> ## Documentation Index
> Fetch the complete documentation index at: https://staging.docs.flowsign.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Power Automate

> Trigger Power Automate flows from FlowSign events and create or send packages from a flow.

You can automate FlowSign with Power Automate using its own HTTP trigger and action: trigger a flow when a package completes, or create and send a package from another system through a flow.

## Receiving events

Create a webhook endpoint in FlowSign at **Settings > Webhooks** ([my.flowsign.app/settings/webhooks](https://my.flowsign.app/settings/webhooks)), or with the API (see [Webhooks](/webhooks/overview)).

1. Create a flow that starts with **When an HTTP request is received** and save it once so Power Automate generates its URL.
2. Paste that URL into the endpoint's **URL** field in FlowSign.
3. Tick the events to subscribe to (for example **Package Completed**) and save. FlowSign shows the endpoint's signing secret once; store it.

Every delivery is a `POST` with three headers and a JSON body:

| Header                   | Value                                                                   |
| ------------------------ | ----------------------------------------------------------------------- |
| `X-FlowSign-Event`       | The event name, for example `PACKAGE_COMPLETED`                         |
| `X-FlowSign-Delivery-Id` | A stable id for this delivery; retries reuse it                         |
| `X-FlowSign-Signature`   | Hex-encoded HMAC-SHA256 of the raw body, keyed with the endpoint secret |

```json theme={null}
{
  "event": "PACKAGE_COMPLETED",
  "timestamp": "2026-09-17T03:40:11.000Z",
  "data": {
    "packageId": "pkg_9f3c2e",
    "packageTitle": "Employment agreement: Ana Reid",
    "completedAt": "2026-09-17T03:40:10.884Z"
  }
}
```

`data` differs per event. See [Events](/webhooks/events) for every event's shape.

## Verifying the signature

<Warning>
  Skipping verification means your flow acts on any unauthenticated `POST` to its trigger URL, not just genuine FlowSign deliveries.
</Warning>

Compute a hex HMAC-SHA256 of the raw body with the endpoint secret and compare it to `X-FlowSign-Signature`. Power Automate's workflow expression language has no built-in keyed-hash function, so this isn't a one-line expression the way it is on the other platforms. The practical option is a small HTTP endpoint you control (an Azure Function is the usual choice) that takes the raw body and the signature header, does the HMAC-SHA256 comparison, and returns a boolean; call it from an **HTTP** action right after the trigger and branch the flow on its response with a **Condition**.

Set the body of that request to the trigger's raw output and the `X-FlowSign-Signature` header along with it, so the function verifies against the exact bytes FlowSign signed rather than Power Automate's re-serialised JSON.

## Calling the API

Use the **HTTP** action for any FlowSign API call.

Base URL: `https://my.flowsign.app`. Every request needs:

| Header           | Value                                                                                |
| ---------------- | ------------------------------------------------------------------------------------ |
| `Authorization`  | `Bearer fsk_your_key_here`                                                           |
| `X-Workspace-Id` | Optional; the workspace to act in. Omit to use the organisation's default workspace. |

Create the key at **Settings > API keys**; see [Authentication](/api-reference/authentication). Keep it in an environment variable or Azure Key Vault reference rather than typing it into the action.

### List packages

Method **GET**, URI `https://my.flowsign.app/api/v1/packages?status=IN_PROGRESS`.

```json theme={null}
{
  "data": {
    "packages": [
      {
        "id": "pkg_9f3c2e",
        "title": "Employment agreement: Ana Reid",
        "status": "IN_PROGRESS",
        "description": null,
        "recipients": [
          { "name": "Ana Reid", "email": "ana@example.com", "action": "Sign", "actionType": "SIGNER", "signed": false }
        ],
        "documentsCount": 1,
        "signingProgress": { "completed": 0, "total": 1 },
        "createdAt": "2026-09-17T01:12:44.000Z",
        "updatedAt": "2026-09-17T01:12:50.000Z",
        "expiresAt": null,
        "completedAt": null
      }
    ],
    "totalCount": 1,
    "page": 1,
    "pageSize": 25
  }
}
```

### Create a package from a template

Method **POST**, URI `https://my.flowsign.app/api/v1/packages/from-template`, body:

```json theme={null}
{
  "templateId": "tmpl_abc123",
  "recipients": [
    { "role": "Employee", "name": "Ana Reid", "email": "ana@example.com" },
    { "role": "Manager", "name": "Ben Toa", "email": "ben@example.com" }
  ],
  "fields": { "start_date": "1 October 2026" },
  "externalId": "order_4471",
  "status": "sent"
}
```

`role` must match one of the template's role names and `fields` keys must match its merge field keys; a mismatch returns `422` with the unknown or missing names in `details`. `status` is `"draft"` (default) or `"sent"`, which sends immediately. `externalId` is optional and makes the call idempotent: retrying with the same value returns the existing package instead of creating a duplicate.

```json theme={null}
{ "data": { "packageId": "pkg_9f3c2e", "externalId": "order_4471", "status": "IN_PROGRESS" } }
```

Creating requires the key's user to have the send permission; see [Errors](/api-reference/errors) for the full status code list.

## Plan and cost notes

Power Automate's generic **HTTP** action is a premium connector, so both calling the API and (if you go that route) the verification callout need a Power Automate plan that includes premium connectors, not just a Microsoft 365 seat. **When an HTTP request is received** is a standard trigger and needs no premium licence on its own.
