[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feSyDq3AjsABVrOLKG5wFiU7oToz5efSjdzVuXQs1Z1I":3},{"slug":4,"display_name":4,"profile_url":5,"plugin_count":6,"total_installs":7,"avg_security_score":8,"avg_patch_time_days":9,"trust_score":10,"computed_at":11,"plugins":12},"signdocsbrasil","https:\u002F\u002Fprofiles.wordpress.org\u002Fsigndocsbrasil\u002F",1,0,100,30,94,"2026-08-29T09:45:06.812Z",[13],{"slug":14,"name":15,"version":16,"author":4,"author_profile":5,"description":17,"short_description":18,"active_installs":7,"downloaded":19,"rating":7,"num_ratings":7,"last_updated":20,"tested_up_to":21,"requires_at_least":22,"requires_php":23,"tags":24,"homepage":30,"download_link":31,"security_score":8,"vuln_count":7,"unpatched_count":7,"last_vuln_date":32,"fetched_at":33},"signdocs-brasil","SignDocs Brasil","1.3.7","\u003Cp>SignDocs Brasil is the official WordPress plugin for \u003Cstrong>legally-binding electronic signatures in Brazil\u003C\u002Fstrong>. Embed signing flows on any page with a shortcode or Gutenberg block, send multi-signer envelopes (sequential or parallel), verify signed evidence directly from the WordPress admin, and track everything through an audit log with CSV export.\u003C\u002Fp>\n\u003Cp>Built on top of the official SignDocs Brasil PHP SDK (\u003Ccode>signdocs-brasil\u002Fsigndocs-brasil-php\u003C\u002Fcode>), the plugin leverages OAuth token caching shared across PHP-FPM workers, deterministic idempotency, webhook secret rotation with a grace window, and observability via \u003Ccode>RateLimit-*\u003C\u002Fcode> \u002F \u003Ccode>Deprecation\u003C\u002Fcode> \u002F \u003Ccode>Sunset\u003C\u002Fcode> response headers.\u003C\u002Fp>\n\u003Cp>The plugin targets the Brazilian market (compliance with MP 2.200-2\u002F2001, ICP-Brasil, NT65\u002FITI for INSS payroll loans), but works for any signing workflow worldwide. The signing UI itself is hosted on \u003Ccode>sign.signdocs.com.br\u003C\u002Fcode>, isolated from your WordPress install, so a compromised WordPress site cannot forge signatures.\u003C\u002Fp>\n\u003Ch4>Why SignDocs Brasil?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Brazilian compliance\u003C\u002Fstrong> — MP 2.200-2\u002F2001, PKCS#7\u002FCMS evidence package, ICP-Brasil A1\u002FA3 certificate support, NT65\u002FITI flow for INSS payroll loans\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Seven verification policies\u003C\u002Fstrong> — CLICK_ONLY, CLICK_PLUS_OTP, BIOMETRIC, BIOMETRIC_PLUS_OTP, DIGITAL_CERTIFICATE, BIOMETRIC_SERPRO, BIOMETRIC_SERPRO_AUTO_FALLBACK\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-signer envelopes\u003C\u002Fstrong> — sequential (each signer waits for the previous one) or parallel (everyone signs simultaneously), with consolidated \u003Ccode>.p7s\u003C\u002Fcode> or combined PDF download when complete\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Two authentication modes\u003C\u002Fstrong> — OAuth2 \u003Ccode>client_credentials\u003C\u002Fcode> (simple) or Private Key JWT ES256 (for regulated customers who cannot store shared secrets at rest)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce integration\u003C\u002Fstrong> — automatically emails the signing link after order completion\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Complete audit trail\u003C\u002Fstrong> — every API call and webhook delivery is logged in a dedicated table with a filterable WP_List_Table view and CSV export\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GDPR \u002F LGPD\u003C\u002Fstrong> — data exporter and eraser handlers registered with the WordPress privacy panel\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Observability\u003C\u002Fstrong> — \u003Ccode>RateLimit-*\u003C\u002Fcode> headers captured for the dashboard widget; deprecation warnings (RFC 8594 \u003Ccode>Deprecation\u003C\u002Fcode> \u002F \u003Ccode>Sunset\u003C\u002Fcode>) surface as admin notices\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Zero code\u003C\u002Fstrong> — configure everything from the WordPress admin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Shortcode \u003Ccode>[signdocs]\u003C\u002Fcode> and Gutenberg block to embed the signing