MostlySign

Sealing and verification

When the last signer finishes, MostlySign produces a final PDF that carries a certificate of completion and the audit trail, and applies a PAdES digital signature (the seal) using the platform certificate. It then asks an independent time-stamping authority for an RFC 3161 timestamp over the seal.

# Read the status, do not assume it

The envelope object tells you what actually happened:

Field Meaning
sealed true once the PDF carries the PAdES platform seal. false means the envelope completed while the sealing credential was unavailable. null before completion.
timestamped Whether an RFC 3161 timestamp from an independent authority is attached. null before completion.
events The audit trail, oldest first, capped at the 80 most recent entries.

# Honest-unsealed completion

If the platform sealing credential is not available at the moment of completion, the envelope still completes so that signers are not blocked, but it is recorded as sealed: false. The audit trail says “Completed WITHOUT cryptographic seal”, and the certificate of completion says so too: it does not imply a seal that is not there. Check sealed before you treat a document as sealed, and surface it if your users rely on the seal.

# Downloading

GET /{envelopeId}/download returns a link valid for 15 minutes. final: true means the completed document.

# Verifying

The seal is a standard PAdES signature, so a sealed PDF can be inspected in a PDF reader that supports signature validation or with an independent PAdES validator. MostlySign also offers a client-side check at /verify that runs in your browser; the file is not uploaded.