Common errors and remedies

Response Cause Remedy
401 Key missing, or pasted without Bearer in front Re-enter the connection as Bearer sk_live_...
403 The key lacks the scope for this operation Re-issue the key with the scopes the flow needs
409 on download Envelope is not COMPLETED yet Trigger on envelope.completed rather than polling
409 on send signer_without_field — a signer has no signature field Add Fields, or build from a template
409 on delete The envelope has already been sent Sent envelopes cannot be deleted or recalled
410 on download The document was purged under the retention policy Stop retrying; the file is gone

Errors carry both a human-readable error message and a stable code. Branch on code — the message can be reworded.

Support

Creating a connection

The connector supports the following authentication types:

Default Parameters for creating connection. All regions Not shareable

Default

Applicable: All regions

Parameters for creating connection.

This is not shareable connection. If the power app is shared with another user, another user will be prompted to create new connection explicitly.

Name Type Description Required
API Key securestring The API Key for this api True

Actions

Create envelope

Create a new envelope in DRAFT status, either from a saved template or straight from documents you uploaded with "Upload document". Fill in exactly one of "Template" or "Documents". With documents, add "Fields" as well so each signer has somewhere to sign — the simplest way is to quote a phrase from the document in "Anchor text" instead of working out coordinates. IMPORTANT: this action only creates the envelope — no email is sent yet. Add the "Send envelope" action right after this one in your flow to actually dispatch it to recipients.

Delete draft envelope

Delete an envelope that was never sent — a flow that failed halfway, a wrong document. DRAFT only: once an envelope has gone out, this returns an error and you cannot recall it from a flow.

Download audit trail

Get the evidence file for a completed envelope — who signed, when, from which IP, with which authentication factors. Archive it alongside the signed PDF: it is what an eIDAS dispute turns on.

Download signed document

Get the signed PDF, certificate page included. Only once the envelope is COMPLETED — before that it returns 409, so trigger on "Envelope completed" rather than polling.

Get envelope

Get the current status and details of an envelope.

List envelopes

Retrieve a paginated list of envelopes.

List templates

Returns your saved envelope templates. Used to power the template picker on "Create envelope".

Send envelope

Dispatch a DRAFT envelope to its recipients for signature — this is the step that actually sends the email. "Create envelope" only saves it as a draft; it does not send anything on its own. Always chain this action right after "Create envelope" in your flow, using the envelope ID it returned.

Upload document

Upload a PDF or image (max 50 MB). Returns a document ID — pass it to "Create envelope" under "Documents".

Create envelope

Create a new envelope in DRAFT status, either from a saved template or straight from documents you uploaded with "Upload document". Fill in exactly one of "Template" or "Documents". With documents, add "Fields" as well so each signer has somewhere to sign — the simplest way is to quote a phrase from the document in "Anchor text" instead of working out coordinates. IMPORTANT: this action only creates the envelope — no email is sent yet. Add the "Send envelope" action right after this one in your flow to actually dispatch it to recipients.

Parameters

Name Key Required Type Description
Subject
subject True string

Envelope subject / title.

Message
message string

Message shown to recipients.

Template
templateId string

Pick a saved template. Use this OR "Documents", not both — a template brings its own documents and signature fields.

Documents
documentIds array of string

Document IDs from "Upload document". Use this OR "Template", not both. When you use documents, add "Fields" too — an envelope whose signer has no signature field is refused at send time.

Signer email
recipientEmail True string

Must match one of the recipients above, exactly.

Document number
documentIndex integer

Which document carries this field, counting from 0 in the order given above. Leave empty when there is only one document.

Page
pageNumber True integer
Field type
fieldType True string
Anchor text (recommended)
anchorText string

Text to look for in the document — the field is placed next to it, so you don't need coordinates. Case-insensitive, and found even when the PDF splits the phrase across runs. Leave empty to use X/Y instead.

Anchor placement
anchorPlacement string

Where to put the field relative to the anchor text.

Anchor occurrence
anchorIndex integer

Which occurrence to use, counting from 0, when the anchor text appears several times.