button on any post or page\u003C\u002Fli>\n\u003Cli>Custom post type \u003Ccode>signdocs_envelope\u003C\u002Fcode> for multi-signer workflows with a signer repeater\u003C\u002Fli>\n\u003Cli>“Verify Document” admin page — paste an evidence ID or envelope ID and inspect signer identities, tenant CNPJ, consolidated downloads\u003C\u002Fli>\n\u003Cli>Audit log with filters by level, event type, and date range, plus streaming CSV export (via \u003Ccode>php:\u002F\u002Foutput\u003C\u002Fcode>, safe for multi-GB exports)\u003C\u002Fli>\n\u003Cli>Webhook secret rotation with a 7-day grace window — both secrets (current + previous) are accepted during rotation\u003C\u002Fli>\n\u003Cli>All 17 webhook event types covered, including the NT65 events (\u003Ccode>STEP.PURPOSE_DISCLOSURE_SENT\u003C\u002Fcode>, \u003Ccode>TRANSACTION.DEADLINE_APPROACHING\u003C\u002Fcode>)\u003C\u002Fli>\n\u003Cli>Custom capabilities (\u003Ccode>signdocs_manage\u003C\u002Fcode>, \u003Ccode>signdocs_send\u003C\u002Fcode>, \u003Ccode>signdocs_verify\u003C\u002Fcode>, \u003Ccode>signdocs_view_logs\u003C\u002Fcode>) automatically granted to administrator \u002F editor \u002F author\u003C\u002Fli>\n\u003Cli>WP-CLI commands (\u003Ccode>wp signdocs health | send | status | webhook-test | log-tail\u003C\u002Fcode>) for shell automation\u003C\u002Fli>\n\u003Cli>WooCommerce integration — “SignDocs Signature” product tab, automatic email with the signing link, order notes after completion\u003C\u002Fli>\n\u003Cli>Popup, redirect, or overlay — pick the embed mode that fits your theme\u003C\u002Fli>\n\u003Cli>Optional anonymous signing with rate limiting\u003C\u002Fli>\n\u003Cli>Credentials encrypted with AES-256-CBC in \u003Ccode>wp_options\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Hardened webhook receiver: timestamp drift gate (≤300s), HMAC-SHA256 timing-safe verification, replay de-duplication via \u003Ccode>X-SignDocs-Webhook-Id\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>OAuth token cache shared via WordPress transients (\u003Ccode>WpTransientTokenCache\u003C\u002Fcode> implements the SDK’s \u003Ccode>TokenCacheInterface\u003C\u002Fcode>) — a single token reused by every PHP-FPM worker\u003C\u002Fli>\n\u003Cli>Deterministic idempotency keys on every resource-creating call — AJAX retries never create duplicate sessions\u003C\u002Fli>\n\u003Cli>Deprecation observer (RFC 8594) that surfaces an admin notice when the API signals an endpoint is being removed\u003C\u002Fli>\n\u003Cli>Translatable: English, Portuguese (Brazil), Spanish\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Use cases\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Law firms\u003C\u002Fstrong> — powers of attorney, contracts, terms, multi-party envelopes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real estate\u003C\u002Fstrong> — rental and sale contracts signed by tenant, landlord, and guarantor (sequential envelope)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>E-commerce\u003C\u002Fstrong> — terms of service, supplier contracts, post-purchase NDAs\u003C\u002Fli>\n\u003Cli>\u003Cstrong>HR and people ops\u003C\u002Fstrong> — employment contracts, NDAs, onboarding paperwork\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Education\u003C\u002Fstrong> — enrollment forms and parental consent (parents + student in a parallel envelope)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>SaaS\u003C\u002Fstrong> — terms of use and license agreements at onboarding\u003C\u002Fli>\n\u003Cli>\u003Cstrong>INSS payroll loans (Brazil-specific)\u003C\u002Fstrong> — NT65 flow with SERPRO biometric verification and purpose disclosure notification\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Banks and financial institutions\u003C\u002Fstrong> — Private Key JWT lets you sign without storing a shared secret in the database\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How it works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Configure your SignDocs Brasil API credentials in the WordPress admin (Client ID + Secret, or Private Key + Key ID)\u003C\u002Fli>\n\u003Cli>Add a shortcode, Gutenberg block, or create a multi-signer envelope from the admin\u003C\u002Fli>\n\u003Cli>The