Aadhaar eSign Automation with n8n
n8n is a good fit when the PDF comes from one system and the result needs to land in another: a form tool, a CRM, Google Drive, Slack. This guide builds two workflows: one that sends a document for Aadhaar eSign with HTTP Request nodes, and one that receives SignYu webhooks and verifies them before acting.
Updated 2026-10-01
What you need
- n8n self-hosted or n8n Cloud. Signature verification in a Code node needs the crypto module, which self-hosted instances allow with NODE_FUNCTION_ALLOW_BUILTIN=crypto.
- A SignYu API key (starts with sk_live_). API access costs ₹999/month with a 3-day free trial; create the key under Developers in the dashboard.
- Signature credits for your signers, from ₹15 per signature (₹15 per signature on packs of 10 or more). Sending uses one credit per signer.
- A webhook endpoint added under Developers, and its signing secret.
Step 1: Create a credential
In Credentials, add a Header Auth credential named SignYu with header name Authorization and value Bearer followed by your sk_live_ key. Every HTTP Request node below uses Authentication: Generic Credential Type, Header Auth, SignYu.
Step 2: Upload the PDF
The previous node must output the PDF as binary data (for example Google Drive Download, or Read Binary File). Configure an HTTP Request node as shown. n8n sends the binary with its stored MIME type, so make sure it is application/pdf.
Method: POST
URL: https://signyu.com/api/v1/documents
Authentication: Header Auth (SignYu)
Send Body: on
Body Content Type: Form-Data
Body Parameters:
1. Parameter Type: n8n Binary File
Name: file
Input Data Field Name: data
2. Parameter Type: Form Data
Name: name
Value: {{ $json.agreementTitle }}Step 3: Add signers and send
Two more HTTP Request nodes. The signers body is JSON built from earlier nodes; the send node has no body. Turn on Settings, Continue On Fail on the send node and add an IF node on the error so a 402 insufficient_credits posts to Slack instead of failing silently.
Add signers
Method: POST
URL: https://signyu.com/api/v1/documents/{{ $('Create document').item.json.documentId }}/signers
Body Content Type: JSON
JSON:
{
"signers": [
{ "name": "{{ $json.clientName }}", "phone": "{{ $json.clientPhone }}", "email": "{{ $json.clientEmail }}" }
]
}
Send
Method: POST
URL: https://signyu.com/api/v1/documents/{{ $('Create document').item.json.documentId }}/send
Output: signers[0].signUrl can be sent on by WhatsApp, SMS or email nodesVerify webhooks
In the second workflow, add a Webhook node (HTTP Method POST) and turn on Options, Raw Body, so the exact bytes are kept as binary data. Set Respond to Using Respond to Webhook Node. A Code node then recomputes the HMAC and either passes the parsed event on or throws. Put the webhook secret in an environment variable such as SIGNYU_WEBHOOK_SECRET.
const crypto = require("crypto");
const item = $input.first();
const raw = await this.helpers.getBinaryDataBuffer(0, "data");
const header = item.json.headers["x-signsetu-signature"] || "";
const expected =
"sha256=" + crypto.createHmac("sha256", $env.SIGNYU_WEBHOOK_SECRET).update(raw).digest("hex");
const a = Buffer.from(header);
const b = Buffer.from(expected);
if (a.length !== b.length || !crypto.timingSafeEqual(a, b)) {
throw new Error("Invalid SignYu signature");
}
// Next: Respond to Webhook (200), then a Switch on {{ $json.event }}
return [{ json: JSON.parse(raw.toString("utf8")) }];Common mistakes
- Without the Raw Body option, the Webhook node gives you parsed JSON only, and re-stringifying it will not match the signature.
- require("crypto") fails unless NODE_FUNCTION_ALLOW_BUILTIN includes crypto, and $env is blocked when N8N_BLOCK_ENV_ACCESS_IN_NODE is true. Check both on self-hosted instances.
- Respond to the webhook before slow nodes run. SignYu times out after 10 seconds and retries, which re-runs the whole workflow.
- The PDF binary from some sources has MIME type application/octet-stream. Set binary.data.mimeType to application/pdf in a Code node before the upload, or it returns 400 invalid_file.
- The downloadUrl is a temporary presigned storage link. Download it with a plain GET and no Authorization header (sending your Bearer key to it makes the request fail), and do not store the URL itself; call GET /api/v1/documents/{id} again for a fresh one.
Frequently asked questions
Is there an official SignYu node for n8n?
Not currently. The HTTP Request node covers every endpoint, and you can save the configured nodes as a template for your team.
Does this work on n8n Cloud?
Sending documents does. Webhook verification needs the crypto module in a Code node; if your plan does not allow it, use a Schedule Trigger that polls GET /api/v1/documents/{id} instead of trusting unverified webhooks.
How do I save the signed PDF to Google Drive?
After document.completed, call GET /api/v1/documents/{id} with the SignYu credential, then an HTTP Request node with no authentication on downloadUrl and Response Format File, then a Google Drive Upload node.
Can I trigger signing from a Typeform or Tally submission?
Yes. Use the form tool's trigger node, generate or fetch the PDF, then run the three SignYu nodes. Map the respondent's name, mobile and email into the signers JSON.
API reference
Get your API key
Start a 3-day free trial of API access and send your first document today.