X
x True number

Points from the left edge. Ignored when the anchor is found — kept as a fallback so the field never vanishes.

Y
y True number

Points from the TOP edge. Ignored when the anchor is found — kept as a fallback.

Width
width True number
Height
height True number
Recipient email
email True string
Recipient name
name string
Role
role string
status
status string
signedAt
signedAt string
Access token
accessToken string

Opens this recipient's signing page at https://certyneo.com/sign/<token>. In sandbox no invitation email goes out, so this is how you sign a test envelope yourself. Returned by "Create envelope" and "Send envelope" — not by "Get envelope", where it stays empty. Treat it as a credential: anyone holding it can sign as this recipient, so don't log it or drop it in a spreadsheet.

Signature level
signatureLevel string
Expires at
expiresAt date-time
Category
category string

Business classification shown on the envelope list. Leave empty and Certyneo infers one from the subject.

Tags
tags array of string

Free-form labels — project code, customer reference, internal status. Up to 10, each up to 40 characters. Lowercased and de-duplicated server-side.

Language
locale string

Language of everything the signer sees: signing page, invitation, reminders, completion email. BCP-47 code, e.g. nl, nl-BE, en-GB, de, fr. Leave empty to inherit the language of the Certyneo account sending the envelope. An unsupported code is rejected with a 400.

Redirect URL
redirectUrl string

Where the signer is sent after signing. Replaces the default Certyneo call-to-action with a single "Continue" button pointing here. Must start with https:// — anything else is rejected with a 400.

Initials on every page
initialsOnEveryPage boolean

Automatically stamp the signer's initials at the bottom of every page of every document, in addition to any field you place yourself. No per-page setup needed — the signer fills their initials once and it applies everywhere. Skips a page where that signer already has a field (e.g. the signature on the last page).

Workspace
workspaceId string

Create the envelope in a shared workspace so every member of that workspace can see and follow it up. Leave empty to keep it in your own account. You must own the workspace or be a member of it.

Returns

Body
Envelope

Delete draft envelope

Delete an envelope that was never sent — a flow that failed halfway, a wrong document. DRAFT only: once an envelope has gone out, this returns an error and you cannot recall it from a flow.

Parameters

Name Key Required Type Description
Envelope ID
id True string

Identifier of the draft envelope to delete.

Returns

Download audit trail

Get the evidence file for a completed envelope — who signed, when, from which IP, with which authentication factors. Archive it alongside the signed PDF: it is what an eIDAS dispute turns on.

Parameters

Name Key Required Type Description
Envelope ID
id True string

Identifier of the envelope whose audit trail you want to download.

Returns

response
binary

Download signed document

Get the signed PDF, certificate page included. Only once the envelope is COMPLETED — before that it returns 409, so trigger on "Envelope completed" rather than polling.

Parameters

Name Key Required Type Description
Envelope ID
id True string

Identifier of the envelope whose signed document you want to download.

Returns

response
binary

Get envelope

Get the current status and details of an envelope.

Parameters

Name Key Required Type Description
Envelope ID
id True string

Identifier of the envelope to retrieve.

Returns

Body
Envelope

List envelopes

Retrieve a paginated list of envelopes.

Parameters

Name Key Required Type Description
Page
page integer

Which page of results to return. Starts at 1.

Page size
limit integer

How many envelopes to return per page.

Status
status string

Return only the envelopes in this status. Leave empty to return every status.

Returns

List templates

Returns your saved envelope templates. Used to power the template picker on "Create envelope".

Returns

Send envelope

Dispatch a DRAFT envelope to its recipients for signature — this is the step that actually sends the email. "Create envelope" only saves it as a draft; it does not send anything on its own. Always chain this action right after "Create envelope" in your flow, using the envelope ID it returned.

Parameters

Name Key Required Type Description
Envelope ID
id True string

Identifier of the draft envelope to dispatch to its recipients.

Returns

Body
Envelope

Upload document

Upload a PDF or image (max 50 MB). Returns a document ID — pass it to "Create envelope" under "Documents".