signer clicks “Sign Document” and is redirected to the secure domain \u003Ccode>sign.signdocs.com.br\u003C\u002Fcode> (signing \u003Cstrong>never happens inside your WordPress site\u003C\u002Fstrong> — this isolates your install from any compromise)\u003C\u002Fli>\n\u003Cli>The signer completes the flow according to the configured policy (click, OTP, biometrics, digital certificate)\u003C\u002Fli>\n\u003Cli>Webhooks update the status in the WordPress admin in real time; the \u003Ccode>.p7m\u003C\u002Fcode> evidence package becomes available for download and verification\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Links\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fsigndocs.com.br\" rel=\"nofollow ugc\">Official site\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.signdocs.com.br\" rel=\"nofollow ugc\">API documentation\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fsigndocs.com.br\u002Fsuporte\" rel=\"nofollow ugc\">Support\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fapp.signdocs.com.br\u002Fcadastro\" rel=\"nofollow ugc\">Create a free account\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fsigndocsbrasil\u002Fsigndocs-brasil-wordpress\" rel=\"nofollow ugc\">GitHub repository\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Ch4>Shortcode\u003C\u002Fh4>\n\u003Cp>Add to any page or post:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>[signdocs document_id=\"123\" policy=\"CLICK_ONLY\" button_text=\"Sign Contract\"]\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>With name \u002F email \u002F CPF form:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>[signdocs document_id=\"123\" show_form=\"true\" policy=\"CLICK_PLUS_OTP\"]\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>\u003Cstrong>Available attributes:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>document_id\u003C\u002Fcode> (required) — ID of the PDF attachment in the media library\u003C\u002Fli>\n\u003Cli>\u003Ccode>policy\u003C\u002Fcode> — one of: \u003Ccode>CLICK_ONLY\u003C\u002Fcode>, \u003Ccode>CLICK_PLUS_OTP\u003C\u002Fcode>, \u003Ccode>BIOMETRIC\u003C\u002Fcode>, \u003Ccode>BIOMETRIC_PLUS_OTP\u003C\u002Fcode>, \u003Ccode>DIGITAL_CERTIFICATE\u003C\u002Fcode>, \u003Ccode>BIOMETRIC_SERPRO\u003C\u002Fcode>, \u003Ccode>BIOMETRIC_SERPRO_AUTO_FALLBACK\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>locale\u003C\u002Fcode> — language: \u003Ccode>pt-BR\u003C\u002Fcode>, \u003Ccode>en\u003C\u002Fcode>, \u003Ccode>es\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>mode\u003C\u002Fcode> — embed mode: \u003Ccode>redirect\u003C\u002Fcode> (default), \u003Ccode>popup\u003C\u002Fcode>, \u003Ccode>overlay\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Ccode>button_text\u003C\u002Fcode> — button label (default: “Sign Document”)\u003C\u002Fli>\n\u003Cli>\u003Ccode>show_form\u003C\u002Fcode> — \u003Ccode>\"true\"\u003C\u002Fcode> to display name \u002F email \u002F CPF \u002F CNPJ inputs\u003C\u002Fli>\n\u003Cli>\u003Ccode>return_url\u003C\u002Fcode> — URL to redirect to after signing\u003C\u002Fli>\n\u003Cli>\u003Ccode>class\u003C\u002Fcode> — additional CSS class for the button\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Gutenberg block\u003C\u002Fh4>\n\u003Col>\n\u003Cli>In the block editor, click “+” to add a block\u003C\u002Fli>\n\u003Cli>Search for “SignDocs” or “Signature”\u003C\u002Fli>\n\u003Cli>Pick a PDF in the right sidebar\u003C\u002Fli>\n\u003Cli>Configure the policy, locale, and mode\u003C\u002Fli>\n\u003Cli>Publish the page\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Multi-signer envelopes\u003C\u002Fh4>\n\u003Cp>For contracts with more than one signer (for example, landlord + tenant + guarantor), use the \u003Cstrong>Envelopes\u003C\u002Fstrong> menu:\u003C\u002Fp>\n\u003Col>\n\u003Cli>WP Admin > Signatures > Envelopes > Add New\u003C\u002Fli>\n\u003Cli>Select the signing mode:\n\u003Cul>\n\u003Cli>\u003Cstrong>SEQUENTIAL\u003C\u002Fstrong> — each signer signs in order; the next signer only receives their link when the previous one completes\u003C\u002Fli>\n\u003Cli>\u003Cstrong>PARALLEL\u003C\u002Fstrong> — all signers can sign simultaneously, in any