{"_id":"@absolutejs/esign-dropbox-sign","name":"@absolutejs/esign-dropbox-sign","dist-tags":{"latest":"0.0.1"},"versions":{"0.0.1":{"name":"@absolutejs/esign-dropbox-sign","version":"0.0.1","description":"Dropbox Sign adapter for @absolutejs/esign","type":"module","license":"BSL-1.1","author":{"name":"Alex Kahn"},"sideEffects":false,"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"bun build src/index.ts --outdir dist --target node --external '@absolutejs/esign' && tsc --project tsconfig.build.json","typecheck":"tsc --noEmit","test":"bun test ../test","check:package":"absolute-changelog check","prepublishOnly":"bun run typecheck && bun run test && bun run build && bun run check:package"},"devDependencies":{"typescript":"^5.9.3","@types/node":"^22.0.0","@absolutejs/esign":"0.0.1","@absolutejs/changelog":"^0.6.0"},"peerDependencies":{"@absolutejs/esign":"^0.0.1"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/absolutejs/esign-adapters.git","directory":"dropbox-sign"},"_id":"@absolutejs/esign-dropbox-sign@0.0.1","gitHead":"2488cbe01e4ca0bf269bf224a0a05d5761988fbc","bugs":{"url":"https://github.com/absolutejs/esign-adapters/issues"},"homepage":"https://github.com/absolutejs/esign-adapters#readme","_nodeVersion":"22.14.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-oF7648VDOnHnirr3kXH4akQqjx9S+sVINUFuQ/cEf0oHA10g2N6ohMdBjTuR0rfCjvvd5SwYcBut2ezQbBv/lA==","shasum":"c17f5d23fb0a75646d6edae7424f2f911328bb2b","tarball":"https://registry.npmjs.org/@absolutejs/esign-dropbox-sign/-/esign-dropbox-sign-0.0.1.tgz","fileCount":7,"unpackedSize":16471,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIGbX15pXE+KjO+Hk0aVrbiqfkwaqHuU8wkoLVaLjuo3aAiEA1LslHOJLo7KbuPhYZ0qx2c00uLizo8+KhAF18BLU82c="}]},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"directories":{},"maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/esign-dropbox-sign_0.0.1_1789096920016_0.5984728667164669"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-11T03:21:59.832Z","0.0.1":"2026-09-11T03:22:00.165Z","modified":"2026-09-11T03:22:00.409Z"},"maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"description":"Dropbox Sign adapter for @absolutejs/esign","homepage":"https://github.com/absolutejs/esign-adapters#readme","repository":{"type":"git","url":"git+https://github.com/absolutejs/esign-adapters.git","directory":"dropbox-sign"},"author":{"name":"Alex Kahn"},"bugs":{"url":"https://github.com/absolutejs/esign-adapters/issues"},"license":"BSL-1.1","readme":"# @absolutejs/esign-dropbox-sign\n\n```ts\nimport { dropboxSign } from '@absolutejs/esign-dropbox-sign';\nconst provider = dropboxSign({\n  clientId: process.env.DROPBOX_SIGN_CLIENT_ID!,\n  accessToken: () => tokenResolver.getFreshToken(),\n  webhookApiKey: process.env.DROPBOX_SIGN_WEBHOOK_API_KEY!,\n  testMode: true,\n});\n```\n\nSupports OAuth bearer tokens or an explicitly configured API key. OAuth tokens are distinct from the API key used to verify callback event hashes. `dropboxSignOAuth` provides authorization URLs, code exchange, refresh, and account discovery. The host must validate OAuth state and persist grants securely.\n\nConfigure the API app's callback URL and allowed embedded domain. App approval is required for production embedded/OAuth use. Keep `testMode: true` until the app is approved and live verification is complete. Test-mode requests are not production signatures.\n\nUse the official `hellosign-embedded` browser client to open the returned signing URL with `clientId`; honor its documented domain checks and configured return flow. Do not treat a browser `sign` or `close` event as completion. Reconcile the saved request with the backend.\n\nDropbox sends callbacks as multipart form data. Pass the exact `json` field to `verifyWebhook`. Return `Hello API Event Received` after processing. The HMAC covers event time/type only; **always fetch the saved request again before updating agreement state**. Completed-document downloads contain the audit trail; a separate audit endpoint is not offered by this adapter.\n\nReferences: [Embedded signing](https://developers.hellosign.com/docs/embedded-signing/walkthrough), [callback verification](https://developers.hellosign.com/docs/guides/events-and-callbacks/walkthrough), [OAuth](https://developers.hellosign.com/docs/guides/o-auth/walkthrough), [field placement](https://developers.hellosign.com/api/manual-reference-pages/constants).\n","readmeFilename":"README.md","_rev":"1-d42fded702fbc70301e5c1c0d5afebf2"}