How to Use Signer Authentication via SMS as an API User
We are happy to announce that our Signer Authentication feature is now enabled for our eSignature API users as well.
Signer Authentication via SMS is an option you can set for each signer of a document, requiring them to use an SMS code they receive to their mobile phone in order to gain access to the document.
Signer Authentication adds an extra level of assurance that the documents you are sending for signature are only accessed by the intended person.
What specific improvements did we make?
We added two optional attributes to the signer
object:
The first attribute is signer_authentication_sms_enabled
which indicates whether Signer Authentication should be enabled for the signer.
The second attribute, signer_authentication_phone_number
, is used to enter the phone number to which SMS authorizations will be delivered. Details can be found here.
Additionally, we extended our Error messages model with new error messages. New error messages help developers and integrators to better understand what went wrong if they did not provide correct data or if an issue occurred during the signing process.
For example, our API customers will get notified if:
- the phone number they entered for the signer is not in the supported format
- the Signer Authentication feature is disabled for that specific account for any reason
- the Signer Authentication Overage is not allowed for that specific account
You can find more information about error messages here.
Additional technical details and concerns
Xodo Sign also supports PIN verification however, combining PIN verification and Signer Authentication for the same signer is not supported and will return the following error if attempted:
signer_authentication_combined_with_pin_not_supported
The following example shows how to prepare a request for the Xodo Sign eSignature API, enabling Signer Authentication for one out of 2 signers:
As a response, you'll receive a common document structure, extended with signer authentication fields:
Additionally, a new event log entry type has been added, with the information that signer authentication has been enabled (in this example, for one signer):
The signer's experience
The signer receives the document for signature via e-mail.
On opening the document, the interface is blurred and the access restricted.
(the same way as when using the Signer PIN feature).
A pop-up window gives you the option to click to receive your confirmation code via SMS text to unlock the document.
Click the Send Code to Mobile Number ... button in the pop-up window.
You will receive an SMS text message shortly after. (typical delay 5-10 seconds)
The sender of the SMS text might not appear as Xodo Sign, but as a phone number or a name such as "SMS Info".
Enter the received code in the pop-up window and click on Authenticate.
If you entered the correct code, you now have access to the document and can sign it.
If you have any questions about our Signer Authentication for API users which are not covered in this blog post or in our help center article, don't hesitate to contact our friendly customer service team.