order\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Add the signers (name + email + CPF or CNPJ + optional per-signer policy)\u003C\u002Fli>\n\u003Cli>Attach the PDF and publish\u003C\u002Fli>\n\u003Cli>Each signer receives an email with their individual link; the admin sees the envelope status update as each signature completes\u003C\u002Fli>\n\u003Cli>After everyone has signed, a combined stamped PDF (or consolidated \u003Ccode>.p7s\u003C\u002Fcode> for non-PDF documents) becomes available for download\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>The webhook events \u003Ccode>STEP.STARTED\u003C\u002Fcode>, \u003Ccode>STEP.COMPLETED\u003C\u002Fcode>, and \u003Ccode>STEP.FAILED\u003C\u002Fcode> are recorded per signer in each envelope’s log.\u003C\u002Fp>\n\u003Ch4>WooCommerce\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Edit a product and open the “SignDocs Signature” tab\u003C\u002Fli>\n\u003Cli>Check “Requires signature” and select the PDF\u003C\u002Fli>\n\u003Cli>Configure the verification policy\u003C\u002Fli>\n\u003Cli>When an order completes, the signing link is automatically emailed to the customer\u003C\u002Fli>\n\u003Cli>After signing, an order note is added with the evidence ID\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cblockquote>\n\u003Cp>The customer’s CPF or CNPJ must be present in the order. The plugin reads the standard \u003Ccode>_billing_cpf\u003C\u002Fcode> \u002F \u003Ccode>_billing_cnpj\u003C\u002Fcode> order meta keys used by the \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwoocommerce-extra-checkout-fields-for-brazil\u002F\" rel=\"ugc\">Brazilian Market on WooCommerce\u003C\u002Fa> extension. If neither is present, the plugin adds an order note explaining the requirement and skips session creation.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>Document verification\u003C\u002Fh4>\n\u003Cp>The \u003Cstrong>Signatures > Verify\u003C\u002Fstrong> page (requires the \u003Ccode>signdocs_verify\u003C\u002Fcode> capability):\u003C\u002Fp>\n\u003Col>\n\u003Cli>Paste an \u003Ccode>evidence_id\u003C\u002Fcode> (single signature) or \u003Ccode>envelope_id\u003C\u002Fcode> (multi-signer)\u003C\u002Fli>\n\u003Cli>The plugin calls \u003Ccode>GET \u002Fv1\u002Fverify\u002F{id}\u003C\u002Fcode> or \u003Ccode>GET \u002Fv1\u002Fverify\u002Fenvelope\u002F{id}\u003C\u002Fcode> and renders:\n\u003Cul>\n\u003Cli>Identities of every signer (name, CPF\u002FCNPJ)\u003C\u002Fli>\n\u003Cli>Tenant CNPJ\u003C\u002Fli>\n\u003Cli>Timestamps for each step\u003C\u002Fli>\n\u003Cli>The applied policy profile\u003C\u002Fli>\n\u003Cli>Download links: evidence package (\u003Ccode>.p7m\u003C\u002Fcode>), signed PDF, consolidated \u003Ccode>.p7s\u003C\u002Fcode> (envelopes), combined PDF (envelopes)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Use the evidence files in external validators (ITI Validador, Adobe Acrobat) for independent confirmation\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Audit log\u003C\u002Fh4>\n\u003Cp>The \u003Cstrong>Signatures > Audit Log\u003C\u002Fstrong> page (requires the \u003Ccode>signdocs_view_logs\u003C\u002Fcode> capability):\u003C\u002Fp>\n\u003Cul>\n\u003Cli>WP_List_Table view over \u003Ccode>{prefix}signdocs_log\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Filters: level (debug \u002F info \u002F warning \u002F error), event type, date range\u003C\u002Fli>\n\u003Cli>CSV export via \u003Ccode>admin-post.php\u003C\u002Fcode> (chunked streaming, safe for multi-GB exports)\u003C\u002Fli>\n\u003Cli>Automatic 30-day retention via the daily \u003Ccode>signdocs_prune_logs\u003C\u002Fcode> cron\u003C\u002Fli>\n\u003Cli>Every API call, webhook delivery, and deprecation warning is recorded with JSON context\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WP-CLI\u003C\u002Fh4>\n\u003Cp>For shell-based operations (useful for automation, CI\u002FCD, and troubleshooting):\u003C\u002Fp>\n\u003Cpre>\u003Ccode>wp signdocs health\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>— check connectivity to the API in the configured environment\u003C\u002Fp>\n\u003Cpre>\u003Ccode>wp signdocs send --document=42 --email=alice@example.com --cpf=12345678901 --policy=CLICK_PLUS_OTP\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>— create a signing session from a WordPress attachment and print the session ID and URL\u003C\u002Fp>\n\u003Cpre>\u003Ccode>wp signdocs status \u003CsessionId>\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>— look up the status of a session by ID\u003C\u002Fp>\n\u003Cpre>\u003Ccode>wp signdocs webhook-test \u003CwebhookId>\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>— send a test delivery to a registered webhook\u003C\u002Fp>\n\u003Cpre>\u003Ccode>wp signdocs log-tail --level=warning --limit=20\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>— show the last N entries of the audit log filtered by level\u003C\u002Fp>\n\u003Ch4>Webhook secret rotation\u003C\u002Fh4>\n\u003Col>\n\u003Cli>In Settings > SignDocs Brasil, click “Rotate Secret”\u003C\u002Fli>\n\u003Cli>The plugin requests a new secret from the API; the previous secret becomes the “previous secret” with a 7-day grace window\u003C\u002Fli>\n\u003Cli>During the window, the \u003Ccode>\u002Fwp-json\u002Fsigndocs\u002Fv1\u002Fwebhook\u003C\u002Fcode> endpoint accepts \u003Cstrong>both\u003C\u002Fstrong> secrets — in-flight deliveries are not rejected\u003C\u002Fli>\n\u003Cli>After 7 days, the daily \u003Ccode>signdocs_expire_prev_secret\u003C\u002Fcode> cron removes the old secret\u003C\u002Fli>\n\u003Cli>The rotation status is visible in the admin (with a countdown)\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>For developers\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Available hooks:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Session lifecycle:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>signdocs_session_created\u003C\u002Fcode> — Session created (via the API, not necessarily via WordPress)\u003C\u002Fli>\n\u003Cli>\u003Ccode>signdocs_signing_completed\u003C\u002Fcode> — Signing completed successfully\u003C\u002Fli>\n\u003Cli>\u003Ccode>signdocs_signing_cancelled\u003C\u002Fcode> — Signing cancelled by the integrator or the signer\u003C\u002Fli>\n\u003Cli>\u003Ccode>signdocs_signing_expired\u003C\u002Fcode> — Session expired without completion\u003C\u002Fli>\n\u003Cli>\u003Ccode>signdocs_signing_failed\u003C\u002Fcode> — Signing failed (unrecoverable error)\u003C\u002Fli>\n\u003Cli>\u003Ccode>signdocs_transaction_fallback\u003C\u002Fcode> — Fallback was triggered (e.g., SERPRO unavailable)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Per-step (for envelopes and custom flows):\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>signdocs_step_started\u003C\u002Fcode> — Step started (OTP sent, biometric capture, etc.)\u003C\u002Fli>\n\u003Cli>\u003Ccode>signdocs_step_completed\u003C\u002Fcode> — Step completed\u003C\u002Fli>\n\u003Cli>\u003Ccode>signdocs_step_failed\u003C\u002Fcode> — Step failed\u003C\u002Fli>\n\u003Cli>\u003Ccode>signdocs_purpose_disclosure_sent\u003C\u002Fcode> — (NT65) Purpose disclosure notification delivered to the beneficiary\u003C\u002Fli>\n\u003Cli>\u003Ccode>signdocs_deadline_approaching\u003C\u002Fcode> — (NT65) ≤2 business days left before the INSS submission deadline\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Tenant \u002F API:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>signdocs_quota_warning\u003C\u002Fcode> — Tenant usage crossed a threshold (80 \u002F 90 \u002F 100%)\u003C\u002Fli>\n\u003Cli>\u003Ccode>signdocs_api_deprecation_notice\u003C\u002Fcode> — API signaled a deprecated endpoint\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>WooCommerce:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>signdocs_wc_signing_completed\u003C\u002Fcode> — A WooCommerce order signing completed\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Each action receives \u003Ccode>$post_id\u003C\u002Fcode> (of the \u003Ccode>signdocs_signing\u003C\u002Fcode> or \u003Ccode>signdocs_envelope\u003C\u002Fcode> CPT) and \u003Ccode>$payload\u003C\u002Fcode> (the raw webhook array) as arguments, except \u003Ccode>signdocs_quota_warning\u003C\u002Fcode> and \u003Ccode>signdocs_api_deprecation_notice\u003C\u002Fcode> which receive only the payload.