Parameters

Name Key Required Type Description
File
file True file

The PDF or image to upload, 50 MB at most.

Document name
name string

Name to file the document under. Defaults to the uploaded file's own name.

Returns

Body
Document

Triggers

When an envelope event occurs

Triggers a flow every time one of the selected events happens on any of your envelopes (e.g. signed, completed, declined). Backed by a real-time webhook — no polling.

When an envelope event occurs

Triggers a flow every time one of the selected events happens on any of your envelopes (e.g. signed, completed, declined). Backed by a real-time webhook — no polling.

Parameters

Name Key Required Type Description
Events
events True array of string

Which envelope/recipient events should trigger this flow.

Returns

Delivered signed with HMAC-SHA256 in the X-Certyneo-Signature header (hex digest of the raw JSON body, keyed with the subscription's secret). Verify it before trusting the payload in a flow that acts on it (see /developers/webhooks).

Definitions

DeleteResult

Name Path Type Description
Success
success boolean

True when the resource was deleted.

Pagination

Name Path Type Description
total
total integer
page
page integer
pageSize
pageSize integer
pages
pages integer

Template

Name Path Type Description
id
id string
name
name string
description
description string
signerCount
signerCount integer
documentCount
documentCount integer

TemplateList

Name Path Type Description
data
data array of Template
pagination
pagination Pagination

Recipient

Name Path Type Description
Recipient email
email string
Recipient name
name string
Role
role string
status
status string
signedAt
signedAt string
Access token
accessToken string

Opens this recipient's signing page at https://certyneo.com/sign/<token>. In sandbox no invitation email goes out, so this is how you sign a test envelope yourself. Returned by "Create envelope" and "Send envelope" — not by "Get envelope", where it stays empty. Treat it as a credential: anyone holding it can sign as this recipient, so don't log it or drop it in a spreadsheet.

Document

Name Path Type Description
id
id string
name
name string
mimeType
mimeType string
size
size integer
status
status string

Envelope

Name Path Type Description
id
id string
subject
subject string
message
message string
status
status string
signatureLevel
signatureLevel string
recipients
recipients array of Recipient
expiresAt
expiresAt string
createdAt
createdAt string
completedAt
completedAt string

EnvelopeList

Name Path Type Description
data
data array of Envelope
pagination
pagination Pagination

WebhookEventPayload

Delivered signed with HMAC-SHA256 in the X-Certyneo-Signature header (hex digest of the raw JSON body, keyed with the subscription's secret). Verify it before trusting the payload in a flow that acts on it (see /developers/webhooks).

Name Path Type Description
event
event string
timestamp
timestamp date-time
Envelope ID
data.envelopeId string

Always present. Feed it into "Get envelope" or "Download signed document".

Subject
data.subject string

Present on envelope events only.

Status
data.status string
Signature level
data.signatureLevel string

Present on envelope.completed and recipient.signed.

Advanced signature signers with a personal key
data.aesSignerCount integer

envelope.completed on an ADVANCED envelope only.

Advanced signature certificate serial
data.aesCertificateSerial string

recipient.signed, when the signer signed with a personal advanced-signature key.

Advanced signature certificate SHA256
data.aesCertificateSha256 string

recipient.signed, when the signer signed with a personal advanced-signature key.

Advanced signature manifest SHA256
data.aesManifestSha256 string

recipient.signed, when the signer signed with a personal advanced-signature key.

Advanced signature timestamped
data.aesTimestamped boolean

recipient.signed, when the signer signed with a personal advanced-signature key.

Recipient count
data.recipientCount integer

Present on envelope events only.

Signed count
data.signedCount integer

Present on envelope events only.

Recipient ID
data.recipientId string

Present on recipient events only.

Recipient email
data.email string

Present on recipient events only.

Recipient name
data.name string

Present on recipient events only.

Recipient role
data.role string

Present on recipient events only.

Signed at
data.signedAt date-time

Present on recipient events only.

Viewed at
data.viewedAt date-time

Present on recipient events only.

binary

This is the basic data type 'binary'.