If you're building a SaaS product that handles agreements (vendor onboarding, freelancer contracts, NDAs, leases), you'll eventually hit the same two requirements:
- Users want to know what they're signing. Auto-renewals, uncapped liability and missing clauses are easy to miss.
- The signature has to be legally usable, with an audit trail you can point to later.
Building both from scratch means wiring up a document parser, an LLM pipeline, signature placement, email delivery, tamper-evident sealing and audit logs. That's a lot of surface area for a feature that isn't your core product.
This post shows how to do it with a REST API instead.
What we're building
A flow where your app:
- Sends a contract for AI review (risk detection, clause extraction, plain-English summary)
- Sends the same document for eSignature
- Tracks the agreement status and receives a signing link
Indigo eSign combines AI contract analysis and eSignatures in one platform, so this can be a single request instead of two integrations.
The request
Here's a basic example in JavaScript:
// Analyze contract for risks & send for eSignature
const response = await fetch('https://indigoesign.com/api/v1/sign-request', {
method: 'POST',
headers: {
'Authorization': `Bearer ${API_KEY}`,
'Content-Type': 'application/json'
},
body: JSON.stringify({
title: 'Vendor MSA Agreement 2026',
enable_ai_review: true,
risk_threshold: 'medium',
signers: [
{ role: 'client', email: 'legal@company.com' }
]
})
});
const { risk_score, status, signing_url } = await response.json();
A few things worth noting:
-
enable_ai_reviewturns on the contract analysis for this request. -
risk_thresholdlets you control how sensitive the flagging is. -
signersdefines who signs and in what role. - The response gives you a
risk_score, the currentstatus, and asigning_urlyou can hand to the signer.
This snippet is the minimal shape of the call. For the full list of parameters (document upload, multiple signers, templates and webhooks), see the API documentation.
Use the risk score in your own logic
The interesting part isn't the call itself, it's what you do with the result. A few patterns that work well:
Gate the signing step. If the risk score is above your threshold, route the contract to a human reviewer before it goes out.
if (risk_score.startsWith('High')) {
await notifyLegalTeam({ title, risk_score });
} else {
await sendSigningLink(signing_url);
}
Show findings in your UI. Surface flagged clauses (for example, an auto-renewal notice period) next to the document so users can make an informed decision.
Log everything. Store the request ID, status changes and audit trail reference alongside your own records. If a contract is ever disputed, you'll want a clean paper trail.
What "legally binding" means here
Signatures created through the platform are designed to meet the US ESIGN Act, UETA and the EU eIDAS regulation. Each signed document gets a tamper-evident seal and an audit trail. That said, a few document types (wills and some family-law or court documents, for example) may still require a handwritten signature or notarization, so check your use case with counsel.
Also worth knowing: signers don't need an account. They sign through an email link on any device, which keeps friction low for external parties.
Limits and plans
API access depends on the plan. At the time of writing:
| Plan | Price | API access |
|---|---|---|
| Free | $0 | No API keys |
| Basic AI | $19.90/mo | 1 key, 1 API template |
| Pro AI + Signer | $49/mo | 10 keys, 50 templates, 1,000 requests/month |
| Enterprise | Custom | Custom webhooks and SLA |
Check the pricing page for current numbers. Currently only PDF documents are supported.
A note on AI review
AI risk flagging is a fast first pass, not a replacement for legal advice. It's best at catching the routine stuff (missing clauses, renewal traps, liability caps) so that your lawyer's time goes to the deals that need it. Design your UI so users understand that, and keep a human in the loop for high-stakes contracts.
Try it
You can create a free account to test the AI review and signing flow in the dashboard first, then grab an API key when you're ready to integrate.
If you're building something similar, I'd love to hear how you handle contract review in your product. Drop a comment below.

Top comments (0)