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Capabilities:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ccode>signdocs_manage\u003C\u002Fcode> — Configure credentials, webhook, branding; manage other users’ envelopes\u003C\u002Fli>\n\u003Cli>\u003Ccode>signdocs_send\u003C\u002Fcode> — Create sessions and envelopes\u003C\u002Fli>\n\u003Cli>\u003Ccode>signdocs_verify\u003C\u002Fcode> — Use the Verify page and inspect evidence\u003C\u002Fli>\n\u003Cli>\u003Ccode>signdocs_view_logs\u003C\u002Fcode> — Access the audit log and export CSV\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Use \u003Ccode>current_user_can('signdocs_send')\u003C\u002Fcode> instead of \u003Ccode>manage_options\u003C\u002Fcode> \u002F \u003Ccode>edit_posts\u003C\u002Fcode> when adding custom functionality.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>PHP SDK:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>The configured SDK client (with encrypted credentials and shared token cache) is available via:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>$client = Signdocs_Client_Factory::get(); \u002F\u002F SignDocsBrasil\\Api\\SignDocsBrasilClient or null\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>See the \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fsigndocsbrasil\u002Fsigndocs-brasil-php\" rel=\"nofollow ugc\">PHP SDK documentation\u003C\u002Fa> for the full surface (transactions, envelopes, verification, users, documentGroups, webhooks, etc.).\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin connects to the SignDocs Brasil platform — operated by the same company that publishes the plugin — to create, deliver, and verify electronic signatures. The plugin \u003Cstrong>cannot function without\u003C\u002Fstrong> sending data to these endpoints, because the signing itself happens on the SignDocs servers (the WordPress site only orchestrates the request and stores the result reference).\u003C\u002Fp>\n\u003Ch4>SignDocs Brasil API (api.signdocs.com.br \u002F api-hml.signdocs.com.br)\u003C\u002Fh4>\n\u003Cp>Used to create signing sessions, register webhooks, verify signed evidence, and manage multi-signer envelopes. The plugin authenticates with the API credentials you enter in the WordPress admin (OAuth2 \u003Ccode>client_credentials\u003C\u002Fcode>, or alternatively Private Key JWT when configured).\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>What data is sent\u003C\u002Fstrong>, per signing-session create: the PDF document content (base64-encoded), the signer’s name, the signer’s email address, the signer’s CPF or CNPJ (one is required by the API), the selected verification policy (e.g. \u003Ccode>CLICK_ONLY\u003C\u002Fcode>, \u003Ccode>BIOMETRIC\u003C\u002Fcode>), the language preference, an optional return URL, and metadata fields identifying the WordPress site URL and source surface (shortcode, AJAX, WP-CLI, WooCommerce, envelope).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When\u003C\u002Fstrong>: every time a signing session is created. This happens on shortcode AJAX submission, on \u003Ccode>wp signdocs send\u003C\u002Fcode> from the WP-CLI, on WooCommerce order completion when the product is configured for signing, and on every envelope creation \u002F new-signer add.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Other API calls\u003C\u002Fstrong> that send no document data: webhook registration, status polling (\u003Ccode>GET \u002Fv1\u002Fsigning-sessions\u002F{id}\u003C\u002Fcode>), evidence verification (\u003Ccode>GET \u002Fv1\u002Fverify\u002F{evidenceId}\u003C\u002Fcode>), envelope status. These send only the relevant identifier you provide (session ID, evidence ID, envelope ID).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Authentication\u003C\u002Fstrong>: every API call is authenticated with a short-lived Bearer token obtained from the OAuth2 token endpoint at the same domain (\u003Ccode>POST {baseUrl}\u002Foauth2\u002Ftoken\u003C\u002Fcode>). The plugin sends your Client ID and either Client Secret or a signed JWT assertion (when Private Key JWT mode is configured) to that endpoint at first call and again when the cached token expires (typically once per hour per environment); the access token is cached in a WordPress transient and reused across all subsequent API calls. No signer data is sent to the token endpoint.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Environment switch\u003C\u002Fstrong>: the plugin uses \u003Ccode>api-hml.signdocs.com.br\u003C\u002Fcode> (HML \u002F sandbox) by default, and \u003Ccode>api.signdocs.com.br\u003C\u002Fcode> only when the administrator explicitly switches the environment to “Production” in the settings page.\u003C\u002Fli>\n\u003Cli>Provided by SignDocs Brasil. \u003Ca href=\"https:\u002F\u002Fsigndocs.com.br\u002Ftermos-de-uso\" rel=\"nofollow ugc\">Terms of Use\u003C\u002Fa>. \u003Ca href=\"https:\u002F\u002Fsigndocs.com.br\u002Fpolitica-de-privacidade\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>SignDocs Brasil browser SDK (cdn.signdocs.com.br \u002F cdn-hml.signdocs.com.br)\u003C\u002Fh4>\n\u003Cp>A JavaScript file (\u003Ccode>signdocs-brasil.js\u003C\u002Fcode>) loaded from the SignDocs CDN that opens the signing popup, redirect, or overlay when the signer clicks the embedded “Sign Document” button rendered by the shortcode or Gutenberg block.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>What data is sent\u003C\u002Fstrong>: nothing directly by this script load — it is a static asset request, the same as any other JavaScript file from a third-party CDN. No personally identifiable information is transmitted by the CDN request itself; the script is bytes-identical for every site that loads it.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When\u003C\u002Fstrong>: every front-end page-view that renders the \u003Ccode>[signdocs]\u003C\u002Fcode> shortcode or the SignDocs Gutenberg block (the script is enqueued conditionally — pages without the block do not load it).\u003C\u002Fli>\n\u003Cli>The CDN environment (HML vs prod) follows the same \u003Ccode>signdocs_environment\u003C\u002Fcode> option as the API.\u003C\u002Fli>\n\u003Cli>Provided by SignDocs Brasil. \u003Ca href=\"https:\u002F\u002Fsigndocs.com.br\u002Ftermos-de-uso\" rel=\"nofollow ugc\">Terms of Use\u003C\u002Fa>. \u003Ca href=\"https:\u002F\u002Fsigndocs.com.br\u002Fpolitica-de-privacidade\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>SignDocs Brasil signing UI (sign.signdocs.com.br)\u003C\u002Fh4>\n\u003Cp>After the signer clicks “Sign Document”, they are taken to the secure signing page on \u003Ccode>sign.signdocs.com.br\u003C\u002Fcode> — \u003Cstrong>not\u003C\u002Fstrong> to a page hosted by your WordPress site. The signing flow (OTP, biometric capture, digital-certificate selection, click-only confirmation) executes entirely on this domain. This isolation is intentional: even if your WordPress site were compromised, an attacker could not forge signatures because the authentication factors are collected on a separate origin under SignDocs Brasil’s control.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>What data is sent\u003C\u002Fstrong>: the signer interacts directly with this domain to complete the signing flow. The data exchanged here (OTP codes, biometric photos, certificate selections) does not pass through your WordPress site. Your plugin only receives the result back via the webhook described above.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When\u003C\u002Fstrong>: when the signer clicks the signing button rendered by the plugin and the browser SDK opens the signing surface (popup \u002F redirect \u002F overlay).\u003C\u002Fli>\n\u003Cli>Provided by SignDocs Brasil. \u003Ca href=\"https:\u002F\u002Fsigndocs.com.br\u002Ftermos-de-uso\" rel=\"nofollow ugc\">Terms of Use\u003C\u002Fa>. \u003Ca href=\"https:\u002F\u002Fsigndocs.com.br\u002Fpolitica-de-privacidade\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n","Legally-binding e-signature for Brazil: OTP, biometrics, ICP-Brasil, multi-signer envelopes, audit log, WP-CLI, WooCommerce.",129,"2026-05-22T23:26:00.000Z","6.9.5","6.0","8.1",[25,26,27,28,29],"contracts","digital-signature","electronic-signature","icp-brasil","woocommerce","https:\u002F\u002Fgithub.com\u002Fsigndocsbrasil\u002Fsigndocs-brasil-wordpress","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fsigndocs-brasil.1.3.7.zip",null,"2026-07-22T17:31:50.256Z"]